Live data from Hacker News

AdGuard Home: Network-wide ad- and tracker-blocking DNS server

github.com

151–160 of 258 posts

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#151

Standing reminder that any device smart enough to run a real web browser shouldn't use one of these and doesn't need one. uBlock Origin works much better for any device capable of running it, both in terms of user experience (the browser understands a block rather than a mysteriously failing request) and because it can block first party ads and clean up page layout. The primary use case for these is for blocking ads…

> Standing reminder that any device smart enough to run a real web browser shouldn't use one of these and doesn't need one.

Why not? Or why not use both?

> The primary use case for these is for blocking ads on devices that don't allow running a real browser and yet still shows ads, such as "smart home" devices, TVs, etc.

What about non-browser apps on mobile devices or even desktops? Lots of apps have invasive ads and are unlikely to offer an extension api to block them with.

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#152
There are a few mostly positive comments here about NextDNS but I'll start a new comment since I'm thinking about switching away from NextDNS. Why? I'm on a Mac / Safari now and would like to enable their "Hide IP address from trackers" feature but if I do, then I start seeing advertisements on websites that would normally be blocked by NextDNS. So I have to uncheck this option and can't use Apple's feature. Overall, I guess the two can't be used together, per an issue reported on the NextDNS Help site:

https://help.nextdns.io/t/q6yq4xy/nextdns-stops-working-prop...

Does anyone by chance know if this is a known issue with AdGuard or even Pi-hole?

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#154
post #25

Don't do this. Network firewalls are harmful. Let people configure their own firewalls on device. Having to VPN around network blocks is annoying to say the least. Network firewalls are harmful and just a lazy excuse for bad client security.

Is it easier to configure a firewall on my iPhone than I think?

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#155

Earlier quoted context omitted.

I believe this only works if your ad blocking DNS is configured to return 0.0.0.0 for all blocked domains rather than NXDOMAIN, since then services might try using the secondary DNS instead and that would result in nothing getting blocked. Ideally your secondary DNS should be a copy of the primary.

do you know if pihole or Adguard can configured to support confirming to the router or the client that resolution took place, rather than try the secondary DNS. If i understand you correctly, if you have a blocking internal DNS running pihole or Adguard and an external general DNS such as google or cloudflare, unless what you described can be configured, the requests that come back "blocked" from pihole would then si…

AdGuard Home should by default be configured to return 0.0.0.0, you can check whether that's the case in Settings -> DNS Settings -> scroll down to Blocking Mode. I don't know about Pi Hole but it probably also has a similar setting.

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#156

Earlier quoted context omitted.

I'm curious what issues you ran into with Pi-hole? I was running my instance for years without a single hiccup. I ended up moving to AdGuard Home about a year ago though because I wanted to run it on my OPNSense box. I have an automatic WireGuard VPN set up on my devices to VPN into my home network when I'm not connected to my SSID, so my local DNS still works remotely.

SD card corruption that just slowly started degrading the results, twice. For the price of a single Pi, I can get NextDNS ad protection for _all_ my devices for multiple years. No matter where they are.

Running pihole on a Pi is severely overrated.

I run it on my NAS Linux server (in a Docker container) where I have a bunch of other things. Zero problems, now using it for more than two years.

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#157
post #3

I ran a competing project[0] on my home network for a few years before I discovered NextDNS[1]. What I lost in performance (requests don't leave my house) I gained in portability: ALL my devices can take advantage – at home and away – and time-saved. PiHole works 90% of the time, but when it did stop working, I'd have to spend a bit of time fixing it. At $20/year, I simply couldn't compete with NextDNS. Note: This is…

Another great (and free!) option is Mullvad’s ad-blocking DNS over TLS or HTTPS. https://mullvad.net/en/help/dns-over-https-and-dns-over-tls

[deleted]

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#158

I'm experienced in DNS but have never seen the point in DNS blocklists. It feels like the wrong layer. I do adblocking with a browser extension. The adblocking has more context, can modify the page, and has easy UI integration for debugging and turning it off. What else are DNS blocklists for? Clients except browsers? For the record, on my desktop I use systemd-resolved (for DNSSEC) and dnscrypt-proxy2 (for encryptio…

I enjoy having ads blocked in apps and on my iPad, where ad blocking is extremely limited otherwise. If you look at the logs from your media box, (whether that is your TV, Roku, or whatever) there's a massive amount of tracking that gets sent up. Combined with Tail scale I can even block ads and tracking on my devices when I'm not home.

Thanks I understand now.

All my devices are plain Linux distro machines, or Android.

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#159

Earlier quoted context omitted.

I'm curious what issues you ran into with Pi-hole? I was running my instance for years without a single hiccup. I ended up moving to AdGuard Home about a year ago though because I wanted to run it on my OPNSense box. I have an automatic WireGuard VPN set up on my devices to VPN into my home network when I'm not connected to my SSID, so my local DNS still works remotely.

> I have an automatic WireGuard VPN set up on my devices to VPN into my home network when I'm not connected to my SSID, so my local DNS still works remotely. Exact same setup for me also. I also run Tailscale since I have run into some remote networks that blocked wireguard's port.

How's the latency?

I like the idea and might set that up but my residential ISP doesn't have great peering and latency isn't great. I wonder if that extra roundtrip would be noticable or not.

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#160
post #3

I ran a competing project[0] on my home network for a few years before I discovered NextDNS[1]. What I lost in performance (requests don't leave my house) I gained in portability: ALL my devices can take advantage – at home and away – and time-saved. PiHole works 90% of the time, but when it did stop working, I'd have to spend a bit of time fixing it. At $20/year, I simply couldn't compete with NextDNS. Note: This is…

I'm curious what issues you ran into with Pi-hole? I was running my instance for years without a single hiccup. I ended up moving to AdGuard Home about a year ago though because I wanted to run it on my OPNSense box. I have an automatic WireGuard VPN set up on my devices to VPN into my home network when I'm not connected to my SSID, so my local DNS still works remotely.

> I'm curious what issues you ran into with Pi-hole?

My primary problem with Pi-hole or any other DNS-based blocker is that it silently breaks things. YouTube stopped saving my spot in videos. I couldn't click through on any link that involved a tracking service.

These things accomplish their stated task well, but leave behind an insidious trail of browser errors, broken pages, and broken apps without ever indicating to the user what the cause of the problem really is.

DNS just isn't the right tool for fixing shitty UX in the browser DOM or a mobile app. It's a happy coincidence that it works more often than not.

Post reply on HN