Cool!
And thank you for your service to the Internet!
Cool!
And thank you for your service to the Internet!
Block any outgoing connection you don't trust instead of simply taking some 3rd party list with URLs, unverified, no quality control etc, and only blacklist these KNOWN bad urls.
Ad parties don't sit still, they don't keep their ads on the same url when they found out they are blocked or maybe already preventive rotate through new urls etc.
In the end you'll end up with some bizar long list which has to be checked for every url you visit etc etc. This will be a performance hog, and if you cant imagine that, then your list isn't long enough yet.
Use proper egress filtering, allow what you know, and don't allow what you don't know, not just what some 3rd party put on a list.
My advice for you in 2018.
For ""Block by default" is a usability nightmare."
yes it is for a week or 2, but I prefer usability nightmare then a safety nightmare.
I have been using uBlock Origin for years and it's one of those things that just works. Turning it off in those rare moments it needs to be off is a bleak reminder of the state of the internet. Why would I want to go through the hassle of managing all of this work by myself?
A massive THANK YOU to the individuals behind uBlock - You literally make the internet tolerable for me.
It's like putting all _caught_ pedofiles in a jail, and then saying children can roam the streets free and in safety...
Negativity usually bills itself as realism, but that doesn't make it so.
Right, and how is that supposed to happen in practice? Manually inspect every CDN domain loaded on every page that you visit? Or just live without scripts, images, fonts, video?
Basically, yes, see uMatrix. It's not for non-web-devs, I feel, but if you can easily recognize unnecessary connections it works pretty well.
I don't know. I'm not a web dev (x), and I went from "dafuq?" to "I get it, this is so cool" in two minutes flat. Let's just say it sure helps if you're a technical person, not j. random user.
(x) but engineer/CS, tbh
edit: remove accidental markup
Certainly, it just can take more time to sift through the list of tens of domains and deciding to allow or ban each connection if you don't already know which connections tend to be needed and which are not.
Still, it's perfectly doable for anyone if you experiment a little, and it's done once per site, so the time needed for this shouldn't be an issue. It's just that people working with this stuff will have an easier time using uMatrix - which is what I really meant in my comment above :)
(Just kidding, I'm actually a foolish middle-aged man. But I'm talking about my inner bright child.)
I find recognizing unnecessary connections to be the painful part.
no i don't work for or get paid in anyway by little snitch, i just love the product.
Imaging you start off with Safari being unable to connect to anything. Little Snitch is running in Alert Mode and it asks you to decide on every outbound network connection. You visit Facebook. LS asks if Safari can talk to facebook.com on port 443. You say "yes, always". What about "server893.ads.facebook.com:443"? You say "make that .ads.facebook.com and block it forever". Do this through the few dozen prompts you'll get on this first visit when you visit a resource-heavy domain. Now hit reload and pick up a few more (like maybe this time you'll get a connection to a video CDN that you didn't see last time). Repeat until the requests taper off to nothing.
Now put Little Snitch into "Silent Deny" mode and enjoy your Safari that can only view ad-free Facebook.
Note: I don't really recommend doing this because I'd rather be doing almost literally anything else, but if I had to set up a social media kiosk for a relative, that's how I'd go about it.
I do highly enjoy telling Little Snitch to deny connections to all the non-port-80/443 ad trackers. I can't imagine a single legitimate reason why I'd want Safari to connect to moatads.com:843.
uBlock Origin allows you to block yourself any outgoing connection to servers you do not trust, including working in default-deny mode if you want[1].
In any case, those filter lists are maintained by dedicated volunteers[2], their work is way under-appreciated, because contrary to what you state, these volunteers spend a whole lot of time ensuring everything work as expected so that in the end all non-technical users who wouldn't be able to deal with default-deny mode can also be protected.
* * *
[1] https://github.com/gorhill/uBlock/wiki/Blocking-mode:-medium...
[2] https://github.com/easylist/easylist/commits/master https://github.com/uBlockOrigin/uAssets/commits/master
They might burn some CPU cycles but surely the ads themselves burn much more.