NHacker Next
  • new
  • past
  • show
  • ask
  • show
  • jobs
  • submit
▲System-level ad-blocking in Android (kevinboone.me)
figmert 1 days ago [-]
I can't recommend AdGuard enough. It works across devices, and just does all the DNS level blocking everywhere. I've been able to install it on my parents' devices, my siblings' devices, and more places. They have apps for just about any device. On top of that, you can install user scripts and use them on your mobile phones even if your browser doesn't support them (does require a CA cert being trusted).

My biggest issue is I can't use it while I'm connected to Tailscale, but my plan is to install AdGuard Home on my homelab and have that take over instead. It does remove many of the functions, but it's better than the alternative

matltc 6 hours ago [-]
Can set for whole lan at gateway by pointing its DNS server to their ipv4/6 addrs.

If you're in stock isp land like me (for now, wip), be sure to cover all your bases, because they quietly hand you over to ipv6 if you just have 4 set. Can verify with eg. resolvectl query doubleclick.net

But yeah definitely do it at device level too. For me on android, simple as settings>private DNS>put ipv4

TheBozzCL 4 hours ago [-]
I self-host my own DNS over TLS for domain-level adblocking. Maybe not the wisest decision, but it's working well so far and it doesn't require a lot of maintenance now that I've refined the setup.

I use a DNS registrar and certificate that support wildcards. That way, I don't have to leak my DoT subdomain and I gain some obfuscation. Android's Private DNS option doesn't support alternate ports, so I'm forced to use the default.

I use nginx as my reverse proxy and TLS terminator. At this stage, I apply rate limiting and subdomain filtering.

Then nginx forwards the streams to Unbound, which filters out any local IPs from the responses to avoid leaks.

Finally, Unbound forwards requests to my Pi-hole, where the magic happens.

somebudyelse 1 days ago [-]
Highly recommend https://nextdns.io, great for all kinds of blocking stuff. Plus Firefox or Edge for uBlock support.
subscribed 1 days ago [-]
Well, yeah, it's pretty good, but has a very low free tier limit. It's barely enough to cover my IOT subnet and subnet for stuff like AVR or TVs.

So if I'm supposed to pay for ad blocking, I might as well read the article and use one of the other methods[1] instead :)

[1] I was trying Rethink several times, but WG Tunnel with ad-- and tracker-blocking service works best for me.

pogue 24 hours ago [-]
I used NextDNS for a long time, but they offer absolutely zero support for their customers.

I ended up just switching to Control D's free tier using the Hagezi blocklist. You can try Normal, Pro & Pro+ for typical usage (I stick to pro normally). That + Brave and I'm pretty much ad free.

https://docs.controld.com/docs/free-dns

ignoramous 8 hours ago [-]
> ended up just switching to Control D's free tier using the Hagezi blocklist

HaGeZi recently launched their own public DNS-over-HTTPS / DNS-over-TLS resolvers: https://github.com/hagezi/dns-servers.

  # privacy
  root.hagezi.org
  # security
  ctif.hagezi.org
pogue 2 hours ago [-]
Very cool. I hope they get some NA server locations as ControlD has them beat there. Hagezi's DNS only use their Pro list + TIF, but if you wanted to use Normal or Light ControlD would still be a good option. I keep their TIF list in adblock.

https://controld.com/network

splatter9859 22 hours ago [-]
I used NextDNS for years and moved over to ControlD this year due to NextDNS literally not innovating at all and having no customer suppport. I've been much happier.
nyarlathotep_ 24 hours ago [-]
My current approach is AdGuard Home, WireGuard VPN to my home network the majority of the time.

This was all pretty simple to setup given hardware that supports VPN, DDNS, etc.

Worth noting too that just blocking hostnames is not enough; Netflix, as an example, uses Google's DNS servers (plain UDP) on some/most clients.

If the network the client operates on can't prevent DNS to other servers, that's a simple "bypass" vector.

