Live data from Hacker News

Mmm, Pi-hole

troyhunt.com

351–360 of 421 posts

Re: Mmm, Pi-hole

#351
post #94

Earlier quoted context omitted.

Can anyone recommend a "2018 good choice" for a consumer router that can run custom firmware (including dnsmasq), or a trustworthy recommendation website? Wirecutter for example doesn't note third party firmware: https://thewirecutter.com/reviews/best-wi-fi-router/

I’ve been also searching for recommendations, particularly on a custom firmware router that allows me to host a VPN server.

It’ll be more involved for you to set up, but pfSense is what I use. I basically forget it’s there until I want to change something (add a new VPN user, monitor bandwidth usage). I’ve set up an IPSec VPN that works well with my Apple devices, especially with a configuration profile that enables on demand VPN (connect via VPN when certain conditions are met, like not on my home WiFi). For hardware I use a cheapish “industrial” computer from AliExpress. Probably not the best thing security-wise (no firmware updates in the past few years, it feels like it’s just shipped directly from a random factory in China), but it’s been great so far.

Re: Mmm, Pi-hole

#352

1) What would be the quickest way to get a either a Pi-hole device or a router supporting that level of functionality (ad-blocking, and DNSCrypt) into the hands of normal consumers on a mass scale (e.g. completely non-technical users like my parents or grandparents)? 2) I know my next suggestion goes against net neutrality, but what would stop an ISP from doing something similar at the level of their router (or clust…

>What would be the quickest way to get a either a Pi-hole device or a router supporting that level of functionality (ad-blocking, and DNSCrypt) into the hands of normal consumers on a mass scale (e.g. completely non-technical users like my parents or grandparents)?

Sell it as a turn-key appliance in a box with three ports: Network in, router in, and power. Operate as a transparent proxy, automatically update, web interface on the inside port only, etc etc.

Biggest issue is ensuring it's got enough performance on both Ethernet ports to not bog down traffic.

Re: Mmm, Pi-hole

#353

Earlier quoted context omitted.

And if you’re that way inclined, a POE Pi hat can get another cable removed.

Have they fixed the PoE issues? http://linuxgizmos.com/refund-offered-for-raspberry-pi-poe-h...

I wasn’t aware of that - thanks. I think I’ll be safe as there will be no peripherals plugged in, but that’s something that needs considering it seems.

Re: Mmm, Pi-hole

#354

Earlier quoted context omitted.

It’s essentially dnsmasq which can be run directly on your wireless router if you are using custom firmware. No separate hw needed, no need to horse around with dockers or containers or any of that stuff. I’d guess a lot of people are already running dnsmasq for other purposes, so adding the blocklist and periodically updating it should be trivial.

Yeah, on openwrt you just install the adblock package https://github.com/openwrt/packages/tree/master/net/adblock/...

Do you know if it’s possible to deploy it on a virtual AP? E.g. have “MyNetwork” and “MyNetworkWithAds” - so that it is easier for nontechnical users to switch, and also doesn’t deactivate for everyone when just one user needs to (even if only for 5 mins)?

Re: Mmm, Pi-hole

#355
post #264

Earlier quoted context omitted.

Cable sucks because the revenue comes from the ads, not your cable bill.

Which is interesting because that is the environment where paid ads have the least structural advantage. My take is that no matter what people say they prefer to subsidize their content by viewing ads over actually paying the equitable price for it.

Nope. People _say_ they want to pay an equitable price for content rather than viewing ads because that's exactly what they prefer and would do.

The problems are:

- Your definition of 'equitable price' when we live in a time where no single human can digest across their lifetime even a single year's worth of the glut created.

- The quality is universally garbage and as an information consumer you'd still have to spend your resources in thinking critically whether to accept and update your assessment of the information. If you're consuming 'content' as escapism well then you still might consider a more cost-effective route such as heroin or even direct neural stimulation.

- Consumers rightfully work out the long game plan of content creators. They'd like to not view ads but know that once you've climbed above the threshold of starving artist you'll get greedy and the ads will come right back. Always. No exception.

Re: Mmm, Pi-hole

#356
post #67
post #7

> Do you use a popular browser extension? How confident are you that the creator wouldn’t accept a $10k offer to hand it over only to have it then go rogue on you? What makes the Pi-Hole organization any more trustworthy? (and the software stack it all depends on) Personally, I'm inclined to trust them both and hope that the long arm of the GDPR will be effective. Optimistic, I know.

https://github.com/pi-hole/pi-hole Pi Hole is open source, so if someone did try to sneak in some malicious code, it would be seen.

Seen by what percentage of users who just download the binaries?

Re: Mmm, Pi-hole

#357
post #314

Earlier quoted context omitted.

You are being compensated. You can visit their website and read their content. Feel you're not being compensated enough ? Stop visiting that site.

You are being compensated...but you are not being informed for what. As an example, lets say you borrow my truck. You compensate me for the use of my truck to move some boxes in town. But then you use my truck to tow a trailer across the country. That is more wear and tear on the vehicle. And then you take my personal information that is on my vehicle registration with my home address and sell that to an ad company.…

Except it is nothing like that.

Re: Mmm, Pi-hole

#358

I'm surprised this is the top slot right now. Troy, generally, puts out interesting info on security related news however this feels a bit minimal. Since the project has been around a number of years now, and it's not relegated to only a RPi I would have expected him to delve into things a bit more. Pi-hole will also break things. I think the common one I always heard from users on my network at home were that Google…

I assume DoH is dns over http, what is DoT?

DNS over TLS

Re: Mmm, Pi-hole

#359

Earlier quoted context omitted.

Have they fixed the PoE issues? http://linuxgizmos.com/refund-offered-for-raspberry-pi-poe-h...

I wasn’t aware of that - thanks. I think I’ll be safe as there will be no peripherals plugged in, but that’s something that needs considering it seems.

I've gone the route of using another box to do PoE -> 5V USB, but unfortunately the TP-Link converter is outputting 4.8V instead of 5V (the Pi3b will technically run on this, but it's not a good idea).

Re: Mmm, Pi-hole

#360

I'm surprised this is the top slot right now. Troy, generally, puts out interesting info on security related news however this feels a bit minimal. Since the project has been around a number of years now, and it's not relegated to only a RPi I would have expected him to delve into things a bit more. Pi-hole will also break things. I think the common one I always heard from users on my network at home were that Google…

I assume DoH is dns over http, what is DoT?

[deleted]
Post reply on HN