HN in RSCserver-reason-react
top.mdnew.mdbest.mdask.mdshow.mdjobs.md
← Back to stories

ESP32-C3 Adblock

100 pointsby jayhoon 8 hours ago36 comments

Discussion

Loading discussion
  • fwip · 7 hours ago

    Cool idea, latency might be too high, wish the docs weren't all AI vomit.

    • thenthenthen · 6 hours ago

      This will be slow for one user, let alone more than one

    • snailmailman · 5 hours ago

      The biggest benefit of my local dns server is latency. On wired internet, my dns is <1ms from my PC. Upstream dns for me is pretty quick. Google and cloudflare dns are ~5ms from me. But WiFi latency alone is ~8ms most of the time in my experience. On my fiber internet, pinging a dns server in some random upstream server miles away is lower latency than WiFi 10 feet away. But the real issue on WiFi is any packet loss at all adding 50-100ms to that at random depending on interference. With DNS you are paying this latency cost all the time on nearly every request.

      • QuantumNomad_ · 1 hour ago

        > With DNS you are paying this latency cost all the time on nearly every request. Surely not? macOS, Windows, and I think most of the big Linux distros, all cache DNS responses. Probably the web browser itself does too.

    • danw1979 · 3 hours ago

      “The trick everyone misses”

  • muti · 7 hours ago

    Weird how the readme talks about hash collisions, but not in the way I would expect. Two blocked domains with the same hash isn't a problem, they both need to be blocked. Where hash collisions matter is false positives, e.g. if hash(google.com) = hash(adserver.com). There does appear to be a web dashboard and /unblock api so should be straightforward to resolve.

    • zamadatix · 6 hours ago

      Yeah, I think they have it backwards. As you say, regardless of how many entries you have locally, the collision risk comes from false positive hash matches not from worrying if the positive hashes collide.

    • close04 · 56 minutes ago

      > Two blocked domains with the same hash isn't a problem, they both need to be blocked. This is a problem if the second one is actually a major useful domain. If HN and adserver have the same hash, you have a problem. This could be described as a false positive for HN. > Where hash collisions matter is false positives, e.g. if hash(google.com) = hash(adserver.com) This sounds like the same issue I describe above where you need to use Google but block adserver. Otherwise it's only a problem if you implemented allow lists, right? This is when you explicitly allow Google and implicitly allow adserver along with it because of the hash collision.

  • 1vuio0pswjnm7 · 6 hours ago

    Whitelist/allowlist is easier, e.g., it's smaller Depends on the user but not everyone is visiting new websites everyday Even for those that are, the number of domain-IP mappings needed will be relatively small Definitely under 140,000 Most DNS data I use is "static", it rarely changes. As such most times I don't have to make DNS queries. I store the domain-IP mappings in proxy memory; this is faster than DNS No "blocklist" needed

    • sheept · 5 hours ago

      I would think that a regular user of Hacker News would be visiting new websites every day (though it'd definitely still be below 140k)

      • Etheryte · 3 hours ago

        This is all a guesstimate, but my gut feel is that a considerable part of the HN population doesn't even read the linked content, only the comment section here.

        • jasonjmcghee · 3 hours ago

          I sure hope that's not true. Maybe hit the comments section first?

          • dwedge · 2 hours ago

            With github being the exception, I use comments to see if the article is AI. If it is, I prefer the condensed opinions in the comments. Not to say it can't be interesting I just don't want to waste time reading overly verbose generated text.

          • lhoff · 2 hours ago

            Depends on the content, for all of these model release marketing sites, I for example only read the comments. If i would estimate it, I only take a look at 1/4 of the links where i read the comments.

  • BLKNSLVR · 4 hours ago

    I'm a bit of a paranoid freak that likes lists, so I've got a PiHole that has a total list of 14-16M blocked domains. Great idea, and good for casual blocking, but I'm almost moving to an "allow list" mindset. This solution would probably work better for that, I wonder if the good parts of the internet would fit into an 140k list.

    • reader9274 · 3 hours ago

      Do you host your lists somewhere you can share?

