I’ve been aware of pi-hole for a while now, but never bothered with it because I do most web browsing on a laptop where browser extensions like uBlock origin are good enough. However, with multiple streaming services starting to insert adds into my paid subscriptions, I’m looking to upgrade to a network blocker that will also cover the apps on my smart TV.

I run most of my self hosted services on a proxmox server, so I’d like something that’ll run as an LXC container or a VM. I’m also vaguely aware that various competing applications have come out since pi-hole first gained popularity. Is pi-hole still the best thing going, or are there better options?

  • PainInTheAES@lemmy.world
    link
    fedilink
    English
    arrow-up
    29
    arrow-down
    1
    ·
    10 months ago

    AdGuard Home and blocky are other popular options. I switched over to AdGuard Home a while back because it supported DNS over HTTPS although I’m not sure if that’s still a relevant reason. I run AGH as a docker container but it is easy to run in a LXC or VM. There’s also a tool to sync configs if you need multiple instances. Notice: AGH block lists are formatted like uBlock Origin lists so you will not be able to use PiHole style lists.

    DNS based ad blockers won’t work when ads are served from the same place as the content. Which is why DNS based ad blockers don’t work against Twitch or YouTube. So YMMV.

    If you’re looking to block interface ads and select streaming service ads there are block lists available like this one. The game with smart TVs is blocking the ads breaks the TV a little because sometimes it calls back to the same servers for updates and misc info like weather.

  • plz1@lemmy.world
    link
    fedilink
    English
    arrow-up
    12
    ·
    10 months ago

    NextDNS.

    Also, be wary of relying on anything blocking ads on streaming services this way. They will likely serve them within the video stream, so not network-blockable.

    • Kid_Thunder@kbin.social
      link
      fedilink
      arrow-up
      1
      ·
      10 months ago

      NextDNS caps your queries per month on the free account. ControlD doesn’t and you can pick a various mix of their public DNS resolvers. You don’t necessarily get the granular control with doing it this way for free that you can get with NextDNS though.

      If you do check out these, make sure you click the Secure Resolvers if you’d prefer for DLS/DOQ/DNS over HTTPS instead of Legacy.

        • Kid_Thunder@kbin.social
          link
          fedilink
          arrow-up
          1
          ·
          10 months ago

          I run pihole and my wireguard VPN server locks all queries through it, which in turn uses unbound and queries via different providers like Cisco’s OpenDNS, Cloudflare and Quad9. However, I wanted to present a similar offering that also has a free-tier without a query cap for people interested.

          • brrt@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            1
            ·
            10 months ago

            Your „free“ option just requires buying hardware that enables all of it and an intensive setup process and knowledge which might be quite time consuming.

            It may be a good solution but it’s far from free for many people.

            • Kid_Thunder@kbin.social
              link
              fedilink
              arrow-up
              1
              ·
              edit-2
              10 months ago

              The free solution I was referring to was my comment about using ControlD, which is certainly offers a free service…which is the comment that the other person was responding to.

  • Decronym@lemmy.decronym.xyzB
    link
    fedilink
    English
    arrow-up
    10
    ·
    edit-2
    10 months ago

    Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

    Fewer Letters More Letters
    DNS Domain Name Service/System
    HTTP Hypertext Transfer Protocol, the Web
    HTTPS HTTP over SSL
    IP Internet Protocol
    IoT Internet of Things for device controllers
    LXC Linux Containers
    PiHole Network-wide ad-blocker (DNS sinkhole)
    SSL Secure Sockets Layer, for transparent encryption
    VPN Virtual Private Network

    7 acronyms in this thread; the most compressed thread commented on today has 5 acronyms.

    [Thread #431 for this sub, first seen 15th Jan 2024, 23:55] [FAQ] [Full list] [Contact] [Source code]

  • methodicalaspect@midwest.social
    link
    fedilink
    English
    arrow-up
    8
    ·
    10 months ago

    Pi-Hole’s great. Got my primary instance on a Pi 4 and three secondaries (one per vlan) on LXCs. Works so well it feels weird seeing ads when I’m not at home, I’m actually considering using Tailscale to route all my queries through my home connection.

    • zylinderhut@feddit.de
      link
      fedilink
      English
      arrow-up
      5
      ·
      10 months ago

      I second that, turns out 90% of the queries on my network come from my Libratone speakers and they seem to desperately try and reach China (.com.cn)

    • Ark-5@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      2
      ·
      10 months ago

      I do this and it works great. Ad block on all my devices regardless of proprietary sandboxes. I also use Syncthing over my tailnet IP addresses so that traffic never leaves my “grounds”. I’m slowly building out a whole suite of services I host only within my tailnet, jellyfin, calibre, invidious, it been a great learning experience. I’m about to set up a proper home lab, finally moving everything off an old laptop.