AFAIK, the best you can get, given sufficient time, patience, and hardware is:

• something like the above

• blocking outbound DOT (853), DOQ (784, IIRC) excepting, perhaps, upstreams you trust

• blocking HTTPS to known DOH endpoints (Cloudflare, Google, etc)

• DNAT for plain DNS cases like the Netflix example above. (to your DNS server(s))

Even that there's plenty of hypothetical opportunities for clients to just use another DOH resolver outside of your domain/IP block lists.

janwillemb 1 days ago [-]
I point "private DNS" to my VPS with pihole and stunnel, works quite well. Adguard as private DNS is also effective.
OroPla 14 hours ago [-]
My solution was to not install anything with ads and to not browse the Internet on my phone.
jurakovic 1 days ago [-]
BLKNSLVR 1 days ago [-]
Whenever I'm out and about I connect to my home system via wireguard VPN, and all DNS traffic through my home system is funneled into PiHole. I also have a healthy collection of DNS block lists setup on the PiHole (which I'm currently setting up a site to explain/share).

I also have a VPS setup in a similar fashion in case my home connection fails for one of many reasons.

I try to only practice safe internet. Raw-dog the internet and you're asking for an infection.

xnx 1 days ago [-]
I want to use something like this, but I don't think I can when also using VPN by Google on an unrooted phone.
altairprime 21 hours ago [-]
It sounds like VPN by Google is an effective strategy for keeping users from using ad and tracking blockers, then; for contrast, iOS routes the connection to the private traffic server over your user VPN connection if one is active.
netsharc 1 days ago [-]
Your comment is how I found out about "VPN by Google".

I wonder how old it is and what their motivation is/was. Maybe to offer something comparable to Apple Private Browsing?

xnx 24 hours ago [-]
Google first offered it in 2020 as the Google One VPN: https://en.wikipedia.org/wiki/Google_One . It's probably most similar to Apple's iCloud Private Relay.
pmontra 1 days ago [-]
I am using Blockada 5 from https://blokada.org
methou 19 hours ago [-]
That's a long article about just DNS.

I'd expect mentioning of the good old Xposed framework.

epihelix 1 days ago [-]
Long-time AdAway user here (via root and a hosts file). I couldn't live without it. Simple and effective.
Sarkie 1 days ago [-]
Blockada old version.

And then add lists.

And add your own constantly when they miss

pizzaiolo 23 hours ago [-]
Why the old version?
jttnr 17 hours ago [-]
The new version requires a monthly subscription and is cloud based.
teo_zero 1 days ago [-]
Why do you need an app at all? Can't you just manually set a private VPN in the settings?
knifelemon 24 hours ago [-]
AdGuard its good
gremlinunderway 1 days ago [-]
>a rogue ad-blocker app is exactly as dangerous as a rogue VPN service. Fortunately, because these ad-blocking apps are usually open-source, there are limited opportunities for bad actors.

I find it naive to state this when earlier he noted that he's suspicious of free services without a clear funding model.

Sure, open source is certainly better than closed source, but its not like somehow magically it prevents exploitation. There's plenty of examples especially in a small project like this with few eyeballs. So why question the funding model of a free VPN but not question the funding model of an open source project? We just assume its being done out of good will? I find that perspective naive.

ndriscoll 1 days ago [-]
Not that this entirely clears the skepticism, but to directly address the question as asked: blocking ads scratches a clear itch for the author. FOSS works great because software has no marginal cost, so as long as someone wants it to exist badly enough to make it so, there's then no reason not to give it away to anyone else who wants it. Providing a free VPN service to the world is quite a bit less likely to be an author-itch, and actually incurs a cost.
Onavo 1 days ago [-]
Sigh, that's a lot of words to describe DNS based adblocking.

In Android you can either set your DNS server in the system settings or via the VPN API.

Sample code here https://github.com/t895/DNSNet/blob/a-couple-updates/service...

