Explanation of the state of uBlock Origin and other blockers for Safari
github.com
github.com
For example; you can have a trigger which contains a regex that matches all images and stylesheets for a given domain. The action can be one of several options, one of which is to block that item.
One advantage this technique provides over ad blocking is that there's no data to be phoned back home. It is, in essence, a mask that is applied to a web page before rendering. Also, it's very lightweight. It's literally just a JSON document which means Safari can perform better.
Now, I'll admit it's not foolproof. Apple and the content blockers have some work to do on it. I'm noticing some issues with it myself after having upgraded to Safari 13. But from a privacy perspective, I personally much prefer this technique.
1: https://developer.apple.com/documentation/safariservices/cre...
Apple's method avoids this issue by never letting the extension see the page contents, it only provides match lists of what to block that the browser then enforces. Even if the extension became malicious it has no access to private data on the webpages it is ad blocking on.
Content blockers impose rules at the outset and the rule generator won't see what the URLs/content actually is.
The way I would think of it would be like "let me see what you're seeing and I'll let you know what to let through" vs "here are a list of things you shouldn't let through but I don't need to know about what the hit rate actually is".
Although I could be misunderstanding the implementation.
I agree it's totally possible they would do that, but one could figure it out pretty easily with a touch of detective work.
1) the Government decides to intervene.
2) Users give up and start using different services.
I'm pushing for #2, but then I switched off like a decade ago, when I saw the writing on the wall.
"The most prevalent tracker, Google's doubleclick.net, showed up in 975 of the top 1,000 Roku channels, with Google analytics trackers showing up in 360, the researchers found." - https://arstechnica.com/tech-policy/2019/09/studies-google-n...
This setup gives the Browser/Maker plausible deniability when they act badly.
If an extension doesn't get full access to all the pages you are reading, it can't do bad things with that access when the extension's owner inevitably changes (see the fight between uBlock and uBlock Origin for example) and spyware features are added.
I’m sure that would have gone over really well, too. /s
That's the rub though. There's nothing but trust preventing them from including some spyware in the next automatic update. Actually not even trust, whoever has account access to publish for uBlock could have their account hacked and someone malicious could inject spyware into a version of the extension.
I trust Raymond Hill more than I trust Google.
I mourn the loss of uBO, but I'll take that tradeoff knowing that I can relax knowing that my family and friends aren't going to end up using some intrusive nightmare of an "ad-blocker" with Safari.
I don't really care, I don't use Apple products and I still have Firefox, which will happily let me shoot myself in the foot on this (for now). You know what else is a "huge vector for security and privacy issues"? Every program I install through my package manager, or other source. The solution isn't to cripple the OS so that only my distribution vendor can run certain kinds of software and no one else.
Sure, if all else were equal I guess I would trust Apple slightly more than an open-source extension developer, but all else is not equal - Apple is taking away the flexibility of arbitrary code and dictating that if you want to block ads in the browser then you have to use their regex-based declarative adblock API. I'm surprised to see such a warm reception on HN to a classic Apple "we're taking this away for your own good" kind of move that has historically not been very popular with enthusiasts.
This is the same pattern that happened with IE where users would install all kinds of toolbars accidentally and then get tons of data stolen or when the first iPhone was jailbroken and everyone wanted all the cool jailbreak features. People would jailbreak the phones of their parents, siblings, relatives, friends, etc. without really every explaining what was happening and what the potential pitfalls of that are.
Now, unfortunately, we're at the same impasse with browser extensions. They're super convenient for most people and are widely used but there's another vector of attack for people that aren't as savvy and don't understand the consequences. Especially when it comes to browsing history, payment data, and passwords, it's so easy to compromise a system now when you can hide it in something like a browser extensions.
The real answer is to do a better job educating people about what everything is but no one wants to do that. More skilled users just want to bitch about what gets taken away from them personally without acknowledging the giant elephant that is ignorance. There is so much advanced technology out there now that people don't even understand the consequences of the most mundane actions.
In my opinion, Apple's trying to do something about that even if it comes at the expense of a few power users losing some conveniences. If their past history is any indicator, they will bring back or improve up on this functionality so that power users get it back somehow but, in the meantime, the bigger and more pressing issue is what takes precedence.
Mobile is the primary user environment for a whole generation of kids and millions of people coming online in developing countries around the world. What we're bequeathing them is worse than anything in early-2000s Slashdot's worst paranoid nightmares. Billions of iPhones only load OS images signed by Apple and jailbreaks are aggressively patched as urgent security issues, guaranteeing vendor lock-in. Third-party code is too dangerous so users have to get it from a vendor-controlled app store and sideloading is forbidden for security reasons. You can't have browser extensions because they can see too much, so now you have to hope that Apple implements an API for whatever you were trying to do. There's a weird double standard where the tech literati are fine with things on mobile that they would never accept on their desktop. I guess it's because we have the luxury of putting our phones away and retreating to our "real computers" to scratch our tinkering itch. Not everyone has that privilege, or inclination. If the freedom to tinker means anything to you then mobile shouldn't be an exception.
