Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #207732 > unrolled thread

Re: firefox > Preferences > When Firefox starts.

Started bypeter@easthope.ca
First post2019-04-21 16:50 +0200
Last post2019-04-28 23:10 +0200
Articles 7 on this page of 27 — 9 participants

Back to article view | Back to linux.debian.user

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: firefox > Preferences > When Firefox starts. peter@easthope.ca - 2019-04-21 16:50 +0200
    Re: firefox > Preferences > When Firefox starts. Curt <curty@free.fr> - 2019-04-21 18:10 +0200
      Re: firefox > Preferences > When Firefox starts. peter@easthope.ca - 2019-04-22 04:30 +0200
        Re: firefox > Preferences > When Firefox starts. Curt <curty@free.fr> - 2019-04-23 16:10 +0200
    Re: firefox > Preferences > When Firefox starts. David Wright <deblis@lionunicorn.co.uk> - 2019-04-21 23:20 +0200
      Re: firefox > Preferences > When Firefox starts. peter@easthope.ca - 2019-04-22 06:20 +0200
        Re: firefox > Preferences > When Firefox starts. Greg Wooledge <wooledg@eeg.ccf.org> - 2019-04-22 15:10 +0200
          Re: firefox > Preferences > When Firefox starts. "der.hans" <deb-user@LuftHans.com> - 2019-04-23 17:40 +0200
            Re: firefox > Preferences > When Firefox starts. Curt <curty@free.fr> - 2019-04-23 18:00 +0200
              Re: firefox > Preferences > When Firefox starts. David Wright <deblis@lionunicorn.co.uk> - 2019-04-23 19:30 +0200
                Re: firefox > Preferences > When Firefox starts. "der.hans" <deb-user@LuftHans.com> - 2019-04-23 20:20 +0200
                  Re: firefox > Preferences > When Firefox starts. David Wright <deblis@lionunicorn.co.uk> - 2019-04-24 17:20 +0200
                    Re: firefox > Preferences > When Firefox starts. "der.hans" <deb-user@LuftHans.com> - 2019-04-24 18:30 +0200
                      Re: firefox > Preferences > When Firefox starts. David Wright <deblis@lionunicorn.co.uk> - 2019-04-25 05:30 +0200
              Re: firefox > Preferences > When Firefox starts. "der.hans" <deb-user@LuftHans.com> - 2019-04-23 19:40 +0200
        Re: firefox > Preferences > When Firefox starts. David Wright <deblis@lionunicorn.co.uk> - 2019-04-22 20:50 +0200
          Browser usage; was "Re: firefox > Preferences > When Firefox starts." peter@easthope.ca - 2019-04-22 22:50 +0200
            Re: Browser usage; was "Re: firefox > Preferences > When Firefox  starts." Curt <curty@free.fr> - 2019-04-23 09:40 +0200
              Re: Browser usage; was "Re: firefox > Preferences > When Firefox starts." rhkramer@gmail.com - 2019-04-23 17:40 +0200
                Re: Browser usage; was "Re: firefox > Preferences > When Firefox  starts." Reco <recoverym4n@enotuniq.net> - 2019-04-23 18:10 +0200
          Re: firefox > Preferences > When Firefox starts. <tomas@tuxteam.de> - 2019-04-23 09:30 +0200
          Re: firefox > Preferences > When Firefox starts. David Wright <deblis@lionunicorn.co.uk> - 2019-04-24 17:40 +0200
            Re: firefox > Preferences > When Firefox starts. Lee <ler762@gmail.com> - 2019-04-24 20:30 +0200
              Re: firefox > Preferences > When Firefox starts. David Wright <deblis@lionunicorn.co.uk> - 2019-04-25 07:10 +0200
                Re: firefox > Preferences > When Firefox starts. Lee <ler762@gmail.com> - 2019-04-25 18:30 +0200
                  Re: firefox > Preferences > When Firefox starts. David Wright <deblis@lionunicorn.co.uk> - 2019-04-28 02:40 +0200
                    Re: firefox > Preferences > When Firefox starts. Lee <ler762@gmail.com> - 2019-04-28 23:10 +0200

Page 2 of 2 — ← Prev page 1 [2]


#207783

From<tomas@tuxteam.de>
Date2019-04-23 09:30 +0200
Message-ID<xPY2m-1as-11@gated-at.bofh.it>
In reply to#207772

[Multipart message — attachments visible in raw view] — view raw

On Mon, Apr 22, 2019 at 01:43:46PM -0500, David Wright wrote:

[...]

