figmert 1 day ago

I can't recommend AdGuard enough. It works across devices, and just does all the DNS level blocking everywhere. I've been able to install it on my parents' devices, my siblings' devices, and more places. They have apps for just about any device. On top of that, you can install user scripts and use them on your mobile phones even if your browser doesn't support them (does require a CA cert being trusted).

My biggest issue is I can't use it while I'm connected to Tailscale, but my plan is to install AdGuard Home on my homelab and have that take over instead. It does remove many of the functions, but it's better than the alternative

  • matltc 5 hours ago

    Can set for whole lan at gateway by pointing its DNS server to their ipv4/6 addrs.

    If you're in stock isp land like me (for now, wip), be sure to cover all your bases, because they quietly hand you over to ipv6 if you just have 4 set. Can verify with eg. resolvectl query doubleclick.net

    But yeah definitely do it at device level too. For me on android, simple as settings>private DNS>put ipv4

TheBozzCL 3 hours ago

I self-host my own DNS over TLS for domain-level adblocking. Maybe not the wisest decision, but it's working well so far and it doesn't require a lot of maintenance now that I've refined the setup.

I use a DNS registrar and certificate that support wildcards. That way, I don't have to leak my DoT subdomain and I gain some obfuscation. Android's Private DNS option doesn't support alternate ports, so I'm forced to use the default.

I use nginx as my reverse proxy and TLS terminator. At this stage, I apply rate limiting and subdomain filtering.

Then nginx forwards the streams to Unbound, which filters out any local IPs from the responses to avoid leaks.

Finally, Unbound forwards requests to my Pi-hole, where the magic happens.

somebudyelse 1 day ago

Highly recommend https://nextdns.io, great for all kinds of blocking stuff. Plus Firefox or Edge for uBlock support.

  • subscribed 1 day ago

    Well, yeah, it's pretty good, but has a very low free tier limit. It's barely enough to cover my IOT subnet and subnet for stuff like AVR or TVs.

    So if I'm supposed to pay for ad blocking, I might as well read the article and use one of the other methods[1] instead :)

    [1] I was trying Rethink several times, but WG Tunnel with ad-- and tracker-blocking service works best for me.

    • pogue 23 hours ago

      I used NextDNS for a long time, but they offer absolutely zero support for their customers.

      I ended up just switching to Control D's free tier using the Hagezi blocklist. You can try Normal, Pro & Pro+ for typical usage (I stick to pro normally). That + Brave and I'm pretty much ad free.

      https://docs.controld.com/docs/free-dns

      • ignoramous 7 hours ago

        > ended up just switching to Control D's free tier using the Hagezi blocklist

        HaGeZi recently launched their own public DNS-over-HTTPS / DNS-over-TLS resolvers: https://github.com/hagezi/dns-servers.

          # privacy
          root.hagezi.org
          # security
          ctif.hagezi.org
        • pogue 1 hour ago

          Very cool. I hope they get some NA server locations as ControlD has them beat there. Hagezi's DNS only use their Pro list + TIF, but if you wanted to use Normal or Light ControlD would still be a good option. I keep their TIF list in adblock.

          https://controld.com/network

    • splatter9859 21 hours ago

      I used NextDNS for years and moved over to ControlD this year due to NextDNS literally not innovating at all and having no customer suppport. I've been much happier.

nyarlathotep_ 23 hours ago

My current approach is AdGuard Home, WireGuard VPN to my home network the majority of the time.

This was all pretty simple to setup given hardware that supports VPN, DDNS, etc.

Worth noting too that just blocking hostnames is not enough; Netflix, as an example, uses Google's DNS servers (plain UDP) on some/most clients.

If the network the client operates on can't prevent DNS to other servers, that's a simple "bypass" vector.

AFAIK, the best you can get, given sufficient time, patience, and hardware is:

• something like the above

• blocking outbound DOT (853), DOQ (784, IIRC) excepting, perhaps, upstreams you trust

• blocking HTTPS to known DOH endpoints (Cloudflare, Google, etc)

• DNAT for plain DNS cases like the Netflix example above. (to your DNS server(s))

Even that there's plenty of hypothetical opportunities for clients to just use another DOH resolver outside of your domain/IP block lists.

janwillemb 1 day ago

I point "private DNS" to my VPS with pihole and stunnel, works quite well. Adguard as private DNS is also effective.

OroPla 13 hours ago

My solution was to not install anything with ads and to not browse the Internet on my phone.

BLKNSLVR 1 day ago

Whenever I'm out and about I connect to my home system via wireguard VPN, and all DNS traffic through my home system is funneled into PiHole. I also have a healthy collection of DNS block lists setup on the PiHole (which I'm currently setting up a site to explain/share).

I also have a VPS setup in a similar fashion in case my home connection fails for one of many reasons.

I try to only practice safe internet. Raw-dog the internet and you're asking for an infection.

xnx 1 day ago

I want to use something like this, but I don't think I can when also using VPN by Google on an unrooted phone.

  • netsharc 1 day ago

    Your comment is how I found out about "VPN by Google".

    I wonder how old it is and what their motivation is/was. Maybe to offer something comparable to Apple Private Browsing?

  • altairprime 20 hours ago

    It sounds like VPN by Google is an effective strategy for keeping users from using ad and tracking blockers, then; for contrast, iOS routes the connection to the private traffic server over your user VPN connection if one is active.

methou 18 hours ago

That's a long article about just DNS.

I'd expect mentioning of the good old Xposed framework.

epihelix 23 hours ago

Long-time AdAway user here (via root and a hosts file). I couldn't live without it. Simple and effective.

