Max_P, The ads come from an ad network where there is very little visibility into what’s going to be displayed in your app. And bad people also keep managing to get their ads published even though the ad network doesn’t allow them
And it all ties into the whole targeted advertising, where they also make sure very few people get the bad ad, and tries to target people they think may be more susceptible to these kinds of tactics. Depending on the amount of interactivity allowed, the ad can even display two different things if it deems you too savvy to fall for it.
It’s basically unescapable unless you only use apps without ads, or pay for the ad-free versions.
The whole advertising industry is sketchy, more news at 10.
Thermal_shocked, Dns adblocking blocks these 100%
Darkassassin07, Pi-hole blocks ads served by these networks just fine. Never seen an ad in Boost for Lemmy or for Reddit, though I tend to use Jerboa now that I’ve gotten used to it while I was waiting for Boost for Lemmy to release.
DNS based adblocking like Pihole or Adguard limits you to receiving advertising hosted by the app provider (youtube for example) which is usually better curated than third party advertising networks and less commonly found at all.
knobbysideup, To be truly effective you must also block DoH and DoT. The first can only be done with endpoint lists, since it is https.
N0x0n, Hey, could you elaborate or send some lecture? I have the upstream quad9 DoH address in adguard. It’s supposed to better encrypt my traffic right? Never saw any ads or strange DNS requests.
Never heard about ads being inject though DoH or DoT, or did I misunderstood your comment?
Darkassassin07, Theoretically an app could use a custom DoH endpoint to retrieve ads instead of the standard dns provided by the system. As this uses purely https without a preceding dns request, pihole/adguard would fail to block it; but it’s just not something currently employed.
Darkassassin07, Maybe in comming years, but I’ve never encountered an ad served explicitly through DoH/DoT. It’s certainly possible, just not actually in use yet.
You can also setup DoH front and back ends for pihole so traffic entering and leaving it is encrypted. When/if it becomes necessary I’ll probably look into https packet inspection using custom Root certs to force clients to use my local DoH services and block other traffic, or look into inspecting the SNI to apply blocking there; but again its just not needed yet and may not be for a long time. We’ll see. I’m sure the pihole/Adguard teams are also investigating solutions.
otter, (edited ) Yep, also the ads don’t get initialized at all if the user buys the ad-free version (going to top all in the Lemmy Boost community should bring up the post about it). It’s relatively cheap and the dev is very active with bugs and requests. The dev is developing for the Fediverse and I’m happy to support that (as well as devs for Sync, Connect, Lemmy, etc.)
I like Boost and paid for ad-Free, but a lot of other clients should work for your needs. While they might not be privacy focussed, many are open source so you can check what is going on.
My preference goes
- Boost (not FOSS, one time payment to remove ads)
- Connect (not FOSS, ad free)
- Eternity (FOSS & ad free)
I uninstalled the other ones and haven’t kept up with them. There may be better ones out there, these are the ones I’m keeping up with
StereoTrespasser, Love how the top comment is a rando saying it’s unavoidable but the dev literally says below that they fixed it.
brbposting, The [exact ad from the] specific advertiser will never be seen again, so indeed the issue has been mitigated.
Other bad actors are still out there, though, hence the need for the report button the dev mentioned.
Asudox, (edited ) Jerboa. It lacks some features, but it’s the official app and it’s also pretty minimalistic with its material you UI. Other than that Thunder is pretty good. They’re both FOSS.
harry_balzac, I used Thunder at first but it would crash frequently. Why? I don’t know. It’d just stop working. Very frustrating because it is otherwise very good.
Switched to Jerboa after a couple of weeks and it’s been great.
folak, Eternity.
13617, PREACH, after using infinity for reddit for years this is the only app that I can ever be comfortable with. It’s genuinely amazing, thank you to the person who ported it.
Gooey0210, This is the right answer
k0mprssd, connect is never mentioned enough in threads like these
AlexisFR, It hasn’t been updated in a while, and it’s behavior when you post is quite bad when it reset all the view.
No to get into the refresh issues, too.
moitoi, I updated it just a couple of minutes ago.
Zoot, Its gotten like three updates in the last month. I will agree the refresh issue is annoying.
The developer has done a fine job at adding requested features, and fixing most bugs that come up as long as you let them know.
Unforeseen, (edited ) It’s updated very regularly on the beta branch.
Suoko, I agree, it’s perfect, except for the side menu which could be nicer, but in the end you almost never use it so it’s ok
BeerMedic, I use it. Very similar to boost. I loved boost for reddit.
However, my experience with this boost has had a few quirks that I don’t like:
- Hard to tell what instance you’re on in the side bar
- My inbox won’t clear when tapping the double check icon
Mr_Mofu, I’ve used Boost since launch and never once seen something like that happen
lemmy_99c4zb3e3, I don’t even have ads. ¯_(ツ)_/¯
Cortius, Same
stratosfear, Same but also paid for no ads. This isn’t a boost issue per se, it’s just how ads are made to look and boost free has ads.
ono, I start with whatever is on F-Droid, and narrow it down from there.
Jerboa was the only option there until recently. I see Voyager and Eternity are there now. I’ll have to give them a try.
WeLoveCastingSpellz, thunder is awesome too
refurbishedrefurbisher, Eternity FTW
schizoidman, Voyager is currently many versions ahead of the one listed on F-Droid. It is still usable but you may want to get the latest version from GitHub.
ono, If new versions don’t make it to F-Droid, they might as well not exist for me. There are only a couple of apps that I find important enough that I’ll spend time manually building/pulling/installing, and a Lemmy reader isn’t one of them. Thanks for the tip, though.
carzian, Have you considered using github.com/imranr98/obtainiumYou give it the repository of the app and it will handle checking for new versions and updating them
ono, Part of what I value in F-Droid is the additional layer in the build/release process, because it makes tampering more likely to be detected.
