check out "Cloud Firewall", a blocker by Gokulakrishna Sudharsan that was inspired by Kashmir Hill's series and Dhruv Mehrotra's VPN:

@privacylab how does this compare/contrast with decentraleyes?

You just CAN'T access to,,, etc. and any requests to these big-tech sites from other sites are also blocked.

It's the hardcore mode for free internet enthusiasts.

Hm, is there a way to whitelist sites so decentraleyes can MITM certain CDNs?

there is an option to toggle:
" Use local offline storage for storing Cache of recent results in format SHA256 hashes of hostnames (default enabled - green!). If disabled (gray), addon will use "in-memory" cache and will lose the cache when browser restarts "

@popefucker @roipoussiere @privacylab hi, developer of cloud firewall here. Yesterday was the first 0.0.1 release, I wished to release ASAP before everyone forgets @KashHill's living without big 5 tech series. In future version, I will add setting to allow user to decide which "resource types" wants to block. Currently it looks at IP of every 1p/3p resource and checks if IP is present in known (bundled) list of ipv4/ipv6 ranges owned by clouds. Pic has list of resource types.

@roipoussiere @popefucker @privacylab hi cloud firewall developer here. It's not just a blocker with list of few host names like and YouTube com. I literally mean "cloud firewall", it looks at IP address of site+ all 1p/3p resources and checks if IP is present in known (bundled) list of ipv4 ipv6 ranges owned by cloud companies. Not the "big tech sites" but "anything hosted in clouds" :)
Please try it out once and review settings page and help page (which is same as readme in repo)

it blocks everything, with decentraleyes you can still use YouTube or Google

@popefucker @privacylab hi, I created Cloud Firewall. It is a firewall i.e it looks at IP address of every 1p/3p resources and checks if it's present in the known (bundled) list of ipv4 or ipv6 ranges owned by cloud companies and decides to cancel request if user has enabled blocking. PFA pic for supported request types it analyzes.

Can you pls review the readme for examples and " how does it work section" and let me know your thoughts?

It seems like a great piece of software but a whitelist would be very nice.

@popefucker @privacylab yes , can you please see the issues list in Gitlab? I have already wrote down a issue about adding a white list button for main_frame (address bar level) and a future feature for "resource type" level like JS, IMG level. Thanks , please let me know your thoughts if you get a chance to try it. I wished to publish it ASAP before everyone forgets Kashhill's series. It's just 1 day after first release of this add-on. :)

@popefucker @privacylab hi, can you review this issue I wrote about having a switch to allow only the resources supported by Decentraleyes, so that it can catch and render from local.

@roipoussiere @privacylab cloud firewall developer here, glad you like it. To clarify, it's a firewall, NOT a "hosts file" type blocker with list of host names to block. It looks at IP of each resource 1p/3p and decides whether it's present hosted in a cloud by checking against bundled ipv4 ipv6 ranges owned by cloud companies. It's not just about "" or '' but stuff hosted in clouds like aws or gcp.

@perflyst @privacylab ohh no, why did you check GitHub? In AMO listing, I linked only Gitlab repo page for both home and support links.

@perflyst @privacylab oh did I accidently type GitHub link there? I will check and update it.

@perflyst @privacylab hi, I corrected the typo mistake. Thanks, I had mentioned correct URL 3 times but missed on that one by typing github out of habit, I should have copied and pasted the URL :)

@judeswae @perflyst @privacylab Hi All,
For My "cloud firewall" add-on, I need some technical help regarding a feature request from a advanced user who tried it and reviewed the code.

It's regarding how to use alternate dns resolver like TBB (currently we use dns.resolve API provided by Firefox to extensions)

Please read this issue link and boost/share it so I can provide the feature for advanced users/advanced use cases.

LB: in case it hasn't been spotted by h.t's eyes yet

Sign in to participate in the conversation

Invite-only Mastodon server run by the main developers of the project 🐘 It is not focused on any particular niche interest - everyone is welcome as long as you follow our code of conduct!