> The other way round: I bank as me, and browse as user "flash", hence

Aha. To add one data point: I chose a bank which doesn't require
me to browse to do electronic banking. Glad I did -- I just do
my transfers and fetch account info with a shell script.

Revenue services... alas [1]. For them I just have a separate
user (I do use browser profiles for other things, but I prefer
to trust Unix-style access controls for "important things".

cheers

[1] It's far more difficult to "choose" who you pay taxes
   to -- in the best case you "elect" them :-)
-- t

[toc] | [prev] | [next] | [standalone]


#207823

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2019-04-24 17:40 +0200
Message-ID<xQsa6-2w3-7@gated-at.bofh.it>
In reply to#207772
[I presume that replying only to me was a mistake.]

On Tue 23 Apr 2019 at 10:38:41 (-0400), Lee wrote:
> On 4/22/19, David Wright <deblis@lionunicorn.co.uk> wrote:
> > On Sun 21 Apr 2019 at 20:30:53 (-0700), peter@easthope.ca wrote:
> >>     From: David Wright <deblis@lionunicorn.co.uk>
> >>     Date: Sun, 21 Apr 2019 16:13:11 -0500
> >> > Does the behaviour reported in your OP cause you *great* concern?
> >>
> >> No.  Just wastes time.  Opening a simple local HTML home page requires
> >> roughly a minute rather than roughly a second.
> >
> > I tend to forget that, because my /etc/hosts file has ~14000 lines,
> > pages appear a lot faster here.
> 
> Have you looked at bind's dns rpz?

Just now.

>   http://zytrax.com/books/dns/ch7/rpz.html
> It lets you do things like
> *.2o7.net               CNAME   .
> *.doubleclick.net       CNAME   .
> 
> to block entire domains instead of having to list each and every
> hostname in the domain.
> 
> And you can log what is blocked/allowed to make troubleshooting easier

It might be a good *mechanism* for the diversion itself, but AFAICT
it's aimed at the *policy* implementers rather than the end-user.

The value I get from Dan Pollock is the list of sites rather than the
most elegant mechanism for handling that list. Looking at the comments
in the list, and by comparing evolving versions, it does appear that
Dan actively "opens holes" where people report interference or
difficulties using certain legitimate sites.

Finally, I wouldn't know where to start to compile a list of sites
like that.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#207829

FromLee <ler762@gmail.com>
Date2019-04-24 20:30 +0200
Message-ID<xQuOB-49W-3@gated-at.bofh.it>
In reply to#207823
On 4/24/19, David Wright <deblis@lionunicorn.co.uk> wrote:
> [I presume that replying only to me was a mistake.]

Nope, responding to your "my /etc/hosts file has ~14000 lines" didn't
seem all that germane to the thread.  & not that this is either, but
if you'd prefer to keep it on the list I don't mind.

> On Tue 23 Apr 2019 at 10:38:41 (-0400), Lee wrote:
>> On 4/22/19, David Wright <deblis@lionunicorn.co.uk> wrote:
>> > On Sun 21 Apr 2019 at 20:30:53 (-0700), peter@easthope.ca wrote:
>> >>     From: David Wright <deblis@lionunicorn.co.uk>
>> >>     Date: Sun, 21 Apr 2019 16:13:11 -0500
>> >> > Does the behaviour reported in your OP cause you *great* concern?
>> >>
>> >> No.  Just wastes time.  Opening a simple local HTML home page requires
>> >> roughly a minute rather than roughly a second.
>> >
>> > I tend to forget that, because my /etc/hosts file has ~14000 lines,
>> > pages appear a lot faster here.
>>
>> Have you looked at bind's dns rpz?
>
> Just now.
>
>>   http://zytrax.com/books/dns/ch7/rpz.html
>> It lets you do things like
>> *.2o7.net               CNAME   .
>> *.doubleclick.net       CNAME   .
>>
>> to block entire domains instead of having to list each and every
>> hostname in the domain.
>>
>> And you can log what is blocked/allowed to make troubleshooting easier
>
> It might be a good *mechanism* for the diversion itself, but AFAICT
> it's aimed at the *policy* implementers rather than the end-user.

