Live data from Hacker News

All-in-One DNS block list

github.com

11–20 of 56 posts

Re: All-in-One DNS block list

#11
post #9
post #3

I really appreciate projects like this because I'm sure keeping these lists up-to-date is not an easy task, and many people benefit from the efforts. That said: maybe it's just me, but I find their website[1] a bit...strange? It looks like one of those SAAS startup landing pages, you can pick your "pack of block list" ranging from "Tru lite" to "XTreme" etc... Or maybe it's supposed to be ironic and I just don't get…

Ironically their website doesn't work if you block 3rd party JS due to Cloudflare.

I abandoned NoScript because I felt like I spent more time whitelisting JS than browsing the web and other people just couldn't borrow my browser.

NoScript really needs the ability to whitelist a TLD for providers like cloudflare.

Re: All-in-One DNS block list

#12
post #9

Earlier quoted context omitted.

Ironically their website doesn't work if you block 3rd party JS due to Cloudflare.

I abandoned NoScript because I felt like I spent more time whitelisting JS than browsing the web and other people just couldn't borrow my browser. NoScript really needs the ability to whitelist a TLD for providers like cloudflare.

They do? You can globally whitelist urls

Re: All-in-One DNS block list

#13

I have been using NextDNS with a few block lists configured at the router level and device level. The internet experience has improved a lot since ads and trackers are blocked system wide. A few block lists that I would recommend: 1. Steven Hosts - https://github.com/StevenBlack/hosts 2. Adguard DNS - https://github.com/AdguardTeam/AdguardSDNSFilter 3. disconnect.me The amount of DNS requests made silently in the bac…

I'm also using NextDNS and one thing that's a huge boon for me is that the default free tier covers my use case insanely well. Given the statistics for the last 3 months I seem to consistently fly under the free tier limit but if I ever do hit it, it will just default back to a regular DNS. A very user-friendly approach and I hope they keep it as they grow.

Re: All-in-One DNS block list

#19
post #17

This repo has a 3-week track record, by one contributor. Disclosure: Some of us have been actively curating such amalgamated lists for a long time. https://github.com/StevenBlack/hosts

What are the dangers of using a sketchy blocklist?

I'm no expert, but the most obvious answer is "you MITM yourself".

If there is a userbase for a list, they have to trust the list to not filter out domains that shouldn't be filtered. I have a hard time thinking how this could lead to hidden repercussions, other than some security flaw that is only exploitable when some subset of requests go through.

Re: All-in-One DNS block list

#20
post #5
post #2

Are there any Firefox, Ubuntu ppl around? Can you guys bake this stuff (host blacklists) into browser, os autoupdates?

If you're familiar with *nix stuff I'd suggest just run a pi-hole.

if youre not familiar I would suggest it too :)

I've gotten a few friends started on pi hole and ended up with minecraft servers, free nas, kodi, and retropi

Post reply on HN