Hacker News new | ask | show | jobs
by Gigachad 1558 days ago
It’s a lost cause. The router should be treated as hostile and shouldn’t be allowed to know anything if possible. DNS over HTTPS and that SNI encryption stuff should be used.
1 comments

How do you plan on blocking ad servers with DoH?
With ublock origin. DNS level ad blocking is rubbish and mostly circumvented by providers now.
I heard that ads were able to circumvent DNS by using canonical names.

But uBlock origin and PiHole both do CNAME inspection to block this.

Is there other ways that ads are circumventing DNS ad-blockers such as PiHole?

I have found that rather than finding a way to sneak ads in, most non browser apps will just detect that the ads are missing and throw up an error refusing to display the content.