• GrapheneOS@grapheneos.social
    link
    fedilink
    arrow-up
    1
    ·
    13 hours ago

    @lka1988 @pineapplelover

    > System-wide hosts-based adblocking

    That’s not a good way to do it.

    > DNS/always-on VPN is not a reasonable solution

    You don’t need to use a DNS service or VPN service to filter remotely. You can filter locally via the VPN service feature, including while using a VPN if you want.

    You should follow our advice and do it with an app like RethinkDNS providing support for both local filtering and optionally using WireGuard VPNs at the same time including chained VPNs.

    • GrapheneOS@grapheneos.social
      link
      fedilink
      arrow-up
      1
      ·
      13 hours ago

      @lka1988 @pineapplelover

      Why do you want to have a slow, legacy and hard to debug implementation of domain-based filtering instead of managing it with an app?

      Domain-based filtering is also very limited in what it can since it’s trivially bypassed by apps or web sites using IPs or doing their own DNS resolution, which is fairly widely adopted. For example, WhatsApp will still work with the domains blocked. In practice, you’ll also only be filtering domains not used for useful functionality.

      • Lka1988@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        2
        ·
        edit-2
        8 hours ago

        Thank you for proving my point:

        every thread the devs get involved with just seems like they’re sniffing their own farts

        Dont get me wrong, I think you guys make a great ROM. However, no advice was requested here, yet you tagged me in multiple consecutive comments chock full of unsolicited advice. Plus, in the first comment, you suggested “RethinkDNS”, which depends on their own DNS servers. How do I know that this service, which I have literally never heard of in my 14 years of fucking with Android devices and ROMs and adblockers until maybe 6 months ago, isn’t just a honeypot? Or will even exist after Trump is done raping the USA? I see they use DNS over HTTPS, but I defer to my previous (rhetorical) question.

        I wouldn’t think a security and privacy-focused ROM should be recommending anything but a locally hosted option. But as others have said, this is your guys’ project and you’re free to implement it how you see fit. And it is a solid ROM. But apparently it’s not for me.