Live data from Hacker News

Pi-Hole 4.3.2

pi-hole.net

101–110 of 224 posts

Re: Pi-Hole 4.3.2

#101

Earlier quoted context omitted.

Go for it, it's really worth the effort, even if it is a small one, with the bonus of being fun (at least for me it is). I can't imagine setting up my home network without pihole, and I'm considering setting it up at work, I manage a small network with 100 devices connected to the internet.

Can a Pi really keep up with that size of network or would you run it on more powerful hardware/a VM?

As @theandrewbailey mentioned, DNS is light protocol, I guess even older PIs would handle it pretty well. But, as a permanent solution, I would opt to set up on a VM/Docker so that I could have snapshots to quickly recover the service in the event of a problem.

Re: Pi-Hole 4.3.2

#102

The one thing that's holding me back on actually using Pi-Hole is the lack of flexibility. What I'd really like to see is the ability to do various things on a per-client basis. For example, one commenter wanted a simple "reload without blocking" functionality and the response was to use a bookmarklet plus the Pi-Hole API to disable it temporarily. This works, but the problem is that it disables it temporarily for ev…

This is what holds me back from using it too. I would love network wide ad blocking but I hate breaking things for no reason. Sometimes certain websites just refuse to work properly with ublock, mainly comment sections and things like that. With a browser extension I can just click and disable for that site temporarily and be happy. With a Pi-hole it seems like way more of a task if something does not work.

And no, I'm not going to spin up and maintain multiple pi-hole instances on my home network. That crosses into the 'madness' territory, I have enough stuff to maintain as it is.

Re: Pi-Hole 4.3.2

#103

The one thing that's holding me back on actually using Pi-Hole is the lack of flexibility. What I'd really like to see is the ability to do various things on a per-client basis. For example, one commenter wanted a simple "reload without blocking" functionality and the response was to use a bookmarklet plus the Pi-Hole API to disable it temporarily. This works, but the problem is that it disables it temporarily for ev…

One solution is to set up two separate wireless networks with separate VLANs where one uses the pihole for DNS and the other does not. Clients can temporarily switch to the ads network at will. It might not be possible unless you have a decently high-end router. I know DD-WRT or Ubiquiti Unifi gear can do this.

Yup, we do this. Works like a charm and makes it easy to configure from any client by just connecting to a new wireless network.

You don't need the VLAN, you can just put the two different wifi networks on different subnets or DNS config depending on your router and you're good to go.

(I do put IoT stuff on a guest VLAN though which can only see the gateway and nothing local in the network).

Re: Pi-Hole 4.3.2

#104

Donno if this is a silly question or not. But if there anywhere to buy a raspberry + pi with pi-hole pre-configured on it? I've wanted one for a while but just wanna plug it in and go to the web console, not buy it set it up install it etc.

I've found this[0]. [0]: https://uk.pi-supply.com/products/pi-hole-kit-network-wide-a...

Adafruit also sells two pi-hole kits, one with a Pi Zero included and one BYOP (Bring Your Own Pi).

https://www.adafruit.com/product/3973

and

https://www.adafruit.com/product/3974

I am not affiliated with Adafruit nor do I own either of these products.

Re: Pi-Hole 4.3.2

#105
post #20
post #18

Earlier quoted context omitted.

Why four weeks? Surely you could have reached a similar conclusion in a day, or less? Or did you learn anything in that time that couldn't have been learnt in a short burst of unprotected internet activity?

Seemed like a reasonable period of time. I got to see what the difference was on different devices including desktop, laptop, tablet and phone. I also got to see how they were affected for work, study and play over weekends and weekdays. I did notice I started to wait longer for pages to load with the ad's so that I would not accidentally click on them while they loaded in. That and I got generally annoyed by the web…

This has always been my conclusion when I experiment with not using an ad blocker. So many websites with outwise "okayish" content are basically ruined by ads.

Some sites are littered with "targeted" ads like download buttons and similar, which I'm not even sure why that's allowed.

It's also fun on "big" websites like MS Teams, Netflix, hulu, etc, to see the "blocked" count raise into the hundreds.