    • rentar42@kbin.social
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      10 months ago

      Hint: you don’t need to route all your traffic through your VPN to make use of the pihole adblocking: Just DNS. If your at home internet is even moderately stable/good then this should barely affect your roaming internet experience, since DNS traffic is such a small part of all traffic.

      Also, since I’m already mirroring the configuration of my PiHole instance to a secondary one, I’m considering putting a tertiary one on some forever-free cloud server instance and just using that when not at home (put it into the same wireguard vpn to prevent security nightmares). That way my roaming private DNS wouldn’t even depend on my home internet.

    • guajojo@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      10 months ago

      Pihole user for more than 5 years,.can confirm that it is indeed better, made the switch few months ago

      • Maximilious@kbin.social
        link
        fedilink
        arrow-up
        1
        ·
        10 months ago

        What makes it better other than the UI? I’m weary of using it because it is developed by Russian developers.

      • Encrypt-Keeper@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        10 months ago

        As an AdGuard home user for more than a few years, I switched back to Pihole because it wasn’t really any better. It was also easier to pair pihole with Unbound.

      • DreadPotato@sopuli.xyz
        link
        fedilink
        English
        arrow-up
        1
        ·
        10 months ago

        What makes adguard home better than pihole? Genuinely curious, I’m running pihole now and have been for a couple of years without issues.

        • dan@upvote.au
          link
          fedilink
          English
          arrow-up
          1
          ·
          10 months ago

          It works well! I have one AdGuardHome instance running on my home server and one running on a Raspberry Pi, both using Docker. Having two prevents the internet from breaking in case I have to shut down one of them for some reason.

  • lemming741@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    10 months ago

    I run pihole on proxomox, and also opnsense in the same box. Then you can forward all port 53 traffic to your pihole. Some devices have hard-coded DNS that will bypass the DHCP DNS.

      • zzzz@lemmy.world
        link
        fedilink
        English
        arrow-up
        9
        arrow-down
        1
        ·
        10 months ago

        Chuck 'em in the garbage and get something that doesn’t break when you insist on privacy.

        • Apathy Tree@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          2
          ·
          10 months ago

          Ha! This is my new way of looking at my smart devices. I’ll sell you off if you don’t do what I want, and buy something that does. Very much a threat.

          I recently factory reset all my Roku TVs, and didn’t connect them to the internet… and they work much better now.

          Roku broke big time when I insisted on privacy. blocked the entire Roku domain, it broke the apps on a 1-month schedule like clockwork to get the network release for reinstall which allowed for phone home. lol no. I trashed it. They are dumb TVs now.

      • DeltaTangoLima@reddrefuge.com
        link
        fedilink
        English
        arrow-up
        2
        ·
        10 months ago

        Really? I run several Chromecasts, and I block their access to all DNS services except my internal Pi-holes. They work just fine.

  • Codilingus@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    5
    ·
    10 months ago

    Adguard home is like pihole, but has built in encrypted DNS options. For easy mode NextDNS.

    They pretty much all have the same block lists to choose from.

  • Darkassassin07@lemmy.ca
    link
    fedilink
    English
    arrow-up
    5
    ·
    10 months ago

    DNS based ad blocking does not block video ads served by streaming services. You’ll need a modified client specific to the service you want to block ads for to achieve that.

  • m_randall@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    edit-2
    10 months ago

    There’s nothing really bad with PiHole but I moved from it to AdGuard, both on proxmox. The UI brought me in, makes management a bit easier. It also supports DoH right out of the box.

    Try em both. See what you think.

  • Father_Redbeard@lemmy.ml
    link
    fedilink
    English
    arrow-up
    4
    ·
    10 months ago

    I ran Pi-hole for years. Switched to adguardhome running on 2 servers (primary and secondary) with AGH sync keeping the two instances identical. I like the UI better, dns rewrites, and the ability to simply block services entirely with a single click.

    • Flying_Hellfish@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      10 months ago

      I did this as well, I still have 2 pihole instances running with gravitysync for now, but AGH sync is much easier to setup and maintain. My 2 pihole instances are running for my guest network only and AGH is running everything else.

  • Dandroid@dandroid.app
    link
    fedilink
    English
    arrow-up
    3
    ·
    10 months ago

    I set up pihole a few months ago. I added a few dozen of the highest recommended block lists, but I wasn’t impressed at all. It didn’t seem very effective at blocking ads in both real world tests and tests that I found online specifically for testing your adblocker.

    • khorak@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      3
      ·
      10 months ago

      The best test I have is my wife complaining, that ads in Google results cannot be opened. It seems to work flawlessly for me 😂

      On a more serious note, what tests are these? The thing is, the ad domain is either in the blocklist or not. Ads inside apps are hard to block (I even have adaway on my android, and some slip through as eg Instagram reuses the backend domains/endpoints for ad delivery).