• 0 Posts
  • 4 Comments
Joined 3 years ago
cake
Cake day: August 6th, 2023

help-circle
  • DNS adblocking is part of a multi-layered defense strategy. It’s defeated by ads being served from the same domain as content. I know that more advanced options like pfblocker allow interrogating “fronting” subdomains to detect those that resolve to an ad-server (e.g. funstuff dot domain dot net actually resolves to eviladtechcompany dot ai) and block them as well and that helps a bit but the best defense is having on-device blockers as well.

    There’s also a lot more ad tech companies that rapidly deploy domains and subdomains to attempt to overwhelm ad list maintainers and they often succeed for a time in a real back and forth battle.

    It’s also possible the goodreads app has hardcoded secure DNS servers (that don’t use the standard DNS port but often 443) that they use to bypass DNS blocking by resolving their ad domains themselves. In that case you’d want to implement a firewall list of the biggest DNS resolvers (for example like this list here I found with a quick search) and prevent any traffic from within your network from reaching them by either dropping or blocking. Importantly you want to ensure that your DNS resolver can still reach the root servers or whatever you’re querying but any other device should be blocked from accessing these. You should also be either redirecting the standard DNS port (53) to your DNS server if locally served or blocking it except for any necessary local DNS servers.


  • People need to stop spreading this. It’s false and it’s dangerous because it presumes a basket of things that isn’t. It is incredibly easy to identify commercial VPNs meant for anonymity, skipping geo-blocks, torrenting, etc and separate them from those used for secure access to internal networks. For starters all traffic has an address. Those commercial VPN providers used easily and quickly identified servers for which off-the-shelf weekly/daily updated lists of IPs can be purchased from commercial companies. There are other things like traffic analysis but it’s frankly not necessary.

    If the UK or the US wanted to block commercial VPNs entirely they could do so very easily. China and Russia have no interest in running no-logs VPNs for westerners to escape their censorship regimes and put in that kind of effort as the west has put into their own VPNs and solutions to enable “dissidents” (CIA provocateurs and liberals) to communicate. People single out China because they can’t block all VPNs, well the GFW designer said it isn’t meant to stop everyone just introduce friction so anyone who does so has to have gone against the current and hopefully knows their stuff. The technical means of doing so which the west has isn’t even getting into their control of the world financial system, they can seize bank accounts, arrest the people running these services, sanction and fine the hosting companies in the west for hosting them, deplatform them, etc. And the problem there is that the anti-west: China, Russia, etc are not interesting in hosting this stuff for westerners outside of western jurisdiction.



  • Assuming you mean hard drives not SSDs: almost nothing. If prices scaled perfectly linearly and all things were equal at these prices per TB it would be worth about $6.

    But all things are not equal. Your drives are assuredly much older than these drives, probably more worn and the power cost of running it compared to capacity and use of limited SATA connectors would not be worth it for any kind of hot storage which lowers its value. The only way to sell them would be in a lot of at least 8, ideally more and you’d probably be lucky to get $3/drive if you can prove the SMART data on all of them is good and they work. Also if they’re not enterprise drives like these are knock that down a bit more.

    Buying drives that small and old is little better than gambling and playing the odds so you have to buy an awful lot of them awfully cheap to deal with the fact you’re assuredly getting some bad eggs. You also have to figure in the hassle for the buyer of managing say backing up their 10TB data-set to 40 drives like this including plugging them in, unplugging, regular testing every year and storing them somewhere safe as well as dealing with failures and documenting what is on each drive. Most people conclude it isn’t worth the hassle though there’s enough desperate people out there now that some might bite.

    250GB SSDs on the other hand assuming they’re not in a failing state are still worth some change as you can use them to install an OS on various homelab devices like a server, firewall, etc.