crssi / NextDNS-Config

GNU General Public License v3.0
27 stars 7 forks source link

Details about your deny list #5

Closed beerisgood closed 3 years ago

beerisgood commented 3 years ago

Why did you add

gvt2.com
pubnub.com
s0.2mdn.net

?

crssi commented 3 years ago

gvt2.com very prevalent on android devices... covers all the beacons at gvt2 and gvt3 and denying it did not cause any breakages. pubnub.com is very prevalent from one of my devices (that is harmony controller), denying it did not cause any breakages and I don't like the idea someone should know every button click on my TV controller. s0.2mdn.net is quite prevalent here, denying it did not cause any breakages.

If you have some info/ideas/concerns to share, please, do so, I am very interested.

beerisgood commented 3 years ago

I am just missing an explanation why these domains are blocked.

So, i make some research about gvt2.com "Beacons" like beacons.gcp.gvt2.com & beacons.gvt2.com. They're used for Google DNS services: https://www.whois.com/whois/gvt2.com

ns1.google.com
ns2.google.com
ns3.google.com
ns4.google.com

-> https://cloud.google.com/dns/docs/dns-overview

Don't think this is a good idea as it will break stuff.

s0.2mdn.net is part of Google DoubleClick and aren't blocked by OISD. It's even whitelisted: https://oisd.nl/excludes.php?w=s0.2mdn.net

crssi commented 3 years ago

https://cloud.google.com/dns/docs/dns-overview

Don't think this is a good idea as it will break stuff.

Do you have a single example? About 10 android devices here and after about a year of blocking no problems were found.

s0.2mdn.net is part of Google DoubleClick and aren't blocked by OISD. It's even whitelisted: https://oisd.nl/excludes.php?w=s0.2mdn.net

It is whitelisted by whitelist upstreams used by OISD. Unfortunately upstreams are very slow to respond. See: https://github.com/FadeMind/hosts.extras/issues/49 https://github.com/StevenBlack/hosts/issues/1560 https://github.com/EnergizedProtection/unblock/issues/6 https://github.com/notracking/hosts-blocklists-scripts/issues/6

Do you have a single example that can be tested where denying this host will break anything?

Any input from you is welcome. Cheers

beerisgood commented 3 years ago

stevenblack only adds external lists to his own and is also not good at removing false positives. he said himself that it is too much work for him.

Do you have a single example that can be tested where denying this host will break anything?

I got some random WiFi disconnects with my phone. Will do more testing. Anyway, blocking without reason isn't recommend and will breaks even if you don't see it in first place. Enumerating badness also doesn't work, so we should keep on blocking only harmful stuff.

crssi commented 3 years ago

I got some random WiFi disconnects with my phone. Will do more testing.

Cool... that is something, mbe what happens on some public hotspots. Cannot wait for feedback. 👍

Anyway, blocking without reason isn't recommend and will breaks even if you don't see it in first place. Enumerating badness also doesn't work, so we should keep on blocking only harmful stuff.

As said, its out of a really long time observation/logging and something that connects to internet non-explainable several hundred times a day is questionable... which is even more questionable when nothing breaks by denying it.

beerisgood commented 3 years ago

As said, its out of a really long time observation/logging and something that connects to internet non-explainable several hundred times a day is questionable... which is even more questionable when nothing breaks by denying it.

That isn't a problem, and many programs or products do. These requests are mostly only a connection test without any data. But blocking them end in higher requests and may end in misbehaviour. Always depending on integrated fallback.

crssi commented 3 years ago

All abbreviations of gvt2.com are covered by 1Hosts Lite and OISD.

I don't like s0.2mdn.net. Its google tracking site and ATM I know for only one page where the breakage, which is https://www.zdnet.com/video/the-first-amendment-vs-tech-giants-ray-wang-explains-your-digital-rights/. I don't care about one domain, where "my" users doesn't browse ever. I have removed it from template... for now.

It there anything else questionable?

beerisgood commented 3 years ago

Looks fine to me

crssi commented 3 years ago

Great 😄 I am looking at Peter Lowe list to fulfill small gap of domains/hosts that his list covers. Would you mind test it too?

Cheers and beers 😄

beerisgood commented 3 years ago

Great 😄 I am looking at Peter Lowe list to fulfill small gap of domains/hosts that his list covers. Would you mind test it too?

Cheers and beers 😄

What's wrong with OISD list?

🍺

crssi commented 3 years ago

What's wrong with OISD list?

Absolutely nothing is wrong with OISD and it is gorgeous, as it is also 1Hosts Lite.