mullvad/dns-blocklists

adding hagezi blocklist

Closed this issue · 4 comments

Have you contacted the Support Team already?

  • I have attempted already, but to no avail, or they pointed me here.

What are the issues you need support with?

My suggestion is that you take a look at hagezi normal or pro list. They are pretty consistent and he clears false positives daily.
And his treat intelligence feed list is very good against malware.

I don't know if you already know it, it's just my suggestion.

Additional Information

No response

What was the response from our Support Team regarding this?

We use Hagezi's list for gambling currently.

I tested your dns against malware and ads. Hagezi blocks way more, and if you implement his lists on your dns, the result would be excellent

Note that oisd is already an aggregate blocklist and it uses hagezi as one of the sources to whitelist domains, though not as a source for the blocklist. The inverse is not the case, i.e. hagezi doesn’t use the oisd whitelist. Adding hagezi can therefore add more false positives, especially since oisd prioritizes not breaking anything above everything else. In the past I had both enabled and noticed that in most cases when hagezi blocked something that oisd didn’t, it was because oisd had that domain on its whitelist (where you can also see the reason, by the way). While oisd aggregates both blocklists and whitelists, hagezi seems to prefer aggregating blocklists only and maintaining his own whitelist based on reports from his users. That makes sense if you want to make a stricter list, but it might also break stuff more frequently. On the other hand, the oisd whitelist might be too lenient, so it's good that users can pick what suits them best. However, Mullvad has to make a balanced choice for their users.

I see that Mullvad already adds AdGuard as a separate source, which is also included in oisd, so it seems that Mullvad already wants to override the oisd whitelist in some cases. If blocking domains has priority over not breaking stuff, adding hagezi would probably be a good idea, as it's a high quality blocklist. If not, I would be careful adding too many overlapping lists. It might frustrate some users when their niche app or website breaks because its functionality depends on a tracking domain that can be safely blocked in many other cases.

The lists have several tiers, from Relaxed to Aggressive, see:
https://github.com/hagezi/dns-blocklists/wiki/FAQ#whatshouldiuse

grafik

The lists are not simple 1:1 copies of sources, see:
https://github.com/hagezi/dns-blocklists/wiki/FAQ#sources