      • BLKNSLVR · 41 minutes ago

        I'm currently (very slowly, in the small gaps between 'life') setting up a site the host the lists and also explains them and their usage. Since it's not ready, it'll be best if I point you to the sources I've aggregated from: https://firebog.net/ https://github.com/hagezi/dns-blocklists https://github.com/StevenBlack/hosts https://github.com/jerryn70/GoodbyeAds Link to my in-progress list file hosting: https://lists.uninvitedactivity.com/DNS/ 00_Tiers directory: I've aggregated the lists into four tiers: Base, Recommended, Aggressive, and Paranoid. And I've got two sets of these, one that includes Newly Registered Domains (Full directory), and one that doesn't include NRDs (NoNRD directory, because NRDs are ... heavy: Paranoid list with NRDs: 9.1 million records, without NRDs: 3.7 million records). 11_Allow directory: A bunch of allow lists sourced from: https://discourse.pi-hole.net/t/commonly-whitelisted-domains... . I also use this list for an Allow list: https://github.com/anudeepND/whitelist 21_SpecificTopics directory: Aggregation of lists under the topic that matches the file name. Fake News list needs to be updated as it contains a _way_ overbroad list that I need to remove from the aggregation.

    • oso2k · 2 hours ago

      Tbh, for the ESP32-C3’s perf, an allow list would likely save RAM and CPU time.

  • manlymuppet · 4 hours ago

    Wow, this is an atrocious name for a project haha. Cool though.

  • nicman23 · 4 hours ago

    i dont get pihole. just use a proper dns? if you want local, just use unbound?

    • Tajnymag · 4 hours ago

      Pihole and unbound can work together. Pihole isn't a good DNS server, it's a good adblocking DNS server.

    • dannyw · 3 hours ago

      people like ease of use, UI, docs, and community. after all, why use opnSense; just use suricata and $PROPER_X! why use TrueNAS; just use $DISTRO and ZFS!

      • nicman23 · 1 hour ago

        it is easier to add adguard dns if you want ease of use

  • jolux · 4 hours ago

    10ms? Good grief that’s slow.

    • moebrowne · 3 hours ago

      Still faster than using a remote resolver: https://www.dnsperf.com/

  • anilakar · 3 hours ago

    There's no point in using PlatformIO for ESP32 MCUs. The native ESP-IDF extension works much better. I would only recommend using it instead of the standard Arduino Processing IDE.

  • rekoil · 3 hours ago

    "They were too preoccupied with whether they could, they never stopped to think whether they should" Jokes aside, very impressive that it works!

  • timvdalen · 3 hours ago

    > The trick everyone misses: Please just write the first sentence of your README yourself

    • dwedge · 2 hours ago

      Apparently solving blocking extra domains due to hash collisions (reducing from 1 to 0) would be extra space "to solve a problem I don't have". I dislike when LLMs talk to me like that. I hate it when humans do it, confidently spewing their overconfident llm assumptions to others

      • lifeisloving · 2 hours ago

        I actually thought this was one of the more communicative parts of the readme and quite liked their explanation.

  • yoavm · 2 hours ago

    If you're ever thinking about getting an ESP32-C3, do yourself a favor and get the variant that you can connect an external antenna to. The normal C3 has a built-in antenna that is extremely weak, making it useless for most things I was planning using it for.

    • n8henrie · 49 minutes ago

      You can find instructions for making and soldering on a small antenna to the common "mini" dev board that reportedly helps quite a bit

  • waysa · 2 hours ago

    I think it could fit even more domains using a Bloom Filter or similar probabilistic data structure. With a chance of false-positives of course. But that's a trade-off the project already makes.

  • jwillmer · 1 hour ago

    pinhole is great but if the device fails your network is down. I swapped to nextdns because of that. maybe support of multiple devices would fix it - now that is this cheap it would not matter .

    • close04 · 1 hour ago

      The simple answer is have 2. If the cost per unit is low enough than deploying 2 PiHoles is trivial. The developers could make users' lives easier by implementing a clustering option that syncs the 2 out of the box. For static deployments, where you don't change the config too often, it's still decent as it is.

      • krtkush · 45 minutes ago

        I did the same (until my RPi zero stopped working). Both the devices share same vertical IP address and if one ever went down, the other would take over without any delay.