Live data from Hacker News

Mmm, Pi-hole

troyhunt.com

241–250 of 421 posts

Re: Mmm, Pi-hole

#241
post #194

Earlier quoted context omitted.

I did not say "a compromised DNS server is completely inconsequential", I said that a compromised WebExtension with :// / and tabs permissions has UXSS (obviously true) and UXSS is worse than compromising DNS resolution. Which one of these is worse: a) I might be able to convince a bad IOT device to connect to an IP I control which may or may not let me do something interesting, -- or -- b) I can just use your sessio…

> The crux of your argument seems to be "it is more valuable to be able to point an IOT device at the wrong IP than it is to get UXSS on a machine on that network". That seems obviously wrong to me for any user, technical or not. If PiHole is malicious, there is already an attacker on your network, DNS Spoofing is just one example of the possible consequences. The PiHole can also port scan, connect to services etc. I…

OK, so there's an attacker on the network in both cases (UXSS and the worst-case-dnsmasq-vuln). So, to compare the two, you look at what else you can do -- and UXSS clearly wins there. "It wouldn't be hard to mount a phishing attack" -- maybe? Except on the most valuable phishing domains, which already have HSTS -- and the UXSS alternative is that I literally control your browser which is clearly worse since I have almost definitionally attained the goal of the phishing attack! And if I really want to just steal your password instead of just using your session, I'm guessing "full control of the DOM everywhere" will help with that.

I have also already argued that an extension does not need to be malicious -- just buggy -- to get UXSS.

Re: Mmm, Pi-hole

#242

Earlier quoted context omitted.

> I heavily believe we should be supporting creators As do I. There's two significant issues I have supporting most sites: 1. They provide only a subscription that is comparable cost to an old-media full subscription. Like most people in the Internet age I have a small number of main sources that I visit daily, and a much larger secondary tier where I may average one or two stories a week. Or they're the sites linked…

I just want to pay a monthly "digital content fee" to some service and have that money be fairly distributed to all the digital services I use: websites, music, video, tools, etc. Is anyone working on a system like that?

Yes, it already exists today, and it's built right into Brave.

https://brave.com/publishers/

Re: Mmm, Pi-hole

#243

Earlier quoted context omitted.

The included dashboard with the pi-hole is incredibly easy to use, so I just have it bookmarked on all our browsers in case someone in my family needs to pause it or whitelist/blacklist a site. We barely ever have to touch it though, mostly just to update the blocklists occasionally.

I was thinking use-cases for house guests or very non-technical folks (what is a bookmark?).

Guest wifi network which doesn’t go through the pi?

Re: Mmm, Pi-hole

#244
post #234

Earlier quoted context omitted.

I just want to pay a monthly "digital content fee" to some service and have that money be fairly distributed to all the digital services I use: websites, music, video, tools, etc. Is anyone working on a system like that?

Personally, I don’t want to pay anything for content. Look at cable tv. It got so bad there is a cord cutting movement. The same will happen again in another form.

I'm confused. You want people to write all content for free? Whilst that works for a lot of people who do it in their spare time, it does restrict anyone looking to write professionally from contributing.

Re: Mmm, Pi-hole

#245

It's easier for me to replicate this functionality myself. I run unbound with a domain name blacklist. Same functionality, no need for additional hardware.

One of the great things about using unbound is how easy it is to blacklist entire domains, without having to know the name of each subdomain ahead of time. I've been doing what pihole does for over ten years using pfSense. I'm up to 437,000 fully qualified domain names blocked, and over ten thousand domains blocked outright. It has been years since I've seen an ad.

Re: Mmm, Pi-hole

#246

My Pi-hole with updated block lists (blocking trackers as well as ads) sits at around 87.7% requests blocked, which is absolutely mind-blowingly ridiculous. I see absolutely no negative effects browsing like this. Everything I've come across still works fine. Even sites that detect uBlock Origin and tell me to disable it, will work with that disabled and Pi-hole still blocking the ads instead. I heavily believe we sh…

> Modern online advertising companies are malicious entities that actively harm users, and I absolutely classify them as malware. This is exactly the response for anyone that is frustrated by blocking ads impacting revenue for web publishers. Had the ad tech not become so invasive and pernicious, users wouldn't be going out of the way for solutions like this. The advertisers have essentially forced our hand.

