Live data from Hacker News

Mmm, Pi-hole

troyhunt.com

191–200 of 421 posts

Re: Mmm, Pi-hole

#191

My Pi-hole with updated block lists (blocking trackers as well as ads) sits at around 87.7% requests blocked, which is absolutely mind-blowingly ridiculous. I see absolutely no negative effects browsing like this. Everything I've come across still works fine. Even sites that detect uBlock Origin and tell me to disable it, will work with that disabled and Pi-hole still blocking the ads instead. I heavily believe we sh…

> I heavily believe we should be supporting creators As do I. There's two significant issues I have supporting most sites: 1. They provide only a subscription that is comparable cost to an old-media full subscription. Like most people in the Internet age I have a small number of main sources that I visit daily, and a much larger secondary tier where I may average one or two stories a week. Or they're the sites linked…

> There's no low user or micro transaction options for these, so I get a choice of pay say £10 a month or nothing

There is yet to be a quick and simple micro-transaction infrastructure for the web. Transaction costs inhibit micro-transactions. They don’t scale down.

Some are trying to use crypto to do micro-transactions, but even crypto has transaction costs that inhibit how small micro-transactions can be, not to mention the exchange rate volatility.

It’s a big unsolved problem. Gotta spend money to spend money.

Re: Mmm, Pi-hole

#192

Don't buy a raspberry pi just for this, chances are you have some old windows machine you can slap Ubuntu server on and set it up easily. That's what I did and I have very little Linux experience. My favorite thing about it is ad-blocking in mobile apps. I tried to use it with OpenVPN on my android phone for ad-blocking when I'm on cellular data, but the speed it was unbearable. I'm not sure if it was my crappy route…

Have had Pi-Hole running on an old 10" netbook for a little over a year now. Set it up just to play around with it, wound up being a perfect machine for it.

Agree about ad-blocking on mobile. The killer feature with Pi-Hole is that you don't have to set anything up on each individual device; anything connected to your network suddenly has near flawless adblocking.

Re: Mmm, Pi-hole

#193

Earlier quoted context omitted.

You can whitelist domains, you can add to the blacklist or you can temporarily disable pihole (5-10min whatever) while you do something.

Yup, I temporarily disabled it and life was good. But I can understand how this would frustrate people, especially when they don't know how to disable it or aren't given the password.

What about WS2811s with a pushbutton to temporarily disable, or a pushbutton on one of the GPIO pins, with the switch in a central location?

Re: Mmm, Pi-hole

#194
post #91

Earlier quoted context omitted.

You don't have to be confident has "no vulnerabilities" (an absurd standard) to understand that the worst possible vuln in the DNS server (say CSRFable RCE in dnsmasq) still puts an attacker in a less privileged position than what they get if they control uBlock Origin: UXSS. Now that browsers are serious about mixed content, DNS poisoning just isn't as interesting as it used to be. Also, odds are a lot of you are ru…

I absolutely agree with you about users already running dnsmasq, but the context here is a malicious developer abusing their position. The actual quality of the software is orthogonal. I still think you are understating the risk of a malicious DNS server. As you note, many users will have unpatched IOT or network facing devices (e.g. cameras, baby monitors or other smart gadgets). With DNS spoofing they all become vu…

I did not say "a compromised DNS server is completely inconsequential", I said that a compromised WebExtension with :/// and tabs permissions has UXSS (obviously true) and UXSS is worse than compromising DNS resolution.

Which one of these is worse:

a) I might be able to convince a bad IOT device to connect to an IP I control which may or may not let me do something interesting,

-- or --

b) I can just use your session cookie for GMail and reset all of your passwords for your IOT services and also everything else? And since I get UXSS, I can scan your internal network and get XSS on that IP/origin too. Or, I dunno: try to use UXSS to log in to your home router and change the DNS server to a machine I control?

The crux of your argument seems to be "it is more valuable to be able to point an IOT device at the wrong IP than it is to get UXSS on a machine on that network". That seems obviously wrong to me for any user, technical or not. If anything, it's worse for non-technical users, because they by-and-large don't have 2FA, making e-mail compromise far worse.

I only use the quality of the software in one sense: to bound how bad DNS resolution could possibly be. dnsmasq has had more than one of those style of game-over vulns. A malicious WebExtension or DNS server is indistinguishable from one with a bad enough vuln.

