Skip to content
itzgee.com

Blog Privacy

Why an ad blocker is not enough

What a browser extension can and cannot protect, why that protection is shrinking, and what changes when the blocking moves into the network itself.

Geeitzgee.comUpdated 28 Sept 20264 min read

An ad-blocking extension is a good thing. It strips ads and trackers out of pages, makes the web noticeably faster, and it’s one of the few privacy tools ordinary people actually install. Even CISA, the US cybersecurity agency, has recommended ad blocking, because harmful ads are a real way for viruses to get in, not just an annoyance.

But be clear about what an extension is. It’s a program running inside one browser, on one device, with only the powers that browser chooses to give it. Its protection stops at the edge of that window. And lately those powers have been shrinking.

The ground is moving under extensions

The most capable blocker ever built, uBlock Origin, no longer runs in the world’s most popular browser. Chrome’s new extension rules (Manifest V3) removed the deep blocking it relied on. Chrome began switching it off in late 2024, turned off the old extension system for everyone in July 2025, and by mid-2026 had stripped out the last of the workarounds. The approved replacement, uBlock Origin Lite, is honest about doing less: its blocklists are capped, and it can’t adapt on the fly to catch trackers that change.

Google says the reasons are security and speed, and those count for something. But this is also a company that makes most of its money from advertising, deciding how much power ad blockers get. A conflict of interest is enough to make that uncomfortable. (The full extension still works in Firefox, which is one good reason Firefox still matters.)

The lesson isn’t “extensions are useless”. It’s that protection built into someone else’s product lasts only as long as they allow it. If you want protection nobody can switch off in an update, it has to live somewhere you control.

The question every device asks first

Before any device can talk to a tracker, it has to ask: where does tracker.example live? That lookup is called DNS. It’s the closest thing the internet has to a phone book, and every connection from every app on every device starts with it.

Normally your ISP (your internet provider) answers, or Google does, and that alone is a full diary of every service your household contacts. Run your own filtering DNS server instead (AdGuard Home and Pi-hole are the well-known open-source options) and the question comes to you. For ordinary websites it answers as normal. For the tens of thousands of known tracking and advertising addresses on its blocklists, it answers: that lives nowhere.

a tracker request, intercepted
  1. 01a device asks a question"where does tracker.example live?" Every connection starts this way
  2. 02the lookup is yoursthe question goes to the network's own filter, not your ISP's
  3. 03known trackers get no answerthe address points nowhere, so the request cannot even start
  4. 04everything else works as normalpages load as usual. The tracking signals simply never arrive

This happens below the browser, so it covers every device on the network: phones, TVs, consoles, the lot, with nothing installed on any of them.

The block happens at the lookup, before any connection exists. Nothing is inspected or unscrambled. The tracker's address is simply never given out.

The request isn’t so much blocked as never made. And because this happens below the browser, it covers the devices no extension can reach: the TV that reports back on what you watch, phone apps with built-in tracking, “smart” appliances, a guest’s laptop. Nothing is installed on any of them. They just get their answers from a phone book with the tracking pages torn out.

That’s exactly what this network does. Every device on the VPN gets its DNS answered by an AdGuard Home filter that we run, so the filtering goes wherever the device goes. How it fits together is explained on how it works. To see what your connection shows right now (your address, your network, who answers your DNS), ip.itzgee.com shows you what any website sees.

Where network filtering stops

Network filtering isn’t magic, and anyone who says it catches everything is overselling.

It works on names, so it can’t block ads that come from the same address as the content. YouTube’s ads come from YouTube, and no DNS answer can separate the two. It can’t tidy up how a page looks the way an extension can. And a badly behaved device can try to get round it by using its own built-in DNS, or by hiding its lookups inside encrypted web traffic. Some TVs and gadgets really do this. You can stop it at the router, but only if you know to.

So the honest answer is layers, not one or the other. Network filtering as the base, covering everything that connects. A proper content blocker in the browser, in a browser that still allows one, for the page-level work DNS can’t do. Neither replaces the other. Each covers what the other misses.

The real difference is about control, not technology. An extension is permission, given inside someone else’s software and able to be taken away in an update. Your own DNS server is yours to keep. The last two years of browser changes are a good reason to own that base layer.

Written by

Gee

We run itzgee.com, a private cloud in daily use, on servers run by us. How it works has the full picture.