Just out of curiosity - do you think pi-hole is aimed at policy
implementers or end users?

> The value I get from Dan Pollock is the list of sites rather than the
> most elegant mechanism for handling that list. Looking at the comments
> in the list, and by comparing evolving versions, it does appear that
> Dan actively "opens holes" where people report interference or
> difficulties using certain legitimate sites.
>
> Finally, I wouldn't know where to start to compile a list of sites
> like that.

https://dnsrpz.info/
If you're a business, you can buy access to an rpz feed.

If you're a [home?] network admin it's simple enough to enable logging
& see what all is allowed that you'd rather have blocked.  And/or grab
things like Dan Pollock's list and turn them into an rpz file.  I just
don't like the size & the churn in curated host files - I'd rather
have a single line
*.advertisingdomain.tld
and have them all blocked vs. the maybe hundreds of lines blocking
each specific host.

Regards,
Lee

[toc] | [prev] | [next] | [standalone]


#207843

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2019-04-25 07:10 +0200
Message-ID<xQENX-1Zy-1@gated-at.bofh.it>
In reply to#207829
On Wed 24 Apr 2019 at 14:29:00 (-0400), Lee wrote:
> On 4/24/19, David Wright <deblis@lionunicorn.co.uk> wrote:
> > [I presume that replying only to me was a mistake.]
> 
> Nope, responding to your "my /etc/hosts file has ~14000 lines" didn't
> seem all that germane to the thread.  & not that this is either, but
> if you'd prefer to keep it on the list I don't mind.

The OP posted a startup problem. Later they stated that their main
concern was the time taken to open pages, as quoted immediately
below. My 14000 line /etc/hosts is installed with the main purpose
of speeding up page rendering. So was using Opera, but I found it
had this major startup problem.

> > On Tue 23 Apr 2019 at 10:38:41 (-0400), Lee wrote:
> >> On 4/22/19, David Wright <deblis@lionunicorn.co.uk> wrote:
> >> > On Sun 21 Apr 2019 at 20:30:53 (-0700), peter@easthope.ca wrote:
> >> >>     From: David Wright <deblis@lionunicorn.co.uk>
> >> >>     Date: Sun, 21 Apr 2019 16:13:11 -0500
> >> >> > Does the behaviour reported in your OP cause you *great* concern?
> >> >>
> >> >> No.  Just wastes time.  Opening a simple local HTML home page requires
> >> >> roughly a minute rather than roughly a second.
> >> >
> >> > I tend to forget that, because my /etc/hosts file has ~14000 lines,
> >> > pages appear a lot faster here.
> >>
> >> Have you looked at bind's dns rpz?
> >
> > Just now.
> >
> >>   http://zytrax.com/books/dns/ch7/rpz.html
> >> It lets you do things like
> >> *.2o7.net               CNAME   .
> >> *.doubleclick.net       CNAME   .
> >>
> >> to block entire domains instead of having to list each and every
> >> hostname in the domain.
> >>
> >> And you can log what is blocked/allowed to make troubleshooting easier
> >
> > It might be a good *mechanism* for the diversion itself, but AFAICT
> > it's aimed at the *policy* implementers rather than the end-user.
> 
> Just out of curiosity - do you think pi-hole is aimed at policy
> implementers or end users?

I don't know about their policies, or whether they have any. I've not
found any description of how you would configure it, only how you
install it. Do they provide blacklists?

It's also not clear to me where I should install it to. My router
uses the Google nameservers, and all my machines have the router
as their nameserver. The router is the only part of the network
that's always up and running.

But let me explain what I mean by those terms I used earlier:

    Mechanism: Any method of modifying the result of trying to resolve
    foo.bar to an IP address, irrespective of the specific domainnames
    which somebody has to give to it. My mechanism is resolving to
    localhost.

    Policy implementers: The people who make the decisions about which
    domainnames should have their resolution modified. If you look
    through the reference I gave for the source of my /etc/hosts, you
    can see their policies listed as comments bracketing the sections,
    and they are:

      #<shock-sites>
      #<shortcut-examples>
      #<hijack-sites>
      #<spyware-sites>
      #<maybe-spy>
      #<malware-sites>
      #<doubleclick-sites>
      #<intellitxt-sites>
      #<red-sheriff-sites>
      #<cydoor-sites>
      #<2o7-sites>
      #<oewabox-sites>
      #<ad-sites>
      #<maybe-ads>
      #<canvass-fingerprinting-sites>
      #<evercookies-sites>
      #<yahoo-ad-sites>
      #<hitbox-sites>
      #<extreme-dm-sites>
      #<realmedia-sites>
      #<fastclick-sites>
      #<belo-interactive-sites>
      #<popup-traps>
      #<ecard-scam-sites>
      #<IVW-sites>
      #<wiki-spam-sites>
      #<Windows10>

    End-users: The people whose browsing experience are improved by
    the policies selected, and implemented using the chosen mechanism.