I don't think the walled garden is even necessarily good for the ill-informed or careless users we're trying to protect. Checking out the "Advanced" mode is how users learn. While it may be dangerous for a casual user to be able to run a command or make a tweak they found recommended on some website, it also can be incredibly helpful - software doesn't always work correctly or the way that you want it to, and there's not always a nice button that does exactly what you need. And there's a real danger of the browser and the other public API surfaces calcifying to only permit what Apple thinks about ahead of time, smothering innovation that could have genuinely benefited users. Imagine if computers followed this philosophy from the beginning. I doubt users would enjoy an app store where user input (text only, of course) is sent securely into the app's stdin and output is text fed securely from the app's stdout to the screen, with no interference permitted by potentially insecure code attempting to provide things like scrollback because it could see all of the user's activity.
So yes, protecting users from the worst malware can be a thing but it's not as obvious as you make it sound that this should necessarily entail removing agency from the user. By aiming for the lowest common denominator user, Apple is depriving everyone else of real advantages. And, I would argue, producing a sterile and stilted experience that's best for no-one.
Of course you’ll hear a lot more noise from the users of the browser with the larger share by a wide margin.
[0] https://en.m.wikipedia.org/wiki/Usage_share_of_web_browsers
Why does narrowing it to desktop devices matter?
I assumed it was just a fluke because I'm in the healthcare space, and that means lots of iPads and doctors rocking the latest iOS gear. I guess not.
I’d expect there are about 500 hardcore safari fanbois on Mac but everyone else uses it to download a different browser.
Microsoft Edge is coming to Mac, obviously that’s the future.
I don't take from that they will apply it in the future, just they don't want to rule anything out.
source: https://www.ghacks.net/2019/09/03/mozilla-wont-follow-google...
Yeah, it makes ad blockers less powerful. It also makes them less of an enormous security risk in that all of your web traffic is redirected through them, and a compromised extension could do whatever it wanted with that.
People are more skeptical of Google's motives because nearly all of their money comes from selling ads and for all we know they're more concerned about their very very very large piles of cash than they are about browser extension security. That's not a motivation that Apple would have for their Content Blocker limitations.
Current ublock origin.
Your adblocker frequently updates lists of patterns to block via any of many user configurable lists.
When you load a site ON YOUR COMPUTER it consults all those lists including custom ones you create yourself for annoying elements on particular sites before loading content. It NEVER sends said content to the adblocker or leaks your information.
Ublock origin provides both the adblocking engine and the lists and can innovate on the former and iterate on the latter as fast as you please.
New chrome restrictions.
Google provides an adblocking engine substantially inferior to ublock. Extensions are able to provide only a list much smaller than current lists and can only update that list when the extension itself is updated. They cannot innovate on the adblocking engine as they are stuck with the crummy one an ad company provides. This basically ensures that ad providers win the arms race with adblockers.
Safari
Shares the same inherent flaw with chrome that Apple will be providing the adblocking engine with the possible benefit that apple isn't directly making money off ads and has less incentive to directly break adblocking.
If someone were able to compromise the developer account and get a malicious version distributed through the Chrome browser gallery, that would be a huge problem. The kind of thing that has been making headlines with compromised npm modules recently.
Google has reviews in place to prevent malicious extensions from being distributed, but they can't be perfect. We've seen that repeatedly with both Chrome extensions and Android apps.
Every extension with permissions set for "This can read and change site data on all sites" has a huge target on it, and the fewer things using that level of access the better. Ad blocking extensions are an obvious place to look for improvement because they're so popular.
I hope that Google can put a blocking system together that will be able to perform as well as existing solutions without adding any huge security risks, but I also agree that it's problematic that their incentives are to do the exact opposite.
It'd make the Content Blocker API kind of pointless but that'd be safer than letting third parties in.
I'm so tired of this trend where folk keep pitching significant reductions of technical capability as some kind of "win" for the consumers and developers of a platform.
This is about exploiting platform owner privilege, no more and no less.
This presumes I trust Apple significantly more than authors of any conceivable blocking plugin — by large enough margin that it would be worthwhile to lose functionality over it. That isn't really the case — I only trust Apple marginally more and, if anything, making such decisions on my behalf erodes that trust.
And trusting a company based almost exclusively on ad revenue to build an ad blocking API is just bonkers. No, the only way to effectively block ads for the foreseeable future is to give ad blockers all the information. Unfortunately.
yet they have shitware called uBlock that's there intended to confuse them with ublock origin, just sitting there in app store...
