HNHacker News
TopNewBestAskShowJobs

rndomsrmn

62 karma · joined November 2, 2017

submissionscomments
rndomsrmn··on Cname / DNS based third party tracking
Websites that use CNAME to forward their main domain to some tracking company, basically give their entire domain away, I don't see how that is a good secure way to track your users..

DNSCrypt-proxy (and even pihole these days I believe) are actually capable of blocking forwarded CNAME requests. Setting up such system for network wide adblocking is not complicated at all, see: https://github.com/notracking/hosts-blocklists/wiki/Install-...

rndomsrmn··on We rendered a million web pages to find out what makes the web slow
https://github.com/notracking/hosts-blocklists

Use this for network wide blocking of all sorts of virtual garbage. Not only for safari, but all your locally connected devices.

rndomsrmn··on Firefox 85 cracks down on supercookies
You can get even better coverage with the NoTracking lists (dnsmasq/unbound or dnscrypt-proxy) https://github.com/notracking/hosts-blocklists

They focus not only on tracking but also malware prevention, where possible via dns filtering.

Pi-Hole still does not properly support wildcard filtering, only via regex but that is not really efficient (requires tons of resources).

rndomsrmn··on URL shorteners set ad tracking cookies
You might want to consider checking for hosts listed in https://github.com/notracking/hosts-blocklists

This is an excellent merged blocklist, with public whitelist (oisd is fully closed, no insight in what is whitelisted and why, also causing more false positives..)

rndomsrmn··on All-in-One DNS block list
Also a ref to: https://github.com/notracking/hosts-blocklists

They have a public whitelist and updates are pushed on a daily basis.

rndomsrmn··on Google rolls out DNS-over-HTTPS support in Chrome 83
See: https://github.com/notracking/hosts-blocklists#dns-over-http... how Mozilla deals with this.

For Chrome this feature seems not to be implemented, making it harder to control your DNS behavior in your own network. (see Q&A at the bottom of the page) https://sites.google.com/a/chromium.org/dev/developers/dns-o...

rndomsrmn··on The opt-out illusion: how we have acquiesced to losing our privacy
It is possible to use this feature 'in' Pi-Hole, see: https://github.com/notracking/hosts-blocklists/wiki/Install-...
rndomsrmn··on The opt-out illusion: how we have acquiesced to losing our privacy
Dnsmasq 'address=' function is just a substr() call, which is as fast as 'normal' hostname blocking (host == "adhost.com"). No regex magic is required there.

You are not able to block something like 'ads.%.adhost.com', but only (prepending wildcard) '%.ads.adhost.com', which in practice will cover almost all scenarios where random subdomains are used by adhosts.

rndomsrmn··on The opt-out illusion: how we have acquiesced to losing our privacy
regex is _extremely_ resource inefficient and should not be used with large sets of rules. Dnsmasqs domain redirecting feature (address=/adhost.com/#) is not supported by pihole.

Is there any other way to wildcard block full domains in Pi-Hole?

Look for example in your list: d41.co, admaster.com.cn, mixmarket.biz chances are extremely slim that all (current) hostnames of those type of domains are currently being blocked.

rndomsrmn··on The opt-out illusion: how we have acquiesced to losing our privacy
dnscrypt-proxy is already supporting CNAME blocking and full domain based blocking (*.adhost.com), something that is still missing in Pi-Hole.
rndomsrmn··on Sensor Tower owns ad blocker and VPN apps that collect user data
A dnscrypt-proxy setup with https://github.com/notracking/hosts-blocklists/tree/master/d... goes a long way!

For anything that is not blockable on DNS level one should use uBlock Origin from Gorhill.

rndomsrmn··on How many users block Google analytics? (2017)
try hosting your own dnscrypt-proxy in combination with https://github.com/notracking/hosts-blocklists. That will turn off most trackers on your entire network.
rndomsrmn··on Remove almost all online garbage using Dnsmasq
You will know on forehand what the fixed DOH servers will be, how else would you be able to locate them?

If for example they will use the 1.1.1.1 DOH instance, you can simply redirect all localnet 1.1.1.1 (80/53) traffic to your own local (DOH)DNS(masq).

Besides that there must be a fallback option for network admins, since using dns filtering and localnet dns is very common in enterprise. Firefox implemented a canary domain, specifically designed for this purpose, see: https://support.mozilla.org/en-US/kb/canary-domain-use-appli...

rndomsrmn··on Remove almost all online garbage using Dnsmasq
uBlock and uMatrix are a perfect addition to a setup with a dns based filtering system, though by themselves alone do not provide a solution for all use cases. Think smarttv's, consoles, IOS devices, apps, etc. Basically anything that is not android firefox browser or a desktop browser.

Additionally having DNS filtering in place will also prevent information leakage in case something goes wrong with one of your browser plugins.

rndomsrmn··on Remove almost all online garbage using Dnsmasq
Mozilla added a feature to allow users to disable DOH network wide (also supported by the notracking list).

Info from notracking: https://github.com/notracking/hosts-blocklists#dns-over-http... Info from Mozilla: https://support.mozilla.org/en-US/kb/configuring-networks-di...

Not sure if Microsoft will do something similar? Else there is still the option to set up your own (local) DOH server and let your router route all DOH traffic to your local DOH instance.

rndomsrmn··on Remove almost all online garbage using Dnsmasq
You can also redirect those public dns servers on you router to your local Dnsmasq server with iptables.
rndomsrmn··on Remove almost all online garbage using Dnsmasq
Pihole does not make use of dnsmasq's build in option to block entire domains (address=/ads.com/::). This list is also optimized because hostnames that match a domain filter are not included, reducing the size a lot.
rndomsrmn··on DNS servers that offer privacy and filtering
Or setup your own very lightweight filtering and caching DNS at home using Dnsmasq and https://github.com/notracking/hosts-blocklists/
rndomsrmn··on Pi-Hole: Why You Need a Network-Wide Ad-Blocker
Or https://github.com/notracking/hosts-blocklists that uses a dnsmasq feature to block full domains.
rndomsrmn··on November Workshop: Running the Pi-hole Network-wide Ad-blocker, and more
Or you just use a very basic dnsmasq installation and make use of a list like: https://github.com/notracking/hosts-blocklists that allows you to also block full domains.

Been using this list for several months now without any issues.

Besides that, it's worth reading in to dnsmasq's configuration in more detail, in the end pi-hole is just a preconfigured dnsmasq installation with a user interface to manage hostname based blocklists.