Live data from Hacker News

AdGuard Home: Network-wide ad- and tracker-blocking DNS server

github.com

241–250 of 258 posts

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#241
post #147

Earlier quoted context omitted.

This looks great. Qs: this says “ Technitium DNS Server is an open source authoritative as well as recursive DNS server” Are pi-hole/Adgyard also recursive DNS server or just a blockers? Edit: I’ve been using pi-hole for ages, trying to figure out if this has any advantage.

Can't speak to Adguard: PiHole isn't natively recursive, but you can easily set up a service alongside pihole on the pi (or in another docker, if your pihole is a container) called Unbound which provides recursive DNS.

Thanks, I’ll take a look at Unbound. I have it running on a Pi.

I had a pfsense, which died a few days ago while upgrading from 2.6 to 2.7. I believe it was running Unbound.

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#242
post #209

Earlier quoted context omitted.

Couldn't you just monitor the query log and whitelist domains that were false positives?

"Just" is doing a lot of work in that sentence. That sounds like a lot of work, and it isn't always obvious which weirdly-spelled domain is causing the issue.

> "Just" is doing a lot of work in that sentence

Not really. You can pull your phone out and do it in less than a minute

> it isn't always obvious which weirdly-spelled domain is causing the issue

It typically /is/ pretty obvious. You can drill down to the device making the request, and it becomes obvious once you see the blocked query

To each their own though. I personally don't want to pay a company to do something for me that I can do myself.

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#243
post #3

I ran a competing project[0] on my home network for a few years before I discovered NextDNS[1]. What I lost in performance (requests don't leave my house) I gained in portability: ALL my devices can take advantage – at home and away – and time-saved. PiHole works 90% of the time, but when it did stop working, I'd have to spend a bit of time fixing it. At $20/year, I simply couldn't compete with NextDNS. Note: This is…

Can nextDNS differentiate between clients coming from the same public IP? Do you get individual DNS IPs?

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#244

Earlier quoted context omitted.

Except all of these third party VPN and DNS type services are literally NSA honeypots and privacy nightmares. I get that you have to do DNS lookups somewhere, but I'm not going to make it ridiculously trivial for a bad actor to scoop up all that data conveniently in a central location.

Mullvad is an NSA honeypot? Got any sources on that?

NSA tapped the phones of the German Prime Minister.

They are the same spooks that intercept router gear in transit, flashed it with secret firmware, then put it back in the mail. Like, of course the United Stated Intelligence apparatus, agencies with an unlimited budget, a national security mission, and is completely exempt from all laws has 100% capability to spy on some tiny company in Sweden.

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#245
post #236

Earlier quoted context omitted.

It’s open source software. MacPaw lists Russian-developed software as a risk because the government can access your data at any time — this is self-hosted open-source software though. The FSB can’t just access your local server with an arbitrary court order. Therefore this doesn’t feel like a legitimate concern but more like Russophobia, which I understand but also think is utterly unasked for as I know first hand ho…

You're swapping out your DNS for a Russian controlled DNS service. Seems dumb IMO.

Russian controlled? It runs on your network and it's open source. Where is the "russian control" on this?

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#246
post #221

Earlier quoted context omitted.

Technically, yes you can. But do you really have the time to sit down to understand a piece of software enough to know if it's doing anything nefarious?

It only takes one obfuscated line of code buried somewhere deep where you wouldn't expect it.

True. But I think they have the means to do that on a lot of (non-russia-associated) repositories. They even probably wouldn't pick this one because it's under too much scrutiny.

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#247

Earlier quoted context omitted.

You're using one product that blocks ads and trackers, but then bypassing that with another product that deliberately provides access to ads and trackers, but via a third party. What is the point of the latter?

I subscribed + configured my router to use NextDNS years ago so ads + trackers are blocked on my IoT devices. More recently, I inherited a MacBook and now an iPhone and naturally enabled their built-in blocking capabilities. I think I assumed two blockers are better than one but now I just leave Apple's IP limiting features off and let NextDNS do its thing but it just feels weird to deliberately turn off a privacy fe…

This is not two ad blockers. One is an ad blocker the other is a tracking blocker. They conflict simply.

If you want both across all apps (not just the Browser) you need a VPN service with included as locking, such as protonVPN, IVPN, Etc. There are a lot.