[1] https://help.getadblock.com/support/solutions/articles/60000... [2] https://blog.chromium.org/2019/06/web-request-and-declarativ...
An ad blocker that would be limited to 30k rules, as originally suggested by the Chromium folks, would be severely neutered. And even with the 150k max, I currently have ~240k rules in uBlock Origin. That's way above Chrome's planned max. But easy enough to implement with Safari's model, even if it requires using at least five lists.
That's why everybody is hating on google - it's a reduction in functionality without an increase of privacy even though that's "why" they did it.
The complaints from blocker developers have been that Google isn't allowing enough rules (Google has agreed to increase that), and that their existing blocking lists are defined in a way that needs more logic than declarativeNetRequest's matching system.
The point I was making is that chrome.webRequest is still around (as I understand it - if I'm wrong, please correct, because that's my whole point!), it's just for observation only now. Plugins can still request that permission... which means plugins can capture just as much data as before this change.
That doesn't seem like a good trade off, given the two complaints you listed.
https://developer.chrome.com/extensions/manifestVersion#mani...
Deprecated in March 2012, stopped accepting updates to Manifest v1 extensions in March 2013, and existing extensions stopped working in January 2014.
EDIT: Google's blog post talks a lot about removing the "blocking version of webRequest", so perhaps the monitoring one still exists? But their goal would be to make these into separate permissions - the very popular blocking extensions can work blindly, while monitoring extensions can still function? It's not very explicit about it, but that's how I'm reading it https://blog.chromium.org/2018/10/trustworthy-chrome-extensi...
If history has taught us anything it's that forcing users to agree to allow access in order to get what they want doesn't stop them from doing it. Especially when programs apps and extensions are required to ask for broad access to accomplish even the smallest tasks that the warnings become meaningless noise. If I want ads blocked and I trust a company enough to install their blocker I'm not going to uninstall it just because it needs access to the content I want it to check over for the presence of ads. No matter how many warnings I get or how scary they sound I still want ads blocked.
Like many things in technology, there are few write ups explaining this, including the pros and cons, in simple terms that most people can understand. So, people are not well informed.
When they are not well informed they will tend to make decisions based on other things, like their business model. We know that Google makes money displaying ads and has generally soaked up information on people to use for their benefit. Apple has been advocating privacy and makes money selling hardware and services.
If there was an "explain it to me like I'm 5" write up on how the changes to Safari and proposed changes to Chrome would work I could imagine it would help people see something other than the business model.
This isn't a double standard. It's people making judgements on something other than the technology.
But there are those of us who understand why the Chrome team made the decision it did, and are sympathetic. And we're happy that the Chrome team and Apple are of the same mind about this.
Apple blocks not only the content, but the ability to even monitor as well. So there is a little extra with the Apple way.
You'd hope google would follow suit, but given their business model it's understandable if they don't. (Not that I'm a supporter of Google's business model, just that I understand why the ability to monitor is still there.)
Specifically, Google proposes to continue allowing extensions to observe all requests, but extensions can’t block requests based on these observations.
The new API is called "declarativeNetRequest" and allows extensions to block requests: https://developer.chrome.com/extensions/declarativeNetReques...
"There are the following kinds of rules:
* Rules that block a network request.
* Rules that prevent a request from getting blocked by negating any matching blocked rules.
* Rules that redirect a network request.
* Rules that remove headers from a network request."
> Google proposes to continue allowing extensions to observe all requests
Their expressed intention is to disallow such behavior in the future:
"The declarativeNetRequest API is an alternative to the webRequest API. At its core, this API allows extensions to tell Chrome what to do with a given request, rather than have Chrome forward the request to the extension. Thus, instead of the above flow where Chrome receives the request, asks the extension, and then eventually gets the result, the flow is that the extension tells Chrome how to handle a request and Chrome can handle it synchronously. This allows us to ensure efficiency since a) we have control over the algorithm determining the result and b) we can prevent or disable inefficient rules. This is also better for user privacy, as the details of the network request are never exposed to the extension."
(Source: https://docs.google.com/document/d/1nPu6Wy4LWR66EFLeYInl3Nzz...)
> In Manifest V3, this API will be discouraged (and likely limited) in its blocking form. The non-blocking implementation of the webRequest API, which allows extensions to observe network requests, but not modify, redirect, or block them (and thus doesn't prevent Chrome from continuing to process the request) will not be discouraged.
I rest my case.
It's similar to when the internet blew up about Google's project dragonfly, which was cancelled, while Apple quietly did the same thing by sharing iCloud user data with the Chinese government.
...this is a fantastic argument for disallowing installation of custom browsers. I do hope y'all like IE and/or Safari.
You can say the exact same thing about any code we run on our devices. We accept that risk or we wouldn't run any software at all. Google isn't worried about our privacy. They take our privacy. They are worried about their profits because that's all any corporation cares about.
