Hacker News new | past | comments | ask | show | jobs | submit login

I don't think you understood the article. Pihole or any blocking DNS server based on blacklists won't help here (thats the point).

By using random, frequently updating CNAME's it effectively defeats the mechanism Pihole uses.

You could still block IP addresses of the advertisers, but often time's they don't do BGP, so they aren't going to have blocks under the same ASN you can simply block.

It's a nuanced and challenging problem for sure.




It's surprising to me that dnsmasq doesn't provide the ability to override the returned names in the chain. I'd just assumed it did. Seems like it shouldn't be _that_ hard to solve, though. I've written my own bespoke DNS server before on top of miekg/dns - I might have to take a crack at my own pihole-like with CNAME interception. :)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: