this post was submitted on 10 Feb 2025
60 points (100.0% liked)

Privacy

800 readers
72 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

I want to block ads and trackers on the whole home network. I’ve been using adblockers and trackers for years now; I currently have a Raspberry Pi. I was thinking of setting up Pi-Hole with AdGuard. Any other suggestions are welcome. (I can’t use a custom router, because my ISP doesn’t allow it)

top 16 comments
sorted by: hot top controversial new old
[–] melroy@kbin.melroy.org 12 points 2 weeks ago (2 children)

You want the truth? Setup OPNsense firewall on your network. Add EasyPrivacy, EasyList, AdGuard List and other blocklists to the Unbound DNS service on the OPNsense server.

Then configure your DHCP to use the OPNsense router/firewall IP (eg. 192.168.1.1) as DNS server in DHCP provisioned computers on your LAN network.

This is how I do it and it's an enterprise setup, which works and scales really well.

[–] Majestic@lemmy.ml 4 points 2 weeks ago

As an extra step you can block DNS requests to external services from within your network to prevent devices trying to reach hardcoded for example Google DNS servers to bypass your filtering which isn't uncommon with some IoT/streaming devices. Best to both block the known IPs as well as have DNS redirects for the urls that point back to your firewall at whatever IP it's using to serve DNS from. There is a list called DoH servers by name or something like that which you can add to the blocklist to try and prevent usage of any DNS but your own.

[–] tetris11@lemmy.ml 1 points 2 weeks ago (1 children)

Do you have any lies to offer?

[–] melroy@kbin.melroy.org 4 points 2 weeks ago (1 children)

Do you want a lie? 2+3 = 8

[–] tetris11@lemmy.ml 1 points 2 weeks ago (1 children)

that's terrible, shame on you

[–] melroy@kbin.melroy.org 2 points 2 weeks ago

Nintendo once had to patch Tetris because players were stacking blocks so perfectly that the game started running out of pieces and crashed.

[–] supervent@lemmy.dbzer0.com 8 points 3 weeks ago

I use Adguard's public DNS on my router for convenience, no problems at all. In the past I had pi-hole with some lists that in the end, from time to time, broke things.

[–] Corgana@startrek.website 6 points 2 weeks ago

OP if you enjoy a fun weekend project, don't go with a pi-hole. It literally only takes about 5 minutes. Also I recommend the blocklistproject lists https://blocklistproject.github.io/Lists/

[–] Xanza@lemm.ee 4 points 2 weeks ago* (last edited 2 weeks ago)
Light + TIF                     https://sky.rethinkdns.com/1:AAkACAQA
Normal + TIF                https://sky.rethinkdns.com/1:AAkACAgA
Pro + TIF                 https://sky.rethinkdns.com/1:AAoACBAA
Pro plus + TIF               https://sky.rethinkdns.com/1:AAoACAgA
Ultimate + TIF              https://sky.rethinkdns.com/1:gAgACABA

Light + TIF                 https://dns.dnswarden.com/00000000000000000000048  
Normal + TIF                 https://dns.dnswarden.com/00000000000000000000028  
Pro + TIF                 https://dns.dnswarden.com/00000000000000000000018  
Pro plus + TIF               https://dns.dnswarden.com/0000000000000000000000o  
Ultimate + TIF              https://dns.dnswarden.com/0000000000000000000000804  

Light                https://freedns.controld.com/x-hagezi-light
Normal                https://freedns.controld.com/x-hagezi-normal
Pro                https://freedns.controld.com/x-hagezi-pro  
Pro plus                https://freedns.controld.com/x-hagezi-proplus  
Ultimate                https://freedns.controld.com/x-hagezi-ultimate
TIF                https://freedns.controld.com/x-hagezi-tif

DNS based adblocking with Hegezi blocklist and TIF (threat intelligence feeds). Works with any device on your network in one way or another (QUIC, DoH/3, DoT, etc) and doesn't require installing anything. Just changing dns settings.

This is a great list. Blocks about 95% of all advertisements. About 4% are unblockable due to one reason or another, and the remaining 1% get added very quickly. I highly recommend this solution. Sure, you can setup a PiHole and do it all yourself, but in the end that requires time and attention. It's the same list, but if you roll PiHole yourself you don't get access to TIF, which are amazing for protecting you from different kinds of threats.

[–] shortwavesurfer@lemmy.zip 4 points 3 weeks ago

Controld.com is what i use and it works great.

They have one server that blocks nothing, one server that blocks known malware, one server that blocks known malware and advertising and tracking, and a server that blocks all of that, including social media. And they are all free.

[–] sic_semper_tyrannis@lemmy.today 4 points 3 weeks ago

Make a NextDNS with the settings/features you like and add that as your router's DNS service. Super simple

[–] kekmacska@lemmy.zip 3 points 2 weeks ago

either pi-hole or or a filtering dnscrypt server

like blahdns-de, odoh-koki-noads-ams

[–] DieserTypMatthias@lemmy.ml 3 points 2 weeks ago

NextDNS or many other DoH services that are out there (I personally recommend Mullvad).

[–] Faceman2K23@discuss.tchncs.de 2 points 3 weeks ago

I use Ad-Guard instead of Pihole because the pi-hole software used to be missing some of the DNS features I wanted at the time, and I just stuck with it ever since. I have the main DNS server running on my Unraid Box, and a backup that runs on my HomeAssistant Pi4B.

[–] JanUwU42@lemm.ee 2 points 3 weeks ago

Either Pi-Hole or there is also AdGuard Home

From what I’ve heard their as good as each other it just comes down on what UI you prefer^^

[–] ertai@programming.dev 2 points 2 weeks ago* (last edited 2 weeks ago)

dnsmasq with a blocklist, like /etc/hosts except you can use wildcards on whole domains. Then you just make your router's default dns to point to the computer running dnsmasq. https://landchad.net/dnsmasq/