PeerBlock
About PeerBlock
A firewall that works from lists rather than rules, blocking connections to and from ranges of addresses somebody else compiled. PeerBlock does that, showing each blocked attempt as it happens and grouping its lists by category.
The PeerBlock categories cover advertising networks, ranges associated with monitoring, government allocations and various others. Subscribing to a list means every address in it is refused in both directions.
Watching the log fill with blocked attempts is compelling, and understanding what those entries actually represent is the more useful exercise.
The reasoning most people installed it for
Here is the honest part about PeerBlock, and it explains why the software faded rather than being replaced.
The popular belief was that blocking the address ranges belonging to rights holders and monitoring firms would keep a file-sharing user from being observed. That reasoning has three problems and each is fatal on its own.
Lists are compiled by people guessing at which addresses belong to whom, from public registration data. They are incomplete, they go out of date immediately, and anybody wanting to observe a swarm can use an address nobody has listed. Renting a server for an afternoon is not difficult.
Observation does not require anything a blocklist recognises either. A participant collecting addresses joins a swarm exactly like every other participant, so blocking a category of addresses does not distinguish them from anybody else.
And the blocking is one-sided in a way that matters. Refusing large ranges of the internet removes peers you would otherwise have connected to, so transfers get slower while the protection remains theoretical.
False confidence is the real problem
That combination produces the PeerBlock outcome worth naming plainly.
Somebody running this believes they have addressed a concern, and behaves accordingly. The belief is the problem rather than the software, since a tool that blocks some addresses is not doing nothing, it is doing something unrelated to what the user thinks.
The concern people actually have is answered differently. Changing the address that others see, rather than trying to enumerate who might be watching, is what a tunnel service does, and Mullvad is built around knowing as little about its own users as possible.
That approach works because it does not depend on a list being complete.
Development stopped, and the lists went behind a charge
Two practical matters finish the picture.
PeerBlock has not been updated in a very long time, so nothing about the points above is going to change.
The lists themselves moved to a paid arrangement, which means the free tool depends on data that is no longer freely available in the form it expects. A blocklist tool with stale lists is a tool blocking last decade’s addresses.
For deciding which programs on your machine may reach the network at all, which is a rule you write rather than a list you subscribe to, simplewall does that directly.
Where list-based blocking still makes sense
Being fair to the PeerBlock idea, since it is not worthless in general.
Blocking known advertising and tracking hosts does work, because those hosts are stable, publicly documented and not trying to hide. That is a different problem from identifying an observer who has every reason to be inconspicuous.
The mechanism for it is simpler too. Sending unwanted hostnames nowhere through the system’s own name mapping needs no software running in between, and a manager for that file with curated lists attached handles the upkeep.
Conclusion
PeerBlock did exactly what its description said, which was blocking connections to addresses on lists. The difficulty was never the implementation, it was the belief attached to it, since enumerating everybody who might be watching is not a problem a list can solve.
Anybody with the concern that made this popular is better served by changing what others see rather than trying to block who they are, and anybody wanting list-based blocking for advertising has simpler options that work. What remains here is an abandoned tool relying on data that has moved on.
Pros & Cons
- Blocks large ranges of addresses in both directions from subscribed lists
- Shows each blocked attempt as it happens, which is informative
- Categorised lists rather than one undifferentiated block
- Small and simple, with a single visible purpose
- The protection most people installed it for does not work as believed
- Lists are incomplete, dated and easily sidestepped by anybody deliberate
- Blocking large ranges removes legitimate peers and slows transfers
- Development stopped long ago
- The lists it depends on moved to a paid arrangement
- Creates confidence that is not matched by what the software achieves
Frequently asked questions
No. Lists are compiled by guesswork from public records, they go out of date immediately, and anybody observing a swarm can use an address nobody listed. A participant collecting addresses also joins exactly like any other peer.
Because refusing large ranges of addresses removes peers you would otherwise have connected to. The transfer has fewer sources and takes longer, while the protection remains theoretical.
No. Development stopped long ago, and the lists it relies on moved to a paid arrangement, so a working installation increasingly blocks addresses that no longer matter.
Yes, for advertising and tracking hosts, which are stable and publicly documented rather than trying to avoid detection. That is a different problem and it has simpler solutions.