this post was submitted on 02 Oct 2023
143 points (96.1% liked)

Privacy

31982 readers
359 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 
top 50 comments
sorted by: hot top controversial new old
[–] IrrerPolterer@lemmy.world 33 points 1 year ago (3 children)

Pi Hole with a few good block lists...

[–] IrrerPolterer@lemmy.world 8 points 1 year ago (5 children)

Also using this on the go through VPN

[–] watson387@sopuli.xyz 6 points 1 year ago (1 children)
[–] Semi-Hemi-Demigod@kbin.social 7 points 1 year ago

Same. Wireguard is a beautiful thing.

load more comments (4 replies)
[–] pacology@lemmy.world 3 points 1 year ago (2 children)
[–] IrrerPolterer@lemmy.world 13 points 1 year ago (1 children)

Out of the box, pihole has a few block lists already set up. Those are pretty good already.

To add more, you can find some good block list collections online. No need to add them all. Pick a good handful, depending on the category of stuff you want to block. Here are some helpful links:

https://firebog.net/

https://github.com/lightswitch05/hosts

... Once you got a few block lists set up, you'll probably want to whitelist some things specifically, that are otherwise caught up in the filter. This is a super helpful resource for that:

https://discourse.pi-hole.net/t/commonly-whitelisted-domains/212

[–] LazerDickMcCheese@sh.itjust.works 3 points 1 year ago* (last edited 1 year ago)

There's a script on github (don't have the link right now) for an automated whitelist. I was expecting it to break some things or end up useless, but it was the perfect addition for me Edit: https://github.com/anudeepND/whitelist

load more comments (1 replies)
[–] user224@lemmy.sdf.org 26 points 1 year ago (1 children)
[–] Albin9326@kerala.party 3 points 1 year ago (2 children)
[–] user224@lemmy.sdf.org 14 points 1 year ago

I was able to test it out first without having to create an account and I liked it. It has simple Ad/Tracking blocklists and supports both DoT and DoH. Also it has rewrites (like /etc/hosts).

[–] Tibert@jlai.lu 10 points 1 year ago

For me, Nextdns. It's mostly because I can choose which list is used by the dns blocking. If adguard has a lost blocking what I use, I can't do anything about it. Or maybe like allow a lot of domains.

Using the Hagezi pro++ list currently and it works damn well without any issues for me.

Also, there is a free way to use it (not sure about adguard).

[–] Platform27@lemmy.ml 25 points 1 year ago* (last edited 1 year ago) (1 children)

Adguard Home. I find it to be more feature complete, compared to Pi-Hole. Nicer GUI, more options, built in DNS-over-HTTPS/TLS, better client controls & detection, more domain information, better domain list blocking, and so on.

I moved from NextDNS, to Adguard Home. All self hosted, and accessed with a reverse proxy.

[–] American_Jesus@lemm.ee 7 points 1 year ago (4 children)

Same, used NextDNS and Pi-Hole then move to AdGuard Home til today.
Built-in (DoH, DoT,...) servers are useful and simple to setup with client identification.

load more comments (4 replies)
[–] EmhyrVarEmreis@lemm.ee 17 points 1 year ago

Adguard home for everything

[–] zwekihoyy@lemmy.ml 14 points 1 year ago* (last edited 1 year ago) (3 children)

nextdns is the most performant option I've used. it often beats our cloudflare even. adguard wasn't bad but it was a bit more cumbersome and very slow.

I don't like recommending self hosting as opening ports on a private network isn't a great idea. you could use something like cloudflare or tailscale to bridge access but you'll run into issues with network speeds.

load more comments (3 replies)
[–] Imprint9816@lemmy.dbzer0.com 13 points 1 year ago (7 children)

Pi-hole for my home network. NextDNS on my phone.

load more comments (7 replies)
[–] possiblylinux127@lemmy.zip 12 points 1 year ago

I just use ublock origin

[–] Anticorp@lemmy.ml 10 points 1 year ago

NextDNS. Easy, free, and effective.

[–] Vexz@kbin.social 8 points 1 year ago

NextDNS because I benefit from it on my phone even when I'm not at home.

[–] chaklun@lemm.ee 8 points 1 year ago* (last edited 1 year ago)

What about Mullwad dns

[–] ShellMonkey@lemmy.socdojo.com 8 points 1 year ago

Adguard home with a few extra lists and custom rules. Just got the sync tool set up to auto replicate changes from one to another so no more copy/paste to a secondary. Great when I need to restart a VM and don't want to take out the internet while it reboots.

Used pihole some while back but the feature list was tiny by comparison, though it was a good while back so probably unfair to compare.