Besides, in the end, it's all about minimization of threats. The existence of one threat is better than the existence of two. Don't let perfection be the enemy of the "good enough."
I'm going to trust uBlock Origin because it is free open source software and I can see everything they are doing with my data. Apple on the other hand forbids reverse engineering safari (trying to understand what it does and how it works).
Once you're a part of the apple eco-system apple could theoretically (and to be clear we're talking about purely theoretical privacy risks in all cases) access your browsing history and also tie that directly to your name, address, credit card/bank account, GPS coordinates, etc.
Putting your privacy in the hands of a company that has so much of your data already is naturally more risky than compartmentalizing. If hackers somehow compromise my browser extension they get access to my browsing history on one device until I notice and correct the problem. If a hacker somehow compromises Apple they could get access to much much more. For all their care and resources Apple is not immune from attacks either. Safari has had a ton of vulnerabilities exposed just this year so far.
Downloading a sketchy browser extension takes deliberate action on the part of the user. Just loading CNN.com can (and has) caused computers to become infected automatically because of ads. Limiting the ability to block ads is not protecting anyone.
Many have no idea these risks even exist, or mostly wrong notions about them.
Pretty sure my parents and grand parents don't even want to know their (probably randomly picked) ad blocker could pick up their credit card number every time they type it in their browser.
How could we hold it against them? Computers to them merely are (sometimes cumbersome and annoying) tools.
> But there are those of us who understand why the Chrome team made the decision it did, and are sympathetic. And we're happy that the Chrome team and Apple are of the same mind about this.
Hey, you probably didn't mean it this way, but your comment kinda sounds like you're saying everyone who opposes Google's decision is a simpleton who doesn't understand the security implications of browser extensions. That's not true, and more importantly, not especially charitable.
As someone who isn't a corpsec/IT practitioner, though, breaking uBO is literally the most important impact of Chrome's Manifest v3 for me.
I wouldn't mind if Google incorporated uBO as a first-party component in Chromium while applying the restricted policy to all other extensions! Most purported adblockers are crap, if not malware. Pick the best one and restrict the rest.
Unfortunately, I doubt an advertising company is going to incorporate uBO in the browser they provide for free.
I totally buy that breaking uBO isn't Google's goal for Manifest v3! It just happens as a beneficial side effect.
> The moral dilemma here seems to be that Google is unwilling to privilege a good-citizen adblocker like uBO over other extensions; they're an ad company and any explicit step towards promoting an adblocker probably is hard to explain at shareholder meetings
Look no further for why our society is having such trouble coming to any sort of agreement on issues that matter.
I read the GitHub post yesterday, immediately bought 1Blocker, and moved on! (And it's been great!)
Did you read the same comment I did? They're baffled and they asked you about several different possibilities to figure you out. That's the opposite of assuming. "Your apathy" was conditional, based on the previous question.
> I'm disappointed, to be sure, but no amount of whinging, no matter how vociferous, is going to change this, so I'm pragmatic about it.
Losing money and being disappointed doesn't sound 'great' to me!
A double standard requires the same person or population to hold logically contradictory viewpoints. That isn't what is happening here.
I certainly would. I had been using Safari on mac only because it was fine and I had no need to switch to firefox or chrome.
Now I will definitely not be using safari anymore.
Are you suggesting uBO is sending data “back home”? It doesn't, and this comment is borderline FUD.
Whether or not this is a sufficient solution is one thing, but there are some legitimate problems with the current state of adblocking. Being able to provide a similar solution in a far more limited fashion would be a good thing for users.
The moral dilemma here seems to be that Google is unwilling to privilege a good-citizen adblocker like uBO over other extensions; they're an ad company and any explicit step towards promoting an adblocker probably is hard to explain at shareholder meetings, even if the engineers want to.
In the end, as has been said by others, if you don’t like it then use Firefox. That’s what’s great about the browser ecosystem we have right now. There are some really great options in browsers.
Agreed about Firefox. My goal here is to call out the hypocrisy of the declarative API. So I want to repeat myself that the declarative API is about giving ads networks an easy way to not get blocked, while using performance and security as false arguments that impress only those who know nothing about performance and security.
`load-type`: An array of strings that can include one of two mutually exclusive values. If not specified, the rule matches all load types. `first-party` is triggered only if the resource has the same scheme, domain, and port as the main page resource. `third-party` is triggered if the resource is not from the same domain as the main page resource.
So our concerns about the cat and mouse game is true, but only for domain triggers.Wipr blocks the same ads as the above combo, but also blocks those on reddit.
YMMY
Is it more difficult than I imagine?
Of course we know that Google has to make money from Ads so its understandable but what about Apple ? They are putting heavy focus in privacy, would it be good if they open their browser to make sure their users will not move to Chrome/Firefox or other browser ?
