Hacker News new | ask | show | jobs
by tw04 2875 days ago
Pi-hole has made some pretty poor blocking choices in the past, so use at your own risk.

For instance, they randomly decided to block *.microsoft.com - you can imagine the chaos that caused.

3 comments

Sure, it would be chaos if you expect everything to just work out OK. But if you defang Windows 10 properly, it doesn't need to reach Microsoft servers. That is, blocking is a supplementary measure.

When I last used Windows, you could host updates locally. And I believe that Microsoft actually recommended that for large firms.

> But if you defang Windows 10 properly, it doesn't need to reach Microsoft servers.

Something has to get the updates in the first place, even with the local P2P sharing.

If you're one of those "I never update my Windows install" people at this point you're beyond hope..

Yes, but the server that gets and shares those updates need contain no PII.

I do not trust Microsoft. And so, when I need to use Windows 10, I do it in a very careful way. I start with an anonymously obtained installer. I install and update in a VM, with Internet connectivity through a nested VPN chain. Then I clone the VM, and work in the clone, with *.microsoft.com blocked.

When necessary, I update another fresh clone. Then I clone that, and securely transfer files from the first clone. That way, Microsoft never sees anything except for a clean install, and has no PII to track.

Don't assume everyone uses windows.
IME DNS based blocking on the router works great.

And yes, you do need a software rule based blocker to supplement IP blocking.

Most ads come from a few sources, that's why hosts based blocking has been effective since 2000s.

Only chaos if you run Windows. I wouldn't even notice if it was blocked.
>Only chaos if you run Windows

so breaking 80+% (being a bit conservative here) of people's computers is okay?

The relevant question is whether it's 80% of people who are using pihole; that number is probably still pretty high, but lower than the average population I expect.
> Only chaos if you run Windows

Or develop for Windows, or have a client who uses Windows, or neer to access any of the documentation on MSDN, or...

Right, so only chaos for 99%+ of the corporations in the US...