They both do the same thing. There are local device-only resolver apps like

https://rethinkdns.com/

https://github.com/m66b/netguard

Another famous one is DNS66 but it's sadly unmaintained. Avoid apps with the word "ad" in their name, they are usually semi commercial and can't be trusted.

Do note all of these methods can be overridden on the app level e.g. a lot of browsers come bundled with first party VPNs or use their own built-in resolvers.

If you want something more reliable, Firefox on Android with the UBlock Origin and Sponsorblock extensions is still the gold standard. Though do note the Android Firefox is extremely slow compared to the Chromium based browsers.

For app level ads, use an app patcher like https://github.com/morpheapp which can remove all in-app advertisements and inject sponsor blocking code.

Larrikin 1 days ago [-]
In what meaningful way is there any difference in speed between Chrome and Firefox on Android?

I also prefer replacing uBlock Origin with Ad Nauseum which is built on top of ubo.

Onavo 1 days ago [-]
On any media or JS heavy site, Firefox on Android lags. Also for whatever reason small stuff like text boxes, zoom, keyboard pop up and tab zoom out animations have significant jitter. UI elements seem to be out of step with platform conventions. It's not the sort of thing that's easy to file a bug report for but you need a staff UX and performance engineer to go over it with a fine toothed comb to iron out the bugs. The current version feels very raw. You get the same vibe as a poorly optimized React Native app. Slight jitters here and there and a dropped frame on some animations. There is plenty of small stuff like the tab switching animation that feels slow. Nothing that will show up on a screen recording but immediately obvious if you are switching between Chrome and Firefox running on the same device. I suspect the root cause is that Firefox implemented a significant part of their UI in JS/HTML instead of native but I haven't checked the source code so that's just a hypothesis. On 2026 flagships, there's no excuse for it not to have a butter smooth UI (Oryon core chips are approaching laptop level of performance).
epihelix 1 days ago [-]
I use a 2019 flagship phone (an s10e), and Firefox for Android is butter-smooth for me. So I cannot imagine why it would be janky for you with your multiple-times-faster modern phone?

Sounds like you're describing Firefox from around the time my phone was made (which was indeed slow and janky, and had lots of UI issues).

kuekacang 24 hours ago [-]
Had dailied redmi note 12 4g, with debloat, ublock and selective uscript block. Many js/media heavy websites (that needed to have their js enabled to be viewed) lagged under firefox
alekescu 1 days ago [-]
There is a special irony to an article about ad blocking containing an apparent undisclosed ad for Nord.
altairprime 1 days ago [-]
> an apparent undisclosed ad for Nord

What evidence supports the link referenced being an advertisement? I'm not seeing any referral, tracking, or any URI parameter data at all that would support the claim, and this seems to be their only instance of referring to it — where, in this 'state of the union' helpdesk-style article, one or more such 'VPN provider' links seems particularly relevant to visitors. (I do not use whatever this company's products are and have no opinion either way on them aside from mistrusting the claim presented here.)

Cider9986 1 days ago [-]
One time I saw someone trying to hide an Amazon affiliate link in a post by putting the link text as amazon.com/dp/12345 but the link was amazon.com/dp/12345/ref=tracking. There's no affiliate link for Nord here but it's weird to use it as an example over better options: https://www.privacyguides.org/en/vpn/
gruez 1 days ago [-]
>ref=tracking

Amazon's `ref` parameter isn't used for affiliate codes. It's certainly used for something, but given that internal links have it (eg. the logo in the top left has `/ref=nav_logo`), I wouldn't immediately conclude it's an affiliate link just because it has ref. Actual affiliate links are through the `tag` parameter.

Cider9986 1 days ago [-]
It was just an example of garbage I got at the end of the link when going to an amazon page. The deleted posts were affiliate links.
minouye 1 days ago [-]
It's a plain link--it's not an ad.
ignoramous 1 days ago [-]
The only link in the article with "in 2026" in the title...
1 days ago [-]
1 days ago [-]
Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
Rendered at 22:43:59 GMT+0000 (Coordinated Universal Time) with Vercel.