Skip to content

Comment on Browser extensions spy on you, even if its developers don'tparent

Comments

Of course, NextDNS and AdGuard are indistinguishable from a watering hole attack.

(I've never heard of them; this is a fundamental problem with using centralized "privacy preserving" services.)

https://en.wikipedia.org/wiki/Watering_hole_attack

I think ublock origin is a bit better, in that it is open source. Does it support reproducible builds though?

Look, either my ISP's DNS servers are a watering hole attack or the NextDNS servers I subscribe to are a watering hole attack. I've got to use someone's watering hole. Why should I trust my ISP more?

Because you are the customer of your isp vs being the product of a free extension?

I am not the product of a free extension, whatever that means. I am a NextDNS subscriber. That makes me just as much their customer as my ISP's.

Besides, I don't know what a paying-customer relationship has to do with trust. I could just as easily be betrayed by someone I'm paying. For example, GrubHub drivers have a chronic problem of "losing" my drinks, despite being promised a tip and wages. I have to go chase refunds every day for these "mistakes". I'm a paying customer, yet I can't trust them to get my order right.

In the US, our ISPs lobbied our government to allow them to sell our data. I am literally forced to give money to my enemy to use the internet.

NextDNS and AdGuard DNS are just DNS providers that return filtered results for ad-related DNS queries. Their filter lists are public:

https://github.com/orgs/nextdns/repositories?type=all

https://github.com/AdguardTeam/AdGuardSDNSFilter

If you don't trust their DNS servers for whatever reason, you can simply add these entries to your hosts file to replicate their functionality locally.

Sorry for jumping in but since AG is mentioned.

If you want to have all the data under you control, there's this: https://github.com/AdguardTeam/AdGuardHome

Regarding open source, AdGuard DNS actually is: https://github.com/AdguardTeam/AdGuardDNS

In the case of AdGuard DNS being open source does not change the fact that it is a centralized service and using such a service is a matter of trust.

AdGuard home or pihole does not prevent “watering hole attacks” (honestly feels like paranoia more than safety but whatever). At the end of the day, you need a DNS for non filtered sites which AdGuard home and pihole uses cloudflare by default.

It’s a DNS…you have to use one regardless of what you do. Your pihole is passing any nonfiltered and white list to cloudflare or google DNS to begin with (or worse, your ISP DNS).

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.