System-level ad-blocking in Android

birdculture 63 points 34 comments October 06, 2026
kevinboone.me · View on Hacker News

Discussion Highlights (16 comments)

figmert

I can't recommend AdGuard enough. It works across devices, and just does all the DNS level blocking everywhere. I've been able to install it on my parents' devices, my siblings' devices, and more places. They have apps for just about any device. On top of that, you can install user scripts and use them on your mobile phones even if your browser doesn't support them (does require a CA cert being trusted). My biggest issue is I can't use it while I'm connected to Tailscale, but my plan is to install AdGuard Home on my homelab and have that take over instead. It does remove many of the functions, but it's better than the alternative

Onavo

Sigh, that's a lot of words to describe DNS based adblocking. In Android you can either set your DNS server in the system settings or via the VPN API. Sample code here https://github.com/t895/DNSNet/blob/a-couple-updates/service... They both do the same thing. There are local device-only resolver apps like https://rethinkdns.com/ https://github.com/m66b/netguard Another famous one is DNS66 but it's sadly unmaintained. Avoid apps with the word "ad" in their name, they are usually semi commercial and can't be trusted. Do note all of these methods can be overridden on the app level e.g. a lot of browsers come bundled with first party VPNs or use their own built-in resolvers. If you want something more reliable, Firefox on Android with the UBlock Origin and Sponsorblock extensions is still the gold standard. Though do note the Android Firefox is extremely slow compared to the Chromium based browsers. For app level ads, use an app patcher like https://github.com/morpheapp which can remove all in-app advertisements and inject sponsor blocking code.

alekescu

There is a special irony to an article about ad blocking containing an apparent undisclosed ad for Nord.

janwillemb

I point "private DNS" to my VPS with pihole and stunnel, works quite well. Adguard as private DNS is also effective.

somebudyelse

Highly recommend https://nextdns.io , great for all kinds of blocking stuff. Plus Firefox or Edge for uBlock support.

pmontra

I am using Blockada 5 from https://blokada.org

xnx

I want to use something like this, but I don't think I can when also using VPN by Google on an unrooted phone.

teo_zero

Why do you need an app at all? Can't you just manually set a private VPN in the settings?

BLKNSLVR

Whenever I'm out and about I connect to my home system via wireguard VPN, and all DNS traffic through my home system is funneled into PiHole. I also have a healthy collection of DNS block lists setup on the PiHole (which I'm currently setting up a site to explain/share). I also have a VPS setup in a similar fashion in case my home connection fails for one of many reasons. I try to only practice safe internet. Raw-dog the internet and you're asking for an infection.

Sarkie

Blockada old version. And then add lists. And add your own constantly when they miss

gremlinunderway

>a rogue ad-blocker app is exactly as dangerous as a rogue VPN service. Fortunately, because these ad-blocking apps are usually open-source, there are limited opportunities for bad actors. I find it naive to state this when earlier he noted that he's suspicious of free services without a clear funding model. Sure, open source is certainly better than closed source, but its not like somehow magically it prevents exploitation. There's plenty of examples especially in a small project like this with few eyeballs. So why question the funding model of a free VPN but not question the funding model of an open source project? We just assume its being done out of good will? I find that perspective naive.

jurakovic

Just use Rethink app https://github.com/celzero/rethink-app

epihelix

Long-time AdAway user here (via root and a hosts file). I couldn't live without it. Simple and effective.

nyarlathotep_

My current approach is AdGuard Home, WireGuard VPN to my home network the majority of the time. This was all pretty simple to setup given hardware that supports VPN, DDNS, etc. Worth noting too that just blocking hostnames is not enough; Netflix, as an example, uses Google's DNS servers (plain UDP) on some/most clients. If the network the client operates on can't prevent DNS to other servers, that's a simple "bypass" vector. AFAIK, the best you can get, given sufficient time, patience, and hardware is: • something like the above • blocking outbound DOT (853), DOQ (784, IIRC) excepting, perhaps, upstreams you trust • blocking HTTPS to known DOH endpoints (Cloudflare, Google, etc) • DNAT for plain DNS cases like the Netflix example above. (to your DNS server(s)) Even that there's plenty of hypothetical opportunities for clients to just use another DOH resolver outside of your domain/IP block lists.

knifelemon

AdGuard its good

methou

That's a long article about just DNS. I'd expect mentioning of the good old Xposed framework.

Semantic search powered by Rivestack pgvector
8,687 stories · 81,484 chunks indexed