[0]https://www.microsoftedgeinsider.com/
[1]https://marketplace.visualstudio.com/items?itemName=ms-edged...
[0]https://www.omgubuntu.co.uk/2019/04/microsoft-edge-may-come-...
Like I said: ux-wise, I'm not impacted negatively by using chrome, at all. If my laptops resources were more limited or my local workload was bigger, I'd probably check out Firefox, but since I'm not bottlenecked, why bother?
At least that is my theory on it.
Content blockers in Safari are limited to 50k filters. uBlock Origin's default filters have more than that. Therefore, the choice is between a new, but much less useful extension, or no extension at all. uBlock Origin decided on the latter.
https://backstage.1blocker.com/say-hello-to-1blocker-x-8b55e...
Most studies[1] done in the last 2 years report between 20-40%, depending on the population and device type (laptop, desktop, phone, tablet) studied.
While I can't say what % you or GP would estimate or whether you'd be surprised that it's 20-40%, I think 20-40% is a lot.
[1]: Choose any study or summary of one: https://www.google.com/search?q=what+percentage+of+internet+...
I doubt uBlock Origin being removed from Chrome will change the status quo. Maybe in a few years when enough powerusers convince enough casual users. If you just look at software out in the world, it's clear that powerusers have next to zero influence. It's why desktop Linux use, for example, is still just a blip after all of these years.
the moment they can't find ad blocker that actually works they will stop switching ad blockers and switch browsers.
What's holding back linux isn't the lack of influence power users have, it's that it's still lacking in gaming, hardware compatibility, and ease of use (although those are improving all the time)
Who do you think the moms and friends all listen to? Their technical friends. This of course won't hit 90% of users but it's enough to have a large influence well beyond just power users.
Few companies survive pissing off the nerds when there is legitimate competition available in consumer products.
I wish this sage advice was part of every business executive's education. :-)
You're probably not wrong that there will not be a rapid initial migration. Maybe more over a longer time period. Maybe not.
And for small browser like safari it will be fast death
And for chrome
On mobile chrome is already (for me) dead coz it not allow extensions
The manifest v3 proposal takes chrome down to roughly the same level as Safari for ad blocking plugins. https://github.com/uBlockOrigin/uBlock-issues/issues/338#iss...
So, that day isn't far off. It was supposed to be in canary last month, I haven't checked.
The big difference is that the functionality problems 20 years ago were easier to explain, and therefore easier to get people upset about. It's a lot easier to weave a compelling political story about straight-up incompatibility than it is to weave one about degraded performance due to differing just-in-time compiler optimization behavior.
Also, we seem to be stuck in a situation where people are still so fixated on a monarch that hasn't been in power for over a decade that they maybe haven't been so concerned that the old monarch's overthrower has consolidated power to become a new monarch.
But I have seen sites that don't work in Safari.
(Scare quotes around "standards" because calling Chrome-only things standard nowadays seems a bit like calling AcitveX a standard 20 years ago.)
That's the only one I remember encountering.
Twitter doesn't work very well on Firefox for Android.
I think most people who wanted adblocking on Android switched to Brave instead, which is essentially a Chrome fork without the Google stuff and with better tracking protection.
What makes you say that? Firefox has been my primary mobile browser for over 5 years, am I missing something?
1. You are on this web page in Fennec[1], and you want to do a web search. Click the address bar, type in your query, hit go. Sometimes, Fennec will start the progress bar and act like it is searching, but will draw another tab in the main viewport before resetting the progress bar and changing the url to the SERP you want. If you don't know its going to do that, it looks like Fennec completely ignored your search and loaded another tab.
2. Fennec will sometimes lose its cool and stop rendering pages. The UI layers will respond, you can open hamburger menus, tab listings and thumbnails, but no matter what tab you select, it no longer renders anything but a blank canvas in the viewport. You have to force close Fennec to restore normal behaviors.
3. Fennec will after a long time of being active lose its extensions like noscript et al, you have to force close and re-open to get them to show up in the hamburger menu again.
Stated as a die-hard Firefox for Android fan.
[1] %s/Fennec/<whateverItActuallyIs/g
As in, the core browser is available and seems to work fine, but for many people there's not much point in switching until it supports extensions. It won't replace Fennec until it does.
>This is because since their core functionality is so similar, small advantages will tip the scales.
It is a a bold assertion, which is not backed up by the data. Despite Mozilla repositioning Firefox recently and reclaiming some lost ground, it is to a larger extent, still only maintaining a steady set of core users. To make an assumption that small advantages will tip the scales in favour of FF is wishful thinking, as demonstrated by some of the conversations. Furthermore, it is inherently not in the best interests of Google to actively promote ad-blocking policy unless it serves it's own purpose, coupled with the acute awareness of why power users and developers pick Chrome ─ they are well positioned to throttle any competition.
https://data.firefox.com/dashboard/user-activity
See the difference here: https://github.com/el1t/uBlock-Safari/issues/158#issuecommen...
