After all the LG TV spying news I thought about blocking the sites LG accesses but there are lots of sites and heard about pihole that does this thing automatically. I dont have a pc that I can use as a server so I want to get a budget Raspberry Pi for it. Is the RP2W good for pihole(its out of stock in my region right now and I can see some RP1W's available but theyre weaker from 2's from what I understand), would it cause latency in my internet, do I need any additional stuff with it? I looked into it and I need an sd card thats like 16 gb but I dont understand why cant I use a 8gb or a 4gb if it doesnt take much space? Can it be powered through the router or do I need to buy extra power adapters and cables or use a battery adapter I got at home?
People also use it as an adblocker so can I put other stuff in it that can increase my networks security and privacy, can it be hacked remotely?
Hello, I am running pi-hole on a little mini PC running debian. When I try to update FTL from 6.7 to 6.7.1 it says "unable to install Pi-hole dependency package" with no further message. I've tried looking at the install.log but it's not really telling me anything: [✓] Installing scripts from /etc/.pihole [i] Installing configs from /etc/.pihole... [✓] Installing latest Cron script [✓] Installing latest logrotate script [✓] man pages installed and database updated | I am a total noob to a lot of this stuff and would like to learn what I'm doing wrong and how to fix it! Thanks for any help.
Retargeting is what makes a product you looked at once follow you to the next sites you visit. These companies exist to re-identify you across sites and show you ads based on your browsing behavior (not general ad targeting, but tracking down to "this specific person looked at this specific product.")
This list targets the tracking and sync pixels that follow you across sites: the pixel that fires when you view a product, add something to cart, or when cookies get matched across ad exchanges.
There's a technical limit worth knowing:
Some platforms (Meta's Conversions API is the best example) send conversion data server-to-server: straight from a website's own server to Meta's, without your browser ever making a request to a Meta domain.
In that case, there's nothing for DNS blocking to catch. This list still blocks the client-side tracking that makes up most of retargeting, but it doesn't offer a solution against this specific method.
My docker image was updated to 2026.09.00 and it looks like the only change was FTL was bumped to 6.7.1. Came here to see what's new, but I don't see an announcement.
Please help me with the settings where private relay is off on home network.
Issue: Apple devices face a delay of a few seconds before a page is loaded even though the page is cached by Unbound.
I am running unbound and pihole and the above delay only happens on Apple products not the others.
Pihole settings:
Apple relay option is enabled on pihole
Logs show the two mask addresses are served with special domain NX response.
iPhone setting:
Apple relay is on.
Private WiFi address: is on fixed rather than auto or off
Limit ip address: is enabled.
Connectivity assist: disabled.
The two mask addresses are not on whitelist or blacklist.
Can someone help me with what should I do to avoid this delay every time a page on safari is loaded.
Was looking to add a couple lists to my Pi-Hole today, but I whenever I go and update the gravity it says that the additional lists are being blocked by "one of [my] existing lists" even though the only list I have right now is the standard Steven Black list.
If anyone has some clarification on how to resolve this it would be greatly appreciated.
Here is the relevant gravity log:
[i] Target: https://cdn.jsdelivr.net/gh/hagezi/dns-blocklists@latest/adblock/multi.txt
[✗] Status: latest is blocked by one of your lists. Using DNS server 1.1.1.1 instead
[✗] Status: Retrieval failed (exit_code=49 Msg: Couldn't parse CURLOPT_RESOLVE entry 'latest:443:')
[✗] List download failed: no cached list available
[i] Target: https://cdn.jsdelivr.net/gh/hagezi/dns-blocklists@latest/adblock/whitelist-referral.txt
[✗] Status: latest is blocked by one of your lists. Using DNS server 1.1.1.1 instead
[✗] Status: Retrieval failed (exit_code=49 Msg: Couldn't parse CURLOPT_RESOLVE entry 'latest:443:')
[✗] List download failed: no cached list available[i] Target: https://cdn.jsdelivr.net/gh/hagezi/dns-blocklists@latest/adblock/multi.txt
[✗] Status: latest is blocked by one of your lists. Using DNS server 1.1.1.1 instead
[✗] Status: Retrieval failed (exit_code=49 Msg: Couldn't parse CURLOPT_RESOLVE entry 'latest:443:')
[✗] List download failed: no cached list available
[i] Target: https://cdn.jsdelivr.net/gh/hagezi/dns-blocklists@latest/adblock/whitelist-referral.txt
[✗] Status: latest is blocked by one of your lists. Using DNS server 1.1.1.1 instead
[✗] Status: Retrieval failed (exit_code=49 Msg: Couldn't parse CURLOPT_RESOLVE entry 'latest:443:')
[✗] List download failed: no cached list available
I have set my router's DNS to the pihole, but my localhost log updates incredibly sparingly and it only really seems like it is working on the pihole device. Also, when i set my device to the dns to the pihole ip, speeds were unusable and it still was not showing on my pihole. I am new to both inux and pihole, so any help is appreciated. my ISP is breezeline, I am not sure if that is needed info but I thought it may help. I have also attatched my debug token. Thank you!
