34 karma · joined March 13, 2017
Say hi to J from me.
No ETAs as yet, of course, but it's something that has been asked about time and time again, and we think we may just have solved it...
Oobe is either 1)leave suggested defaults as is 2)don't use those lists.
Option 2 is available in the installer before you're even up and running. There is only so much hand holding we can do, to be fair. We have an extensive support community, and plenty of documentation, and yes, whilst I agree some users may fall between the cracks, the majority are able to find a solution to their problems.
It's safest for us, and our reputation, to stay out of the finer points of the actual blocked/not domains and instead defer to individual list maintainers who make that their business.
You can configure the lists that you use to suit your needs. You can also whitelist any domains that you need. It's up to you what you ultimately block!
An Rpi3, even a Rpi B or zero is plenty good enough for DNS queries! The Admin interface has been a bit of a bugbear for a while, but we are working on some massive improvements for the 3.0 release (coming soon™)
There are also other tools to help with blacklisted domains that cause issues/site breakages, such as a query log to identify them, and the ability to whitelist with ease!
Essentially all that is happening is a client asks for a domain (e.g ssl.google.com) and if it is on the blacklist, then it returns it's own local IP address for that domain instead of the real one. Which is where you will find the browser complaining. All we return is a blank page/blocking information page, but not via https.
Of course, we could probably get around that by generating self-signed certificates on install, but the user would then need to install that certificate on all of their client machines (I think, I'm not massively proficient in this area!) which makes it an extra, and not vital, step that may scare off the more novice users.
Thanks for vouching for me :)
The name has just kind of stuck, even though you can in fact run it on most linux distros (We officially support Ubuntu/Debian based distros, but there is limited support for Centos, and even forks for Arch, and Docker!), on a whole host of different hardware.
Updates are manual, too, so unless you intervene, there is no reason that a working system would suddenly become compromised, except if somebody had access to your network. But then you have a different issue...
Everyone's mileage varies, but I have only had to whitelist 5 or 6 sites using the default blocklists.
Compare the "automagical" whitelist entries (http://imgur.com/a/rxgsC) to the Default whitelist here: https://github.com/pi-hole/pi-hole/blob/master/adlists.defau...
Edit: The code that does it: https://github.com/pi-hole/pi-hole/blob/master/gravity.sh#L2...