Quite the spin to make a negative a positive.
"Privacy" is the new buzzword.
Normal extensions can potentially monitor everything you do inside your browser, even in incognito mode. They could even impersonate you.
That's a huge gaping security hole, and I think Apple is doing the right thing by preventing that.
They've spent a lot of effort with sandboxing to limit the attack surface of native apps -- it's logical that they do the same inside the browser.
Now there is a security hole, yes, but closing it comes at a huge cost: the removal of useful ad blocking.
I suspect more and more uBO users will be forced to move to Firefox and/or install a pihole.
Many people don’t have time or inclination to check which extension is doing what. Proof is the fact that ublock and adblock are bad, but ublock origin is good.
Whose non-techy friends and family are going to spend time to figure that one out? In that case, the macOS and iOS content blocking system is better for those users.
I’m sorry, but does uBlock Origin detects & filter ads based on contents?
I thought they maintained a database of URLs that serve ads & page elements... and Safari content blockers also have the same capability to block content based on URLs (hence can block YouTube ads).
BTW, PiHole blocks ads based on hostname... and is more incapable than Safari content blockers.
And I'm aware PiHole is just DNS filtering, but an extra layer of blocking is useful.
Have you ever used a content blocker? For all their restrictions, they’re still quite effective.
I'd give Apple's claim here as much credence as I give Google's claim that webRequest caused performance problems when extensions used it.
For that matter, on macOS I don't have anything in Safari, and regularly go between Safari, Chrome and Firefox (the latter two with uBlock Origin). Somehow just the native anti-aggravation technology in Safari is more than sufficient to give me a great experience. If it has a list solution like the iOS Safari, then I'll partake of that.
Apple should enable classic-style blocking as an admin override kind of thing, but remarkably their list-based regex approach has been remarkable effective.
MitM like "antiviruses" do? Nice
I'd love an adblock system that allowed me to block trackers with a purely declarative API. I do not trust Apple (or Google) when they say that their API will be as effective as current extensions.
Ublock Origin and UMatrix are hands-down the gold standard for blocking right now. I'm very, very cautious about ignoring the advice of the person who made them, and that person is saying that declarative APIs don't offer enough flexibility for the blocking they want to do.
Of course extensions are a privacy risk. But I only need to vet two extensions, and without them I need to vet hundreds of websites. If the current extensions do a better job without a declarative API, then I'd rather risk installing them. You have to look at the risk of extensions in the context of the risks of the broader ad ecosystem on the web.
Yes, ad networks can track you across participating networks. But an ad network can only attack the sites that use it.
An extension can access everything.
And how do you "vet" an extension? By checking if the author looks like a trustable person on their Github photo?
If you're worried about malicious transfers of power, turn off auto-updating in Firefox. If you're worried about being able to audit the actual installed code, use Firefox Developer Edition and audit and compile your own version to run.
In practice, I trust UMatrix and Ublock Origin because I'm familiar with Gorhil's work and comment history around Github and HN. I also extend a similar amount of trust to Decentraleyes for similar reasons. Those are the only big 3 you need to get the biggest impact on your privacy. Arguably, you don't even need Decentraleyes if you only want to trust one person.
There's a tradeoff between default privacy settings and user simplicity. As a power user you're still free to run whatever complicated scheme/browser you want to.
Ideally, we would like sandboxing on the desktop to be at least as good as sandboxing on the web (preferably better). People don't run sandboxed desktop apps right now because the ecosystem currently makes it inconvenient. Wayland and Flatpack are both good steps in the right direction. Apple's making some progress as well there, but it's all pretty early-stage stuff.
Until the sandboxing gets better, you should be cautious about installing unvetted desktop and phone apps. You should also be cautious about installing unvetted browser extensions. But browser extensions are complicated because while keeping a minimal system isn't that hard, you're probably not going to stop visiting unvetted websites, even if you know it's dangerous. It's a much higher priority for experienced users to make the browser sandbox good than it is to make the extension sandbox good.
People take a long-term view on this, and while I agree with them in theory, I don't think it's always particularly helpful to think about what technology will look like. With browsers, it's not a question of whether or not theoretically it would be good in the future to make extensions entirely declarative. Of course it would be good. It's a question of, 'is it possible to do that right now?' At the moment, Safari's declarative API is significantly less powerful than the blocking API that Firefox has. In the future, that could definitely change, but people have to use computers today.