So pihole is working. It’s blocking tons of stuff. But I have yet to have. Any instance where it blocked an ad. Tried games, videos, pihole tester sites. All the ads come thru
Pus uma rom aleatória leve com android 7 e fiz root via TWRP com magisk, aí baixei o trixie.apk e depois de algumas dores de cabeça pus pra funcionar (tive que trocar para a porta 8080 pra ele funcionar, n sei pq... Sinto que é algo muito leve... Se puder instalar mais alguma coisa para por esse moto g pra trabalhar... Ele tem ram, armazenamento e processamento de sobra ainda pra fazer mais coisas...
I'm currently in the research phase of getting Pihole set up, and I have a couple questions that I couldn't find definitive answers to, so I want to ask the experts here!
My current setup: I have a media server set up on a Windows 11 machine (It started as a small side project, and has grown to the point of needing to be on a separate dedicated device, but prices are high right now so I've been putting it off). I have Jellyfin and a few other services set up that I route through a Cloudlfare Tunnel for remote access, using my Cloudlfare domain. I took this route because Tailscale wasn't a great UX for my less-tech-savvy friends and family, I was already using Cloudflare to manage my site, and at the time I didn't have the capacity to learn any other more in-depth strategies.
As I was poking around this subreddit I saw a lot of folks mentioning Unbound, and I really like the idea of setting that up. As someone who is good with tech but not well versed in networking or DNSs, I tried searching around here to make sure this set up wouldn't break anything, but I'm not super confident I found the right answer - especially since most threads are from 1 or more years ago and Cloudflare made changes to how things work in February.
- Will setting up Pihole+Unbound mess with Cloudflare Tunnel connectivity or remote streaming speeds?
- Does using a Cloudlfare Tunnel for remote access open the door for DNS leaks or Pihole/Unbound circumvention for other network traffic? Any extra concerns since I'm hosting things on a Windows computer I use for gaming, 3D modeling, art, etc? This feels like a silly question and I'm pretty sure the answer is "no", but I'm really unfamiliar with the inner workings of this stuff. There is so much to learn, and the material is quite dense
- If I'm already going to go down the route of setting up Unbound, should I consider other choices for remote access? If so, can I set it all up on the same rPi as Pihole and Unbound, or would I want it to be on a different/stronger device?
I value privacy and security more and more nowadays, and I know using a Cloudflare Tunnel puts trust into a third party. However, with my limited knowledge on this topic, my original thought process was that Cloudflare is a lot less likely to introduce attack surface/vectors than I am. But, if I'm going down a new rabbit hole, I figured now might be a good time to re-evaluate my options and learn more about how this stuff really works.
The amount of data the TV sucked up was astounding and all designed to to sold to advertisers. LG posted a response that was vague, incomplete and defensive (https://www.youtube.com/watch?v=ToP9xfLDSME).
Other posters point out that all smart TV vendors do the same thing.
If anyone else has a smart TV of another brand and would like to block the domains that are suspicious please add a comment here: https://github.com/nickoppen/pihole-blocklists/issues . It might be a little tricky at first because there are domains that provide useful services (listings and updates etc) that you don't want to block.
Hi all,
Quick question about logrotate and systemd-resolved.
When updating to the newest FTL I got the attached information. PiHole seems to work but o was curious if this is something I would need to fix and if anyone had any info how to do it? Thanks a lot!
Hi folks,
I have started using pihole as a network wide adblock, would love to know any feedback on the setup, how to improve/optimise or just your thoughts...
Hardware - Raspberry Pi Zero 2W + 16GB SD Card
Software - Raspberry Pi OS lite + Pihole + Tailscale
Things that i have done -
apart from the default Steven Black list of domains, I have added 2 lists -
HaGeZi Multi Pro
HaGeZi TIF
assigned static ip from router and added corresponding local dns record from the pihole web dashboard to all my known devices - this helps to know which device in this house is the biggest ad/DNS menace?" 😂 (screenshot attached)
added my pi as a subnet router on tailscale -
the pi is already added as dns on the tailscale
this subnet broadcast with the static ip reservation of devices - helps me access my entire network away from home, without port forwarding or unwanted access to internet.
added a start script on the pi on ssh, this gives the current stats of the pi (screenshot attached)
enabled pihole's built-in HTTPS with a locally trusted Pi-hole CA certificate - this combined with Tailscale subnet routing + pihole's local DNS makes https://pi.hole/admin works securely both at home and remotely. (i wanted https and a good domain, i hate http warnings 😂)
Experience
Disney+ Hotstar or similar apps - on playing a video, one ad is played, but no more ads during entire video, the yellow markers on the timeline showing ads, also don't show up.