Sarkie 1 day ago

Blockada old version.

And then add lists.

And add your own constantly when they miss

  • pizzaiolo 22 hours ago

    Why the old version?

    • jttnr 16 hours ago

      The new version requires a monthly subscription and is cloud based.

teo_zero 1 day ago

Why do you need an app at all? Can't you just manually set a private VPN in the settings?

gremlinunderway 23 hours ago

>a rogue ad-blocker app is exactly as dangerous as a rogue VPN service. Fortunately, because these ad-blocking apps are usually open-source, there are limited opportunities for bad actors.

I find it naive to state this when earlier he noted that he's suspicious of free services without a clear funding model.

Sure, open source is certainly better than closed source, but its not like somehow magically it prevents exploitation. There's plenty of examples especially in a small project like this with few eyeballs. So why question the funding model of a free VPN but not question the funding model of an open source project? We just assume its being done out of good will? I find that perspective naive.

  • ndriscoll 23 hours ago

    Not that this entirely clears the skepticism, but to directly address the question as asked: blocking ads scratches a clear itch for the author. FOSS works great because software has no marginal cost, so as long as someone wants it to exist badly enough to make it so, there's then no reason not to give it away to anyone else who wants it. Providing a free VPN service to the world is quite a bit less likely to be an author-itch, and actually incurs a cost.

Onavo 1 day ago

Sigh, that's a lot of words to describe DNS based adblocking.

In Android you can either set your DNS server in the system settings or via the VPN API.

Sample code here https://github.com/t895/DNSNet/blob/a-couple-updates/service...

They both do the same thing. There are local device-only resolver apps like

https://rethinkdns.com/

https://github.com/m66b/netguard

Another famous one is DNS66 but it's sadly unmaintained. Avoid apps with the word "ad" in their name, they are usually semi commercial and can't be trusted.

Do note all of these methods can be overridden on the app level e.g. a lot of browsers come bundled with first party VPNs or use their own built-in resolvers.

If you want something more reliable, Firefox on Android with the UBlock Origin and Sponsorblock extensions is still the gold standard. Though do note the Android Firefox is extremely slow compared to the Chromium based browsers.

For app level ads, use an app patcher like https://github.com/morpheapp which can remove all in-app advertisements and inject sponsor blocking code.

  • Larrikin 1 day ago

    In what meaningful way is there any difference in speed between Chrome and Firefox on Android?

    I also prefer replacing uBlock Origin with Ad Nauseum which is built on top of ubo.

    • Onavo 23 hours ago

      On any media or JS heavy site, Firefox on Android lags. Also for whatever reason small stuff like text boxes, zoom, keyboard pop up and tab zoom out animations have significant jitter. UI elements seem to be out of step with platform conventions. It's not the sort of thing that's easy to file a bug report for but you need a staff UX and performance engineer to go over it with a fine toothed comb to iron out the bugs. The current version feels very raw. You get the same vibe as a poorly optimized React Native app. Slight jitters here and there and a dropped frame on some animations. There is plenty of small stuff like the tab switching animation that feels slow. Nothing that will show up on a screen recording but immediately obvious if you are switching between Chrome and Firefox running on the same device. I suspect the root cause is that Firefox implemented a significant part of their UI in JS/HTML instead of native but I haven't checked the source code so that's just a hypothesis. On 2026 flagships, there's no excuse for it not to have a butter smooth UI (Oryon core chips are approaching laptop level of performance).

      • epihelix 23 hours ago

        I use a 2019 flagship phone (an s10e), and Firefox for Android is butter-smooth for me. So I cannot imagine why it would be janky for you with your multiple-times-faster modern phone?

        Sounds like you're describing Firefox from around the time my phone was made (which was indeed slow and janky, and had lots of UI issues).

        • kuekacang 23 hours ago

          Had dailied redmi note 12 4g, with debloat, ublock and selective uscript block. Many js/media heavy websites (that needed to have their js enabled to be viewed) lagged under firefox

alekescu 1 day ago

There is a special irony to an article about ad blocking containing an apparent undisclosed ad for Nord.

  • Cider9986 1 day ago

    One time I saw someone trying to hide an Amazon affiliate link in a post by putting the link text as amazon.com/dp/12345 but the link was amazon.com/dp/12345/ref=tracking. There's no affiliate link for Nord here but it's weird to use it as an example over better options: https://www.privacyguides.org/en/vpn/

    • gruez 1 day ago

      >ref=tracking

      Amazon's `ref` parameter isn't used for affiliate codes. It's certainly used for something, but given that internal links have it (eg. the logo in the top left has `/ref=nav_logo`), I wouldn't immediately conclude it's an affiliate link just because it has ref. Actual affiliate links are through the `tag` parameter.

      • Cider9986 1 day ago

        It was just an example of garbage I got at the end of the link when going to an amazon page. The deleted posts were affiliate links.

  • altairprime 1 day ago

    > an apparent undisclosed ad for Nord

    What evidence supports the link referenced being an advertisement? I'm not seeing any referral, tracking, or any URI parameter data at all that would support the claim, and this seems to be their only instance of referring to it — where, in this 'state of the union' helpdesk-style article, one or more such 'VPN provider' links seems particularly relevant to visitors. (I do not use whatever this company's products are and have no opinion either way on them aside from mistrusting the claim presented here.)

  • minouye 1 day ago

    It's a plain link--it's not an ad.

    • ignoramous 23 hours ago

      The only link in the article with "in 2026" in the title...