Earlier quoted context omitted.
You can change your DoH resolver, so you could setup a raspberry pi as a DoH server theoretically, and still keep the benefits of a PiHole. Mozilla is making CloudFlare the default but they aren't forcing it, you can use another server.
You can change it on web browsers, for now, but not on IoT devices.
Cname cloaking, a disguise of third-party trackers
71–80 of 202 posts
Re: Cname cloaking, a disguise of third-party trackers
#72Use a Pihole + your adblocker of choice - defense in depth. It's easy to set up, brainless to keep updated, and helps to protect all devices on your network, not just the things that can run uBlock. I've got mine running in a Docker container, which upstreams to a stubby container, which gets DNS-over-TLS, so I get adblocking and DNS query encryption out to Cloudflare for the whole network, and it's really not all th…
Check this article, pi-hole can’t block this yet: https://medium.com/nextdns/nextdns-added-cname-uncloaking-su...
In general though, DNS filtering + client filtering is an awesome combo.
Re: Cname cloaking, a disguise of third-party trackers
#73Earlier quoted context omitted.
You can change your DoH resolver, so you could setup a raspberry pi as a DoH server theoretically, and still keep the benefits of a PiHole. Mozilla is making CloudFlare the default but they aren't forcing it, you can use another server.
You can change it on web browsers, for now, but not on IoT devices.
Re: Cname cloaking, a disguise of third-party trackers
#74Earlier quoted context omitted.
Do you think ad companies will really trust reverse-proxied ad traffic? Seems like a tremendous opportunity for fraud. Right now with user agents hitting ad servers directly, there's much less opportunity for content publishers to fake impressions and clicks.
When user agent clicks the ad, that's how the ad companies know it's real.
Re: Cname cloaking, a disguise of third-party trackers
#75Use a Pihole + your adblocker of choice - defense in depth. It's easy to set up, brainless to keep updated, and helps to protect all devices on your network, not just the things that can run uBlock. I've got mine running in a Docker container, which upstreams to a stubby container, which gets DNS-over-TLS, so I get adblocking and DNS query encryption out to Cloudflare for the whole network, and it's really not all th…
That will only work for so long, as more and more browsers are forcing DoH for "privacy" on users, making them bypass traditional DNS in-favor of DNS over HTTPS to a provider selected by the Browser removing user control Mozilla for example is going to force everyone to use CloudFlare as a Resolver
https://twitter.com/selenamarie/status/1175092910200483840?s...
Re: Cname cloaking, a disguise of third-party trackers
#76The easiest way for site-owners to delegate control has been to include third-party javascript. With new browser restrictions, we're starting to see companies switching to loading JS via CNAMEd subdomains, because that's nearly as easy. The next step is probably reverse proxies, though, where the third-party JS comes from the same server that gives you the rest of the site's JS. (Disclosure: I work in ads; speaking o…
Re: Cname cloaking, a disguise of third-party trackers
#77Earlier quoted context omitted.
Check this article, pi-hole can’t block this yet: https://medium.com/nextdns/nextdns-added-cname-uncloaking-su...
I personally setup nextdns for 30+ people. It is that simple and useful. Thanks. I've a couple of questions, though: 1. Do you run one unbound instance per configuration, or share among multiple configurations per user or...? The reason I ask is, sometimes the latencies are too high, 2000ms+. Should I be creating less configurations per account? 2. How could nextdns combat ad-networks resorting to DoH: https://1.1.1.…
Re: Cname cloaking, a disguise of third-party trackers
#78The easiest way for site-owners to delegate control has been to include third-party javascript. With new browser restrictions, we're starting to see companies switching to loading JS via CNAMEd subdomains, because that's nearly as easy. The next step is probably reverse proxies, though, where the third-party JS comes from the same server that gives you the rest of the site's JS. (Disclosure: I work in ads; speaking o…
Honest question, and I'm not making any value judgements: Do you have any moral issues working an adtech?
Re: Cname cloaking, a disguise of third-party trackers
#79Earlier quoted context omitted.
That also means most of their audience blocks ads. What are they to do?
Start providing content that users are willing to pay for?
In most cases, people don't want to commit a portion of their monthly budget to a specific website for the rest of their life. I don't know how often I read Ars Technica, but it's probably a couple of articles a month. That is worth maybe $0.10 to me, so they can never collect that profitably. They use ads because then I "pay" whenever I visit, without having to approve any payment. More people visit, they automatically get more money.
I wish there were some sort of globally-accepted micropayment system. With the billions of cryptocurrencies floating around, it surprises me that nobody has attempted this yet. I buy $10 of cryptocurrency. It gets loaded into my web browser. The webserver says "hey, you have to pay for this". My browser asks me if I want to do that. If I pick yes, then the server sends me the rest of the HTML after it agrees that the money was in fact transferred.
(The closest thing I've seen to this are Twitch "bits". That is a micropayment platform that seems to be working pretty well, but it's used by the same people that want to pay their favorite content creators a stipend and so real-money recurring subscriptions are just as good. For that reason, I'm not sure we can infer much from that model, except that people will buy value in bulk and then dole it out to individuals at random intervals... which is pretty interesting if you think about it.)
I think what is stopping this from being a thing is not any technical issue, but rather just greed from the content creators. I am sure that anyone that sells a subscription service is making money from people that have forgotten to cancel or don't get the maximum value out of their subscription, and it's probably a lot of money. Nobody is going to give that up.
I also think advertisers pay too much for ads. I bet the "brand awareness" ads aren't worth nearly as much money as they pay. Meanwhile, publishers are making a lot of money off of selling impressions, and are probably hesitant to turn off free money from dumb people. Remember, serving an ad requires no input or investment from the end user; the website loads, they get money. If there were "brakes" applied every so often ("are you sure you want to pay the content creator using your real-world hard-earned cash?") revenue would go down.
So I think the problems here are:
1) Advertisers want to advertise. If you remove your publication from the list of places where they can get something advertised, they'll go elsewhere. The money won't be removed from the ecosystem, and your competition will be enriched. That's not strictly a PROBLEM, but your investors will not be making happy faces at you when you leave money on the table. Only some sort of law could change that, and there will never be any such law.
2) Publishers are making a lot of money on unused subscriptions, so they continue to push subscriptions over micropayments.
A lot of people are making content worth paying for. It's just that we can't afford it, but the advertisers can.
Re: Cname cloaking, a disguise of third-party trackers
#80Earlier quoted context omitted.
As I understand it, ad companies and the people who sell their websites to ad companies have some base level of distrust of one another, which has kept them from integrating like this. Ad companies want to serve the code to be sure that no click fraud is occurring, and people who run websites don't want to completely hand over their domain. But it's easy to see them forging this alliance if ad delivery depended on it…
What if they didn't need to trust the website operators because they only pay them if users click? When the user clicks, it goes through the ad company's domain with the Referrer who would be paid for it.
Ad companies could move to only paying when ads result in a sale, but that only works if there's a sale that can be tracked. If I click a BMW ad and then buy one in the showroom that's really hard to track.