> > The value I get from Dan Pollock is the list of sites rather than the
> > most elegant mechanism for handling that list. Looking at the comments
> > in the list, and by comparing evolving versions, it does appear that
> > Dan actively "opens holes" where people report interference or
> > difficulties using certain legitimate sites.
> >
> > Finally, I wouldn't know where to start to compile a list of sites
> > like that.
> 
> https://dnsrpz.info/
> If you're a business, you can buy access to an rpz feed.

I'm not, but I take it that different feeds have different policies on
which sites to include, and come at different prices.

> If you're a [home?] network admin it's simple enough to enable logging
> & see what all is allowed that you'd rather have blocked.  And/or grab
> things like Dan Pollock's list and turn them into an rpz file.

Frankly, I don't want to be bothered with processing the list.

And, of course, logging a site means that you must have already
encountered it, which defeats the object of having those "shock
sites" listed: the point is not to see them at all.

> I just
> don't like the size & the churn in curated host files - I'd rather
> have a single line
> *.advertisingdomain.tld
> and have them all blocked vs. the maybe hundreds of lines blocking
> each specific host.

I can see that one or two sections of Dan's list could be factorized
into a *.foo.bar pattern, but as compressing the file only gives 75%
reduction, there are still a lot of sites to be fed into whichever
mechanism you choose for resolving/diverting them.

And finally, I'm not sure whether it's been mentioned in this thread,
but there's a reason I wrote "Does the behaviour reported in your OP
cause you *great* concern?". I should then have reported the fact that
when I get the page with "Sorry, we're having trouble getting your
pages back", I just press Return, and all the Tabs reappear.
So for me, that message has been a non-issue for several years.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#207859

FromLee <ler762@gmail.com>
Date2019-04-25 18:30 +0200
Message-ID<xQPq1-8k9-1@gated-at.bofh.it>
In reply to#207843
On 4/25/19, David Wright <deblis@lionunicorn.co.uk> wrote:
> On Wed 24 Apr 2019 at 14:29:00 (-0400), Lee wrote:
>> On 4/24/19, David Wright <deblis@lionunicorn.co.uk> wrote:
>> > On Tue 23 Apr 2019 at 10:38:41 (-0400), Lee wrote:
>> >> On 4/22/19, David Wright <deblis@lionunicorn.co.uk> wrote:
>> >> > On Sun 21 Apr 2019 at 20:30:53 (-0700), peter@easthope.ca wrote:
>> >> >>     From: David Wright <deblis@lionunicorn.co.uk>
>> >> >>     Date: Sun, 21 Apr 2019 16:13:11 -0500
>> >> >> > Does the behaviour reported in your OP cause you *great* concern?
>> >> >>
>> >> >> No.  Just wastes time.  Opening a simple local HTML home page
>> >> >> requires
>> >> >> roughly a minute rather than roughly a second.
>> >> >
>> >> > I tend to forget that, because my /etc/hosts file has ~14000 lines,
>> >> > pages appear a lot faster here.
>> >>
>> >> Have you looked at bind's dns rpz?
>> >
>> > Just now.
>> >
>> >>   http://zytrax.com/books/dns/ch7/rpz.html
>> >> It lets you do things like
>> >> *.2o7.net               CNAME   .
>> >> *.doubleclick.net       CNAME   .
>> >>
>> >> to block entire domains instead of having to list each and every
>> >> hostname in the domain.
>> >>
>> >> And you can log what is blocked/allowed to make troubleshooting easier
>> >
>> > It might be a good *mechanism* for the diversion itself, but AFAICT
>> > it's aimed at the *policy* implementers rather than the end-user.
>>
>> Just out of curiosity - do you think pi-hole is aimed at policy
>> implementers or end users?
>
> I don't know about their policies, or whether they have any. I've not
> found any description of how you would configure it, only how you
> install it. Do they provide blacklists?