Re: Mmm, Pi-hole

#196
post #191

Earlier quoted context omitted.

> I heavily believe we should be supporting creators As do I. There's two significant issues I have supporting most sites: 1. They provide only a subscription that is comparable cost to an old-media full subscription. Like most people in the Internet age I have a small number of main sources that I visit daily, and a much larger secondary tier where I may average one or two stories a week. Or they're the sites linked…

> There's no low user or micro transaction options for these, so I get a choice of pay say £10 a month or nothing There is yet to be a quick and simple micro-transaction infrastructure for the web. Transaction costs inhibit micro-transactions. They don’t scale down. Some are trying to use crypto to do micro-transactions, but even crypto has transaction costs that inhibit how small micro-transactions can be, not to me…

I suggest looking at Lightning Network for micro-transactions. Still emerging tech, but it shows great promise.

Re: Mmm, Pi-hole

#197

Earlier quoted context omitted.

Can anyone recommend a "2018 good choice" for a consumer router that can run custom firmware (including dnsmasq), or a trustworthy recommendation website? Wirecutter for example doesn't note third party firmware: https://thewirecutter.com/reviews/best-wi-fi-router/

Not really an off-the shelf consumer router, but since you want to install custom firmware anyways, you might want to consider the PC-Engines APU2 board [1]. You can either install any "normal" desktop x86_64 Linux distribution or a specialized router OS such as OpenWrt [2]. The AMD APU on the board supports hardware virtualisation, so you're able to run several VMs via KVM to isolate the services the router is provi…

I second this. I've been running PC engines stuff for a few years and it's great. I currently have an APU and it handles my gigabit fiber no problem. I use a separate off-the-shelf wireless router in bridge mode which let's me upgrade that independent of the PC engines (wireless hardware tech moves faster than router hardware tech).

I run openwrt on it and use the "adblock" package which works like pi-hole (minus the nice web stats). Having it be a plain x86 CPU is nice—For example, I compiled Telegraf on my local Linux machine (since openwrt doesn't have a package for it) and was able to just drop it on with minimal problems.

Re: Mmm, Pi-hole

#198
post #108
post #95

Earlier quoted context omitted.

That's not always true. Check out the new GMail, my new corporate account has no ads but it still weighs in at 25MB (well 28MB now - still asyncing stuff!) for the inbox. In this case, the largest resources are Javascript and CSS (yes 1.2MB CSS files!). The weird thing is that it appears to be making requests with different cache-busting strings and getting resources that are the same size. (32MB now, I haven't done…

> Check out the new GMail, my new corporate account has no ads but it still weighs in at 25MB (well 28MB now - still asyncing stuff!) for the inbox. The new gmail is the slowest web app I have ever used. It's gotten so bad I've started managing my email on my relatively snappy inbox iOS client. It wouldn't be so bad if they didn't load so much crap, like the gchat functionality nobody has used since 2008.

Agreed 100%. Just getting it to load takes forever, and Google Calendar sometimes never renders for me (on latest Chrome for OSX-1).

Re: Mmm, Pi-hole

#199

I'm surprised this is the top slot right now. Troy, generally, puts out interesting info on security related news however this feels a bit minimal. Since the project has been around a number of years now, and it's not relegated to only a RPi I would have expected him to delve into things a bit more. Pi-hole will also break things. I think the common one I always heard from users on my network at home were that Google…

The simplest approach is to use a hosts file: https://someonewhocares.org/hosts/

There's also Steven Black's host file:

https://github.com/StevenBlack/hosts

Re: Mmm, Pi-hole

#200

My Pi-hole with updated block lists (blocking trackers as well as ads) sits at around 87.7% requests blocked, which is absolutely mind-blowingly ridiculous. I see absolutely no negative effects browsing like this. Everything I've come across still works fine. Even sites that detect uBlock Origin and tell me to disable it, will work with that disabled and Pi-hole still blocking the ads instead. I heavily believe we sh…

I use a /etc/hosts-based ( https://github.com/StevenBlack/hosts ) approach to add blocking across my machines, but I have found some sites (fansided.com) comes to mind, which detect that I'm blocking and won't let me read them. How easy is it to get around this with the pi-hole?

Very easy. You can pause it for 10s, 30s, 5mins, or a custom timeframe via the dashboard, or whitelist domains/subdomains as well. You basically do everything via a very slick dashboard running locally on its IP.
Post reply on HN