So for the moment, the browser advice I give to non-power users is to install UBlock Origin and Decentraleyes on Firefox and nothing else. I think that's a safer, more private environment than anything they'll be able to set up on Safari. I advise power users to add uMatrix to that list, and for people who are really paranoid, I advise them to run Firefox Developer edition, which will let them compile extensions from source.
If you're just handing someone a computer and you don't trust them not to go off and install random extensions, then sure, give them Safari. In that context, it's not confusing why Apple would do this -- they're optimizing for the largest number of users; people they can't trust not to install random extensions. It just means that more experienced/responsible users will be safer using Firefox.
Some security vulnerabilities are acceptable in some situations in exchange for user freedom and/or other benefits, such as blocking ads, which are essentially malware for your brain.
It's nice that random extensions can't peek at your browsing history, but on the other hand, you have to trust that Apple won't decide to ignore any block rules. What if one day they make a deal with Disney and now all Disney ads are on the permanent do-not-block list?
Apple doesn't care individually what users use. However, Apple (and everyone else for that matter) does have reason to be concerned about Google's Chrome completely dominating the web in the way IE once did. iOS is certainly their biggest bulwark, but that doesn't mean they'd be delighted if Mac users felt required to use Chrome. Further, they also have made being able to avoid the anti-privacy ad-driven ecosystem to some extent an important differentiating factor. Even with Firefox existing, having a purely Mac focused and maximally optimized browser (FF is only barely catching up this/next version on basic power efficiency for example) that has strong privacy protections with no conflicts of interest is a sales point.
That doesn't mean it's a total core focus of course, but neither is there no pressure at all.
Just like most printer manufacturers don’t focus on AirPrint compatibility because of the Mac. That’s just a byproduct of iOS compatibility - which they do care about.
Any web standard is useless without Apple being on board. Developers either won’t implement it or create an app for iOS to use a feature they need.
We don't want websites to be written for compatibility with a single browser engine. That means developers are writing to Chrome's quirks, not to actual web standards. Over the long term, that gives Google complete control over how the web is run.
There are currently between 3 and 2.5 browser engines that matter, depending on how you count webkit vs blink. I'd really rather that not fall down to only 2 on desktop.
I thought Apple were way out in front when it came to tracking and whatnot...
My wife uses a MAC at home and was complaining about how slow our internet was (70Mb down... not slow) a while back.
She mainly looks at news sites and when I saw what she was looking at I knew the problem wasn't the internet connection.
The entire page, apart from a tiny bit in the middle, was cluttered with moving shit!
I installed uBlock Origin and... the result was fantastic: pages loaded in a fraction of the time.
When she realised that the articles were a tiny proportion of the downloaded crap she realised she'd been missing out for so long.
Once, when the MAC went back for repair, it was replaced with a new one and OMG the horror when she fired up Safari and it had no blocker... UBlock Origin to the rescue.
I agree with one of the other comments on here: The web is utterly unusable without it.
Personally, I’m totally cool with the trade-off of having less capable ad blocking functionality, if I can be sure my web plugins aren’t a security or privacy risk.
https://github.com/gorhill/uBlock/
It's a very popular project on GitHub with many developers scrutinizing any changes to the codebase. Fears of uBlock Origin being a "security or privacy risk" based on code in the extension are unfounded.
(I also wish they'd kept the APIs open, just stating the other case.)
Computers should do what their users tell them to.
I wouldn't appreciate a smartknife with a blade that only extended when something I was authorized to cut was in range. "Unrecognized cultivar".
Tools do the work their possessors wish. Why would you let someone limit your tools? It's everywhere now. It's in the coffee pods.
Why does everyone else know better than the user what the user should be doing?
See windows and the malware infested ecosystem. People obviously don’t know what they’re doing, and/or don’t have the time vet every little action they do on their computer.
I'm sympathetic to concerns about people who don't know what they're doing, but if I'm a Safari user, I have to value keeping myself safe first. This change makes ordinary users safer, but makes power users less safe.
I understand why Apple is doing it. But I'm still going to advise responsible owners to ditch Safari and pick a browser that will do a better job of blocking trackers.
Are the uBO alternatives like ka-block so bad?
Ka-Block actually advertises itself as being less effective than uBO. It's selling point is that it's a simpler extension that blocks fewer ads and trackers, under the assumption that this is good enough and on it'll on average be faster because of the reduced overhead.
> Some ads will get through this filter, and that's ok. We already have extensions that block every ad that's ever appeared on the web with a completionist zeal that must be admired.[0]
If you're blocking ads just to make pages load faster, Ka-Block is probably fine. If your primary goal is to protect your privacy, you shouldn't be using Ka-Block.
In the meantime, it's useful to be able to do things like block all third-party AJAX requests and whitelist them on the fly on a per-site basis, or intercept CDN requests for common libraries and redirect them to locally hosted versions.