It looks like they give you a default list of lists that you can modify:
https://github.com/pi-hole/pi-hole/blob/master/automated%20install/basic-install.sh#L1181

> It's also not clear to me where I should install it to. My router
> uses the Google nameservers, and all my machines have the router
> as their nameserver. The router is the only part of the network
> that's always up and running.

I have a server that I leave running all the time; reconfigure your
router to use your dns server instead of google, add a firewall rule
to block all outgoing tcp/udp traffic to port 53 except from the
server & you're done.

> But let me explain what I mean by those terms I used earlier:
>
>     Mechanism: Any method of modifying the result of trying to resolve
>     foo.bar to an IP address, irrespective of the specific domainnames
>     which somebody has to give to it. My mechanism is resolving to
>     localhost.
>
>     Policy implementers: The people who make the decisions about which
>     domainnames should have their resolution modified. If you look
>     through the reference I gave for the source of my /etc/hosts, you
>     can see their policies listed as comments bracketing the sections,
>     and they are:
>
>       #<shock-sites>
>       #<shortcut-examples>
>       #<hijack-sites>
>       #<spyware-sites>
>       #<maybe-spy>
>       #<malware-sites>
>       #<doubleclick-sites>
>       #<intellitxt-sites>
>       #<red-sheriff-sites>
>       #<cydoor-sites>
>       #<2o7-sites>
>       #<oewabox-sites>
>       #<ad-sites>
>       #<maybe-ads>
>       #<canvass-fingerprinting-sites>
>       #<evercookies-sites>
>       #<yahoo-ad-sites>
>       #<hitbox-sites>
>       #<extreme-dm-sites>
>       #<realmedia-sites>
>       #<fastclick-sites>
>       #<belo-interactive-sites>
>       #<popup-traps>
>       #<ecard-scam-sites>
>       #<IVW-sites>
>       #<wiki-spam-sites>
>       #<Windows10>
>
>     End-users: The people whose browsing experience are improved by
>     the policies selected, and implemented using the chosen mechanism.
>
>> > The value I get from Dan Pollock is the list of sites rather than the
>> > most elegant mechanism for handling that list. Looking at the comments
>> > in the list, and by comparing evolving versions, it does appear that
>> > Dan actively "opens holes" where people report interference or
>> > difficulties using certain legitimate sites.

But the holes get opened only after someone reports a problem.  If
you're using a host file, how do you figure out which host name(s)
being blocked are causing the problem?

I never figured out an easy way to troubleshoot hostfiles & switched
to something that logged what all was blocked and allowed.

>> > Finally, I wouldn't know where to start to compile a list of sites
>> > like that.
>>
>> https://dnsrpz.info/
>> If you're a business, you can buy access to an rpz feed.
>
> I'm not, but I take it that different feeds have different policies on
> which sites to include, and come at different prices.
>
>> If you're a [home?] network admin it's simple enough to enable logging
>> & see what all is allowed that you'd rather have blocked.  And/or grab
>> things like Dan Pollock's list and turn them into an rpz file.
>
> Frankly, I don't want to be bothered with processing the list.

That makes it easy then, stay with what you've got :)

Regards,
Lee

[toc] | [prev] | [next] | [standalone]


