Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That doesn't stop anyone using IP addresses directly, and I find that a small minority does (but that minority does including, e.g. Microsoft for some Win10 updates).

Depending on your threat model, you might need to go the proxy/firewall route.

Hosts file is a weird middle ground - that has to be installed and maintained on every device, many of which (e.g. iphone/ipad) won't let you do that. It's better to set up a local DNS, which will serve every local machine; and as I mentioned, doing this at a firewall level is better yet.



That only works on your local network. You always need something on the device if you want to take it anywhere.


Homelab: pi-hole, pfsense, openvpn Mobile Devices: openvpn client


I started using the brave browser, which i noticed blocks alot of network requests. Loading the NYT took about 25 seconds to finish all requests using chrome. With brave it took 4 seconds. Also brave gives you the option to pay the sites you visit with BAT tokens, if you want. Brave in conjunction with Pi-hole looks like even more secure and perhaps further page load speed.

Edit: spelling


That's mostly what I use at home too. It works very well.

It doesn't quite work well while on the road sometimes. For those cases, I have a docker running diginc/pi-hole (with some additional hosts file blocking going on), then I point my laptops DNS towards that and am good to go.


Even better, replace pfsense with PF running on OpenBSD. Pi-Hole is awesome though, can't recommend it enough.


With PfSense you can block by country or ASN and avoid huge blocklists


This is pretty much my jam at home and away. Works great.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: