I somewhat wished that when Chrome switches to manifest v3, uBlock Origin would stop supporting Chrome and its clones. Firefox is the only browser where uBlock Origin is actually working as intended, Chrome on the other hand (even in manifest v2) is blocking so many features that uBO isn't actually able to work as a privacy and anti-malware tool. CNAME uncloaking is essential because websites can counter any filter r…
By not using recursive DNS, including open resolvers or other third party DNS providers, I avoid this problem. I do not need to maintain a list of domains to block,^1 I only need to maintain a list of domains for hosts that I actually want to access. I do not even make remote DNS lookups because generally I already have the DNS data stored (gathered in bulk beforehand), so the web becomes faster, not slower. One of the requirements for the web to suck the way it does, and for so-called "tech" companies to proliferate by collecting data and selling ad services, is that the web browser and webpages must be give free reign to resolve any domain name. IME over nearly 20 years of controlling own DNS, restricting that ability makes the web instantly readable, even so-called "dumpster fire" webpages.
1. AFAICT no one actually does this anyway. They delegate the task to third parties, "blocklist" maintainers.