Re: Pi-Hole 4.3.2

#106

I've had my Pi-Hole for a month now. It's great, but many blocklists are bad. People often use https://firebog.net/ to get their blocklists, and use only those with a checkmark which are, quote, "least likely to interfere with browsing". Bollocks, I've had to disable a few of the recommended ones, and adding manual whitelisted hosts because they were blocking legitimate sites (ocsp.apple.com), blocking Windows update…

I agree that blocking OCSP (Online Certificate Status Protocol) servers is a bad practice. The argument to block them is that they can be used for tracking purposes. OCSP stapling is a great way to use OCSP without the risk of tracking - but not everyone does it or supports it.

Anyways, I maintain an 'Ads & Tracking' blocklist that I believe is pretty reliable and you are welcome to give it a try if you like: https://www.github.developerdan.com/hosts/

I've been maintaining my list publicly for over a year, and I've got to say its not always clear what deserves to be blocked, what should be blocked but can't be due to broken functionality, and what is legitimate like the OCSP servers. Everyone has their own personal level of expected privacy vs functionality. Its impossible to make everyone happy. I just wanted to say that being a maintainer of these lists isn't always easy. The obvious example you provided with (ocsp.apple.com) isn't exactly obvious because it _could_ be used for tracking, and it certainly isn't need for functional reasons (although I would argue that it is needed for security reasons). Anyways, there is a lot of gray when it comes to blocking and you can't make everyone happy.

Re: Pi-Hole 4.3.2

#107

Is this substantially better than using ublock origin? I feel like my browsing experience is pretty good right now, and I'm uncertain what the benefits to upgrading are.

It really depends on what you want/need. The Pi-hole blocks ad traffic by blocking DNS requests to known advertisement URLs. Ublock Origin works great in your browser. However, what about that app on your phone that plays an ad every time you open it? What if you use a mobile browser that doesn't have extensions (Chrome on mobile doesn't).

It really comes down to where you want to block ads.

Also, I don't know if Ublock Origin actually blocks the ad requests or just prevents them from loading, but if it's the latter, then you can reduce traffic with Pi-hole as well.

Re: Pi-Hole 4.3.2

#108

Is this substantially better than using ublock origin? I feel like my browsing experience is pretty good right now, and I'm uncertain what the benefits to upgrading are.

You need to setup ublock origin on every browser on every device. With pihole, all your devices automatically get adblocking, even your friends coming home and connecting to your wifi get the ad blocking advantage without anything to do on their part.

Re: Pi-Hole 4.3.2

#109

Is this substantially better than using ublock origin? I feel like my browsing experience is pretty good right now, and I'm uncertain what the benefits to upgrading are.

No. But it works on all devices in your network (phone, computer, smart TV, WiFi connected dishwasher, etc.). I've never really understood how much tracking some apps on my phone did until I saw the graph showing lookups to Facebook's and Google's servers. In the middle of the night, a bunch of apps started trying to reach some tracking domain, something I would never have noticed if it wasn't for the graphing feature.

One way I've noticed the difference with and without pihole is that most apps on my phone become ad free when I connect to my home network. On most phones ad blockers exist, but those are just another layer of software that needs to be woken when the phone wakes from deep sleep.

I use pihole + uBlock in Firefox with tracking protection (on both mobile and PC) for my browsing, but Pihole saves me the effort of finding a reliable Android system ad blocker that's reasonably power efficient. I'm considering also using it on my laptop as a VM to get the same features on the go.

Re: Pi-Hole 4.3.2

#110

Earlier quoted context omitted.

I run mine at home but have opened it up to be accessible remotely (just port 53 remotely) so I can use it whilst out and about.

Please do not open port 53. Without proper counter-measures, open resolvers contribute to DNS Amplification attacks. If you have an open resolver, I guarantee that it is being used maliciously. Please close your port 53 and use a VPN to securely access your pihole. DNS Amplification Attacks: https://www.us-cert.gov/ncas/alerts/TA13-088A

didn't know about that. I'll give that a read later.
Post reply on HN