Also ran with pfBlocker for a while, nice to have it right on the gateway but found it a bit opaque and lacking customization for my needs.

[–] vox@sopuli.xyz 8 points 1 year ago

nextds, feels almost like a pihole but unnecessarily crippled in some ways, which don't really matter to me.

[–] toxicyeti@sh.itjust.works 6 points 1 year ago* (last edited 1 year ago) (1 children)

Adguard home for everyone in the house. Externally I just use ublock Origin and Cloudflare's DoH.

[–] Albin9326@kerala.party 3 points 1 year ago (2 children)
load more comments (2 replies)
[–] jeanofthedead@sh.itjust.works 6 points 1 year ago

NextDNS. Several years now. It’s absolutely brilliant.

[–] railsdev@programming.dev 6 points 1 year ago* (last edited 1 year ago)

I roll my own. I created a Docker image that periodically downloads tons of blocklists, smashes them into an Unbound configuration file then runs Unbound with TLS enabled.

On my iPhone and macOS devices I just connect to the encrypted service using .mobileconfig files to apply it system-wide. My home router also uses it as an upstream server (again with TLS) so all connected clients benefit from it as well.

[–] shortwavesurfer@monero.town 5 points 1 year ago

Controld.com

[–] Shape4985@lemmy.ml 5 points 1 year ago (1 children)
[–] djquadratic@kbin.social 4 points 1 year ago

does quad9 block ads as well? I thought it was only trackers

[–] drwho@beehaw.org 5 points 1 year ago

Specifically DNS? I have a Pi-Hole on my home network that is configured as a recursive resolver, and a second Pi-Hole on my personal VPN server (same).

[–] scytale@lemm.ee 5 points 1 year ago* (last edited 1 year ago)

ControlD with AdGuard as backup. Might have to try Mullvad's as well. Then AhaDNS Blitz on my phone.

[–] umami_wasbi@lemmy.ml 4 points 1 year ago* (last edited 1 year ago)

Blocky installed locally as a service for my PC https://github.com/0xERR0R/blocky

RethinkDNS for my phone https://rethinkdns.com/configure

[–] droidpenguin@lemmy.world 4 points 1 year ago

PiHole with the Star Trek web UI theme. I think it looks pretty nice and has worked well for me.

[–] Rooki@lemmy.world 3 points 1 year ago (1 children)

Just use pihole the rest is just a honeypot

[–] fluffery@lemmy.ml 3 points 1 year ago (2 children)
load more comments (2 replies)
[–] lckdscl@whiskers.bim.boats 3 points 1 year ago

Adguard Home on the homelab, with my router set to use it as DNS, alongside Tailscale with Headscale on top to reroute all traffic through the home network so that ad blocking works all the time, on all devices that can use Tailscale, and also away from home.

[–] varaki@lemm.ee 3 points 1 year ago* (last edited 1 year ago)

I'm using controld dns, the oisd full version, legacy dns on the home router and as a private dns on android. I've tried multiple combinations, but this one has a sweetspot for both blocking and usability.

[–] craigevil@lemmy.ml 3 points 1 year ago

NextDNS, plus Ublock Origin on any web browser.

[–] ioslife@lemmy.sdf.org 3 points 1 year ago

I couldn’t get AdGuard Home working properly on my server, so I have been using NextDNS.

This is a good reminder to attempt to get it set up again

[–] lemonuri@lemmy.ml 3 points 1 year ago

I use the Adblock plugin on an openwrt router to provide blocklists for the whole lan. It works rather weell.

[–] Turbo@lemmy.ml 3 points 1 year ago

Pihole. Default block lists

[–] Samsy@lemmy.ml 3 points 1 year ago

If you are the "VPN to home, always on" user, go for pi-hole.

Adguardhome has it's strengths when it comes to DoH, DoT, Quic usage.

[–] hellequin67@lemm.ee 3 points 1 year ago* (last edited 1 year ago) (1 children)

I use two across different devices.

base.dns.mullvad.net

noads.libredns.gr

Both offer DNS over TLS and both are privacy focused which was why I decided to use them.

[–] Contort3860@links.hackliberty.org 4 points 1 year ago (1 children)

Does DNS over TLS have any advantages over DNS over HTTPS?

[–] hellequin67@lemm.ee 7 points 1 year ago (1 children)

Not really and some would argue that from a local network perspective HTTPS is preferable.

The main difference is that HTTPS routes through a standard port so gets "lost" in all other Https traffic whereas TLS uses a distinct port so whilst it's encrypted you would be able to see at the local level that you're using DNS over TLS but not what you're doing.

load more comments (1 replies)
load more comments
view more: next ›