Where I feel my hand was forced was when a friend wanted help promoting a professional conference in the area of data and tech. I went to the website and, in the center of the page, there was an ad for cellulite cream.

OH! C'MON!!! I believe in the conference, but I'm not going to share the link with that ad on it.

It's been explained to me that the website owners don't know what ads are being served up. All they know is they signed up for an ad service. If that ad is a redirect to a porn site, the website owner has no clue unless people complain.

And that's why I ordered a raspberry-pi to set up a pi-hole.

I get that a lot of my friends won't like this. They're in advertising and marketing, and they insist that they're one of the good ones. Fine. But the bad ones are REALLY bad.

Also. I've spent HOURS opting out of tracking cookies. Then I heard that my effort is only as good as the entities that respect that I opted out. OH? WOW!

So, when I hear people complain that we're hurting them, and they're one of the good ones, it ignores the real problem. Look ...

if I was bitten by 10 dogs out of 50 dogs, I'm gonna have a problem with dogs. Period. You can insist on how friendly your dog is, but no. Talk to the other dog owners before trying to get me to take another risk.

Re: Mmm, Pi-hole

#247
post #240

Earlier quoted context omitted.

I just want to pay a monthly "digital content fee" to some service and have that money be fairly distributed to all the digital services I use: websites, music, video, tools, etc. Is anyone working on a system like that?

I'm surprised no one's mentioned the Brave browser, which operates exactly on the model you describe: https://brave.com/

I'm interested and will read more later. But that should not be built into a browse, at least not exclusively. It feels like it could be an add-on. Of course, preventing gaming and malicious manipulation is something to consider...

This is an interesting problem!

Re: Mmm, Pi-hole

#248

I'm surprised this is the top slot right now. Troy, generally, puts out interesting info on security related news however this feels a bit minimal. Since the project has been around a number of years now, and it's not relegated to only a RPi I would have expected him to delve into things a bit more. Pi-hole will also break things. I think the common one I always heard from users on my network at home were that Google…

On an RPi I can plug it in to the USB on my router for power and connect with ethernet. Otherwise I have to run a full powered server perpetually to manage DNS for the home network. Made sense to me. I stopped using it as mine was seemingly hacked (100,000 lookups or so in a short time, presumably some sort of page-impression generation?) and I hadn't the time to trace if it was a problem with the project or not.

And if you’re that way inclined, a POE Pi hat can get another cable removed.

Re: Mmm, Pi-hole

#249
post #240

Earlier quoted context omitted.

I just want to pay a monthly "digital content fee" to some service and have that money be fairly distributed to all the digital services I use: websites, music, video, tools, etc. Is anyone working on a system like that?

I'm surprised no one's mentioned the Brave browser, which operates exactly on the model you describe: https://brave.com/

Initially, Brave was set up so a user could add bitcoins to an account and set a monthly spending target. Then Brave would split up that monthly amount and send it to sites based on how much time the user spent at each site. But as far as I can tell, they discontinued that model, and now they also sell ads.

Re: Mmm, Pi-hole

#250
post #161

Earlier quoted context omitted.

A lot of these list maintainers put a lot of work into not breaking things, but their are just too many websites out their to know if a block breaks one of them or not. Send the list maintainer an email - or if they are on Github/Gitlab open a ticket and have a discussion. I think you'll find many of them are happy to remove breaking domains. Of course whitelist is always an option too if the list maintainer disagree…

I spoke directly with the pihole maintainers. They took a Hardline position that them blocking email from my city was the right thing to do because it used click tracking or some other metric gathering and was deemed a privacy risk. I understand the devotion to a cause but it was too myopic for me.

As commented below, we don't actually maintain any of the lists, so that wasn't us you spoke to!

You can configure the lists that you use to suit your needs. You can also whitelist any domains that you need. It's up to you what you ultimately block!

Post reply on HN