#207919

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2019-04-28 02:40 +0200
Message-ID<xRG1j-6I4-3@gated-at.bofh.it>
In reply to#207859
On Thu 25 Apr 2019 at 12:28:37 (-0400), Lee wrote:
> On 4/25/19, David Wright <deblis@lionunicorn.co.uk> wrote:
> > On Wed 24 Apr 2019 at 14:29:00 (-0400), Lee wrote:
> >> On 4/24/19, David Wright <deblis@lionunicorn.co.uk> wrote:
> >> > On Tue 23 Apr 2019 at 10:38:41 (-0400), Lee wrote:
> >> >> On 4/22/19, David Wright <deblis@lionunicorn.co.uk> wrote:
> >> >> > On Sun 21 Apr 2019 at 20:30:53 (-0700), peter@easthope.ca wrote:
> >> >> >>     From: David Wright <deblis@lionunicorn.co.uk>
> >> >> >>     Date: Sun, 21 Apr 2019 16:13:11 -0500
> >> >> >> > Does the behaviour reported in your OP cause you *great* concern?
> >> >> >>
> >> >> >> No.  Just wastes time.  Opening a simple local HTML home page
> >> >> >> requires
> >> >> >> roughly a minute rather than roughly a second.
> >> >> >
> >> >> > I tend to forget that, because my /etc/hosts file has ~14000 lines,
> >> >> > pages appear a lot faster here.
> >> >>
> >> >> Have you looked at bind's dns rpz?
> >> >
> >> > Just now.
> >> >
> >> >>   http://zytrax.com/books/dns/ch7/rpz.html
> >> >> It lets you do things like
> >> >> *.2o7.net               CNAME   .
> >> >> *.doubleclick.net       CNAME   .
> >> >>
> >> >> to block entire domains instead of having to list each and every
> >> >> hostname in the domain.
> >> >>
> >> >> And you can log what is blocked/allowed to make troubleshooting easier
> >> >
> >> > It might be a good *mechanism* for the diversion itself, but AFAICT
> >> > it's aimed at the *policy* implementers rather than the end-user.
> >>
> >> Just out of curiosity - do you think pi-hole is aimed at policy
> >> implementers or end users?
> >
> > I don't know about their policies, or whether they have any. I've not
> > found any description of how you would configure it, only how you
> > install it. Do they provide blacklists?
> 
> It looks like they give you a default list of lists that you can modify:
> https://github.com/pi-hole/pi-hole/blob/master/automated%20install/basic-install.sh#L1181

Yes, and taking one of the sites mentioned, I see they explain their
policy at https://hosts-file.net/?s=policy
and that's what I want done for me.

> > It's also not clear to me where I should install it to. My router
> > uses the Google nameservers, and all my machines have the router
> > as their nameserver. The router is the only part of the network
> > that's always up and running.
> 
> I have a server that I leave running all the time;

… and I don't.

> reconfigure your
> router to use your dns server

… which doesn't exist …

> instead of google, add a firewall rule
> to block all outgoing tcp/udp traffic to port 53 except from the
> server & you're done.
> 
> > But let me explain what I mean by those terms I used earlier:
> >
> >     Mechanism: Any method of modifying the result of trying to resolve
> >     foo.bar to an IP address, irrespective of the specific domainnames
> >     which somebody has to give to it. My mechanism is resolving to
> >     localhost.
> >
> >     Policy implementers: The people who make the decisions about which
> >     domainnames should have their resolution modified. If you look
> >     through the reference I gave for the source of my /etc/hosts, you
> >     can see their policies listed as comments bracketing the sections,
> >     and they are:
> >
[snipped]
> >
> >     End-users: The people whose browsing experience are improved by
> >     the policies selected, and implemented using the chosen mechanism.
> >
> >> > The value I get from Dan Pollock is the list of sites rather than the
> >> > most elegant mechanism for handling that list. Looking at the comments
> >> > in the list, and by comparing evolving versions, it does appear that
> >> > Dan actively "opens holes" where people report interference or
> >> > difficulties using certain legitimate sites.
> 
> But the holes get opened only after someone reports a problem.  If
> you're using a host file, how do you figure out which host name(s)
> being blocked are causing the problem?

I guess the people who report the problem figure that out. Looking at
the comments, they're not services that I use.

> I never figured out an easy way to troubleshoot hostfiles & switched
> to something that logged what all was blocked and allowed.

That would be easy to check. I build /etc/hosts with a commandline:

# cat /root/hosts-[0-9]-*[^~] | sed -e "/^[[:space:]]*192.168.1.[0-9]\+[[:sp
ace:]]\+$HOSTNAME.corp[[:space:]]\+$HOSTNAME\$/s/[[:space:]]*\([0-9.]\+\)[[:sp
ace:]]\+\(.*\)\$/127.0.1.1\t\2\t# \1/" > /etc/hosts

so I would hide Dan's file (whose final destination is a file that
matches /root/hosts-[0-9]-*[^~]) before rerunning that command.