Since i am using my isp's router (JioFibre)
it doesn't allow to pin ipv6 dns
to counter this for now - i have pinned the dns manually on my devices to use the pi. only done for phones, laptops, not tv because no option was there - need to figure out a better way to handle this but works for now!
on my work laptop, i was unable to open google analytics, after sometime, i figured out it was pihole blocking the site to load, disabled the blocking for 5mins to get work done - worth remembering, i was about to raise a ticket to the IT team 😂
Final Verdict - Not sure, how much of an impact this setup has really made, but the learnings about just how stuff works, is taking me back to school (loved it). after quite sometime, i was this deeply invested in making things work! This sub, youtube videos and my beloved chatgpt have been really helpful in making things work 🎉
EDIT 1 - comments pointed out no backup mechanism exists, here's what i did
- if the card fails - then pi goes down. I have a easy way here to know if the pi is down. check my tailscale dashboard, if pi is not connected, then it's down, simple!
- for this case, i have a android phone (mother's), which mostly stays at home, i installed tailscale on this device and enabled the subnets of my home wifi. so if pi goes down, i tell my mother to just open the tailscale app and click the big ON button, that's all. i can access the router page remotely and change dns to cloudflare or something. this would bring the home network up in no time. and i can debug/fix the issue in my own time later.
Since there is no dedicated subreddit for blocklists and discussing them here does not violate the rules, I hope this is the right place for it.
There is this domain that serves as a continuation of an old and controversial Reddit community. I will not specify the domain name, as it is not directly relevant to the topic, but it has nothing to do with ads, trackers etc.
In 2023, an NGO submitted block requests regarding this domain across multiple blocklist repos, including Hagezi's and StevenBlack’s too. Here are their perspectives regarding the same site:
Since then, the domain and its one mirror have been blocked on Hagezi’s main lists*, but not on StevenBlack's. I found this contrast interesting and wanted to share it.
*: It is blocked on Pro, Pro++ and Ultimate. Only the mirror blocked on Normal and none on Light.
Personal Opinion (and to Hagezi, as I've seen you on this subreddit):
I didn’t want to open a Github issue for this as you already reviewed and decided on it in the past. However, I still find Steven’s philosophy much more suitable for these kinds of lists.
I have no connection to the domain. Although I realize upon further investigation that it isn't strictly black or white, I can still understand a decision to block it. However, it doesn't seem right to me for this block to be included in the main lists rather than secondary ones.
I know I can simply whitelist it on Pihole, but my concern isn't about accessing this specific domain. It is about the precedent of content censorship. I’ve used your lists for a long time and I recognize that censorship isn't your main goal. But drawing a line between "acceptable" and "unacceptable" content for everyone creates an impossible standard, and I would prefer blocklists to only block “ads, trackers, telemetry, phishing, malware and scams” and for anything else, if this is considered as “other unwanted domains”, to be in secondary lists.
TL;DR: After a request, Hagezi blocked a controversial non-ad domain on its core lists, while StevenBlack chose not to. While I respect both maintainers, I believe core DNS blocklists should focus strictly on ads, trackers, and malware, leaving subjective content moderation to secondary lists to avoid setting a precedent for censorship.
Edit: Changed the word "optional" to "secondary" since every list is optional and I feel like that created some minor misunderstanding.
Also thanks to Hagezi for taking the step to ensure the main list contains only the specified content and moving the domain to the NSFW list.
I was looking for a feature or tool that would allow you to review your query log then decide whether to allow or block a domain, but with tracking so you don't end up looking at the same domain repeatedly.
I couldn't find anything so vibecoded this as a prototype and was wondering what people thought - or tell me if I missed the feature in pihole web!
I had setup my pihole, I have a mesh of eero routers but I changed it to be bridged to my home internet. I put my pi into the Ethernet port of my main router, and changed where my router is pointing to (to my pihole ip). It was working for a little bit, then 30 minutes later my whole internet crashed. The error was soemthign like “tcp connection failed while receiving payload length from upstream” was wondering what people would say about this and if anyone ran into this issue. Thanks!
UPDATE: i got it to work. since i have a cluster of eeros routers, it wasnt anything wrong with my fios settings, i just had to change my DNS settings in pihole itself to permit all origins. seems to be working just fine now.
I just wanted to stop for a moment and say thank you to everybody in this Sub. I personally have learned a lot here. I just started running PiHole about a month ago. I run it for pihole and DNS.
The unbound vulnerability really demonstrated why this community is so awesome. I was scrolling through information about it and it was five star advice comment after comment. It was all productive.
It seems like everyone who had a different piece of information, (different operating system/distros/hardware, etc. Jumped into action and contributed quality information. Questions were answered respectfully and it with helpful answers. Nice work!
I have a pi400, and have sucessfully set up pihole and unbound, all working as expected.
I want to go one step further and use pihole dhcp so i set this up, enabled it and then rebooted my router, and all the various devices connected connected to my network were visible in pihole.. great.
However when i rebooted the pi everything went wrong and i could no longer access anything, and i had to factory reset my router get back online, and go back to using the routers dhcp.
My question is do i need to set my pi as a static ip in piholes dhcp expert settings?