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#248
post #3

I ran a competing project[0] on my home network for a few years before I discovered NextDNS[1]. What I lost in performance (requests don't leave my house) I gained in portability: ALL my devices can take advantage – at home and away – and time-saved. PiHole works 90% of the time, but when it did stop working, I'd have to spend a bit of time fixing it. At $20/year, I simply couldn't compete with NextDNS. Note: This is…

NextDNS sends EDNS client subnet (ECS). If challenged on privacy grounds they can claim it is for performance but a primary benefit of ECS, whether intentional or not, is to serve online advertising interests.^1

1. Dishonest people might try to debate intentionality. But forseeability is indisputable. The privacy issues created by ECS were known when it was introduced by Google. If ECS is truly for performance _that benefits the user_ then it stands to reason that it should the _user's_ choice whether to send it. That is, ECS should be optional. This is not merely a personal opinion. It was a consensus. See: https://yacin.nadji.us/docs/pubs/dimva16_ecs.pdf AFAIK, NextDNS, like Google and OpenDNS, will not allow any user to disable sending ECS.

For example, Cloudflare when it launched 1.1.1.1 decided not to send EDNS subnet and they have claimed this is based on privacy grounds.

Whether anyone cares about privacy is their business, not mine. And whether anyone believes ECS improves peformance for them is for them to decide, not me.^2 Here I am just presenting some facts for consideration. Anyone is free to disregard these facts.

2. When considering "performance" we might differentiate between performance in requesting the resource the user is trying to access versus performance of ad servers or tracking servers. Needless to say, ads are not the resource the user is trying to access. And tracking is not even a resource. The speed of ads and tracking are obviously very important to Google, the company behind ECS. When we see a campaign for a "faster internet" from so-called "tech" companies such as Gooogle and Facebook we should keep in mind that "the internet" as envisioned by these middlemen is an internet full of advertising and tracking. As such, "faster internet" does not necessarily mean better speeds when downloading a resource. Ads and tracking are the not resources that users are intentionally requesting. They only serve to add delay and impede the user's retrieval of a desired resource. Hence the need for "ad blocking".

Personally, I do not use third party DNS services, i.e., shared DNS caches operated by third parties. Historically these shared caches are the source of various problems. There are plenty of alternatives available today what with the enormous advances in network speeds and local storage that have occurred since the days when shared DNS caches were a necessity. For example, all the DNS data I use is stored locally and served from loopback addresses, either in the memory of a forward proxy or from authoritative DNS servers. Requests never leave the computer. (NB. PiHoles send requests to upstream third party DNS providers by default. Unless the parent commenter changed the PiHole's i.e., dnsmasq's, configuration to use a local DNS server serving locally stored DNS data then requests would by default be sent to the internet. In the case the configuration is changed to point to a local DNS server serving local DNS data and the user is satisfied with DNS-based blocking, like what NextDNS provides, then the utility of a PiHole would be questionable. Just omit DNS data for ad/tracking servers. I have been doing this for decades; I began using DNS for "blocking" before "adblockers" or PiHole existed.)

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#249
post #206

Earlier quoted context omitted.

I think it's weird when people suggest that a self-hosted on-prem solution requires no maintenance and has so little downtime such that the time spent fixing issues doesn't matter. I run a bunch of local services on RPis and a decade-old Mac Mini. I love having the control over things, but I don't pretend I don't spend a decent amount of time maintaining it. I only run things that don't need to be highly available, s…

> I love having the control over things, but I don't pretend I don't spend a decent amount of time maintaining it. I don't know the nature of your maintenance, but I've had unattended security updates working for years, I automated a bunch of stuff and use etc-keeper. > I only run things that don't need to be highly available Redundancy helps. 2 (more!) RPis cam be primary/secondary/tertiary DNS servers to match para…

Oddly I found myself upvoting this comment AND the parent. Neither are wrong. There is no right or wrong on this subject.

$20 a year spent on a hand-rolled RPi that you have full control over and enjoy tinkering with—amazing value!

$20 a year for something like NextDNS so you can spend your time worrying about more important (to YOU) things, amazing value!

It's wondrous the choices we have today. 30 years ago it would have taken a rack full of noisy servers and a few thick books to keep a DNS service up and running at anything even close to 99%.

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#250

Earlier quoted context omitted.

I subscribed + configured my router to use NextDNS years ago so ads + trackers are blocked on my IoT devices. More recently, I inherited a MacBook and now an iPhone and naturally enabled their built-in blocking capabilities. I think I assumed two blockers are better than one but now I just leave Apple's IP limiting features off and let NextDNS do its thing but it just feels weird to deliberately turn off a privacy fe…

This is not two ad blockers. One is an ad blocker the other is a tracking blocker. They conflict simply. If you want both across all apps (not just the Browser) you need a VPN service with included as locking, such as protonVPN, IVPN, Etc. There are a lot.

but NextDNS' own homepage says it "blocks ads and trackers on websites and in apps" - https://nextdns.io
Post reply on HN