> >> > Finally, I wouldn't know where to start to compile a list of sites
> >> > like that.
> >>
> >> https://dnsrpz.info/
> >> If you're a business, you can buy access to an rpz feed.
> >
> > I'm not, but I take it that different feeds have different policies on
> > which sites to include, and come at different prices.
> >
> >> If you're a [home?] network admin it's simple enough to enable logging
> >> & see what all is allowed that you'd rather have blocked.  And/or grab
> >> things like Dan Pollock's list and turn them into an rpz file.
> >
> > Frankly, I don't want to be bothered with processing the list.
> 
> That makes it easy then, stay with what you've got :)

Sure. I like to publicise it when I'm reminded that its use might help
someone else fix any sort of problem.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#207951

FromLee <ler762@gmail.com>
Date2019-04-28 23:10 +0200
Message-ID<xRZdD-1Ad-13@gated-at.bofh.it>
In reply to#207919
Hi David,

I think we're both going for
> I like to publicise it when I'm reminded that its use might help
> someone else fix any sort of problem.

so I snipped a lot; hopefully without messing up who wrote what.

On 4/27/19, David Wright <deblis@lionunicorn.co.uk> wrote:
> On Thu 25 Apr 2019 at 12:28:37 (-0400), Lee wrote:
>> On 4/25/19, David Wright <deblis@lionunicorn.co.uk> wrote:
>> > On Wed 24 Apr 2019 at 14:29:00 (-0400), Lee wrote:
>> >> On 4/24/19, David Wright <deblis@lionunicorn.co.uk> wrote:

>> >> > The value I get from Dan Pollock is the list of sites rather than
>> >> > the
>> >> > most elegant mechanism for handling that list. Looking at the
>> >> > comments
>> >> > in the list, and by comparing evolving versions, it does appear that
>> >> > Dan actively "opens holes" where people report interference or
>> >> > difficulties using certain legitimate sites.
>>
>> But the holes get opened only after someone reports a problem.  If
>> you're using a host file, how do you figure out which host name(s)
>> being blocked are causing the problem?
>
> I guess the people who report the problem figure that out. Looking at
> the comments, they're not services that I use.

Some of the services are things I've used, or at least wanted to take
a look at, which is why I brought up
>> I never figured out an easy way to troubleshoot hostfiles & switched
>> to something that logged what all was blocked and allowed.
>
> That would be easy to check. I build /etc/hosts with a commandline:
>
> # cat /root/hosts-[0-9]-*[^~] | sed -e
> "/^[[:space:]]*192.168.1.[0-9]\+[[:sp
> ace:]]\+$HOSTNAME.corp[[:space:]]\+$HOSTNAME\$/s/[[:space:]]*\([0-9.]\+\)[[:sp
> ace:]]\+\(.*\)\$/127.0.1.1\t\2\t# \1/" > /etc/hosts
>
> so I would hide Dan's file (whose final destination is a file that
> matches /root/hosts-[0-9]-*[^~]) before rerunning that command.

That looks like an all-or-nothing on/off switch for your
ad/malware/etc. hosts file.  Which isn't a problem if you've never had
a blacklist prevent you from getting to wherever it is you want to go,
but I've had blacklists block more than I want so I'd rather be able
figure out what needs to be allowed, fix the problem & keep everything
else blocked.

For a single host solution like /etc/hosts, I like
- privoxy so you can see what all is blocked/allowed
    https://packages.debian.org/stretch/privoxy
- grab some blacklist files & turn them into a privoxy action files.
eg. something along the lines of
    echo "{ +block{someonewhocares hosts file} }" > swc-hosts.txt
    curl https://someonewhocares.org/hosts/hosts | grep '^127\.0\.0\.1 ' |\
    sed -e 's/127\.0\.0\.1 //' >> swc-hosts.txt
    # sanity checks, backup, whatever before
    mv swc-hosts.txt  swc-hosts.action
- create a privoxy whitelist action file for sites you don't want
blocked even if they show up in one of your blacklists
    echo "{-block}" > whitelist.action
    echo "localhost" >> whitelist.action
- add swc-hosts.action and whitelist.action to the privoxy config
- tell your browser to use 127.0.0.1:8118 as it's http & https proxy

You can leave privoxy logging enabled all the time if you're curious
or just turn it on as needed to figure out what needs to be allowed to
unbreak some website.

And you can do things like
{ +block{TLDs I probably don't want} }
.ad/
.biz/
.cn/

I've got one exception for
 .cn/
three for
 .biz/
and none for
 .ad/


> I like to publicise it when I'm reminded that its use might help
> someone else fix any sort of problem.

Same here ;)

Regards,
Lee

[toc] | [prev] | [standalone]


Page 2 of 2 — ← Prev page 1 [2]

Back to top | Article view | linux.debian.user


csiph-web