It’s still nice to know a tool like obtanium exists, though. Thanks for the link.
jacktherippah, This is exactly the reason why I don’t like F-Droid as a way to get apps. You’ll have to trust an additional party when getting your apps, and updates are often a couple days behind. I prefer to get it straight from the developer’s GitHub or Coderberg or whatever.
ono, (edited ) You’ll have to trust an additional party when getting your apps, and updates are often a couple days behind.
I know how it works, and in this case, that’s fine with me.
F-Droid has an excellent track record; better than many developers have. And I’m not addicted to having the latest versions of everything on the day they’re released. In fact, not immediately jumping on the latest versions has saved me from nasty bugs more than once.
FutileRecipe, Part of what I value in F-Droid is the additional layer in the build/release process, because it makes tampering more likely to be detected.
Barely and not really. “F-Droid can’t ensure the apps are safe. You still need to trust the upstream developers. We only do some basic check.” forum.f-droid.org/t/…/2
ono, N + 1 > N
FutileRecipe, N + X - Y ? N
Except now you’re adding an additional party to trust (the -Y). So it could still be considered less secure than N.
ono, So it could still be considered less secure than N.
It could be, or it could not be. Depends on the particulars, and on the needs of the individual.
Mind, I’m not going around presuming to tell other people what’s better for them, as one or two others in this thread are doing. I’m just stating what’s a good fit for me.
FutileRecipe, Depends on the particulars, and on the needs of the individual.
That’s not really how things like security works. It’s either more secure or it’s not. The security of a thing does not depend on needs. Now, does the application of it or does someone need it to be more secure? That’s where risk acceptance and the needs of the individual come into play.
I’m not going around presuming to tell other people what’s better for them, as one or two others in this thread are doing.
Same. I’m not saying “stop doing this.” I’m just trying to educate people and make sure they’re not operating with a misunderstanding. Needs of the individual and all that. I think some people just go crazy for something that’s not big tech, and then quit looking at the particulars.
ono, Depends on the particulars, and on the needs of the individual.
That’s not really how things like security works.
If that were true, threat modeling wouldn’t exist. ;)
I think some people just go crazy for something that’s not big tech, and then quit looking at the particulars.
I expect that’s probably true. It’s safe to assume I’m not one of them, though. Cheers.
FutileRecipe, (edited ) If that were true, threat modeling wouldn’t exist.
I feel like we’re talking about different things. I’m talking about static concepts, if X is more secure than Y, not individual setups where something is tweaked. Threat modeling is tailoring the security to your needs. It doesn’t bend security of a static object or make the application of something less than what it is. It requires one’s actions to do that by not utilizing it.
Take bullet proof glass, for example. Bullet proof glass is more secure than regular glass. Now, do you need (does your threat model require) bullet proof glass? No? Ok, that doesn’t mean bullet proof is now less secure than regular glass, it’s just unneeded.
FutileRecipe, I’m not sure why people insist on F-Droid, considering the F-Droid Security Issues.
ono, I use it because, contrary to what that scare piece you linked would have the reader believe, it’s better for my needs than the alternatives.
(I’m no stranger to software development and security, by the way. I understand the pros and cons.)
FutileRecipe, that scare piece you linked would have the reader believe
So an indepth and critical analysis of something is now a “scare piece?” Ok.
deegeese, I like Voyager a lot but it might be iOS only.
refurbishedrefurbisher, (edited ) Voyager is on Android as well. It’s technically a webapp, so you can run it on any device that supports displaying a webpage.
Example: m.lemmy.world
knobbysideup, This is why ad blockers should always be used. Small devs don’t have relationships with advertisers or control over what ad networks will do.
Or you can pay once and be done with them. I think the price of a burger is not a big ask for something you use every day.
I do both.
refurbishedrefurbisher, Even the FBI recommends ad blockers for security.
Oha, Infinity is great
illectrility, It’s Eternity now but yes it is
cupcakezealot, i got scared cause i was on infinity and saw this post and thought infinity was showing ads now :p
daftwerder, Eternity is great! free, no ads, and no lag while scrolling. it also supports swipe to go back from posts.
Rez, I’m so used to navigating in Eternity at this point that all other apps seem clunky and unintuitive
Oha, same
SheeEttin, I use Boost and I like it. But I gave the dev the few bucks for ad-free.
If there’s a malicious ad, report it to the dev. I’m pretty sure they can ban it.
OminousOrange, (edited ) I like Boost too. And it’s only a one-time payment for ad-free too, unlike Sync.
andthenthreemore, Sync is a one time payment for ad-free. It’s ultra that is subscription which has a load of bumph you don’t need and ad-free as well.
OminousOrange, Ah, thanks for clarifying.
cupcakezealot, i bought boost the first day because i loved boost for reddit but, honestly, i’m loving eternity even more these days.
it’s on neo store/fdroid and the repo is here: codeberg.org/Bazsalanszky/Eternity
library_napper, Kinda sketch if they’re not on the official fdroid repo
cupcakezealot,
ModsAreCopsACAB, Blokada, never seen a single ad in any of my apps. It’s a battery hog, but it works like a charm since I can’t get access to my router for a pi-hole.
library_napper, I use AdAway for this
tryagain, Voyager!
Psythik, +1. No ads; doesn’t track you (at least according to the DDG app).
Trincapinones, I use Eternity, it’s a fork of Infinity for reddit
vpklotar, Me too, absolutely love it! Been working great for me the last couple of months.
Add comment