Extensions like UBlock Origin may be a band-aide, but sometimes band-aides are useful if you're waiting for an open wound to heal. In the same way, when I give people privacy advice, I'm optimizing for things they can do right now.
The problem is that all of the spyware says exactly the same thing. If the API exists, ordinary users are going to be asked to make huge security decisions with no effective way to tell whether the vendor (or the new owner who just bought it) is being honest.
> I'm sympathetic to concerns about people who don't know what they're doing, but if I'm a Safari user, I have to value keeping myself safe first.
This change still means that Firefox will have better adblocking and privacy tools than Safari. It's a tradeoff -- and if I'm a user that's already conservative about granting extensions permissions, I don't see how I get any benefits from this. I only get the downsides in the form of less effective blockers.
As an aside, no one is stopping you from binary patching Safari on macOS, provided you don't mind turning off SIP. The nice API just isn't there anymore.
Your computer is a desk weight without the (or an) OS and software that runs on it. Each os/or software package down to libraries make trade offs that restrict their usage from general purpose to a specific set of functionality. It is impossible to write a line of functioning code without constraining the concept of "general purposes" as you have implied above -- each line of code does "something" not "Everything" by its very nature.
I see nothing about “free and open source” which prevents this.
One malicious push/release effectively enables every user on browsers that have not transitioned to the passive list/filter model of blocking to be completely owned.
It is not about intent, it is about the many many extensions out there that use this feature set for good intent, but inherently open the risk of a full on traffic funnel should they be exploited * the number of users for each of them.
That cannot be "just replicate"d for javascript extensions.
This is false. You can deploy a react native app with dynamic code downloading and execution to the apple app store.
This is false too. If extensions aren't allowed to communicate with the internet and can't auto-update themselves, then they also can't run arbitrary code without the user's consent.
I've had to help others, whose computers did not have such blocking software (and they might not want to), and had to physically put my hand over parts of pages "cluttered with moving shit" in order that it would not distract me and allow focusing on the content itself. These people are also the ones who tend to miss details in instructions and seem to blindly ignore things like (actually important) notifications and warning messages, which leads me to wonder if their natural state of mind while reading pages is so distracted that they have trouble focusing.
Imagine trying to browse modern web pages on a dial-up speed connection. Many sites now completely refuse to load until you load their JS, which calls some external JS, which then renders the page. I run almost every web page without JS and Cloudflare is the number 1 reason for not being able to access a page.
* it doesn’t allow leaking browsing history
* it runs in native code (not js like alternative ad blockers) so much fast
In a way, Apple is doing this to protect user privacy.
In contrast, Apple has introduced & provided the API for a few years, and popularized the idea of mobile win ad blockers.
I can’t see how Apple is doing ‘pretty much the same as Google’. Can you clarify?
Google probably wants to discourage ad-blocking because it's a threat to their business model. Apple just dislikes not having full control on what the users run (and sometimes for good reasons, they probably want to avoid malware extensions). Still, in the end they both end up with subpar ad blocking facilities as a result.
Firefox really needs to become a worthy competitor once again. And no I don't consider forks of Chromium to be reasonable alternatives in the long term, at least until those teams prove that they can maintain a deep fork of the browser on their own which will be necessary if they need to maintain functionality that Google removes from upstream.
A Firefox multi-touch zoom extension also exists[2], but it's not smooth enough to be useful to me (admittedly, this is on my old and slow 12" Macbook).
[1] https://bugzilla.mozilla.org/show_bug.cgi?id=688990 [2] https://github.com/haxiomic/firefox-multi-touch-zoom
For me it's always been, I've used Firefox without pause since it was called Phoenix. I know there was a small exodus to Chrome when it had better parallelization, but as far as I know Firefox is leading on that front again.
So what do you mean by "worthy"? Higher market share or some missing features? I'm obviously biased as I never left for competition but I don't have any complaints, neither on desktop nor with the Android version.
I've used alternative sites when necessary, though. Bing Maps is actually fairly decent.
I think the most probable reason for that has been the complete support for addons that no other browser ever did. For instance, why doesn't Chrome have support for vertical/tree-style tabs without using a separate window? That one feature alone keeps me on firefox. By removing the tab bar at the top of the screen, you regain a significant amount of vertical space on a laptop.
Last time I tried tree tab, it wasn't possible to remove the tab bar. Has this changed? And if so, would you mind sharing how to do it?
#TabsToolbar {
visibility: hidden;
}The former, I also use Firefox as my main browser (and have been doing so for a long time). I worry that it may not survive in the long run if its market share remains so low.
That being said the latter might also be true for Mac users as apparently it suffers from performance issues (it's even mentioned in the Github issue linked). Fortunately it seems that it's going to be fixed in the not-so-far future.
On Windows or Linux, IMO there is no competitive advantage on Chrome vs Firefox; However on macOS, Safari has a very big competitive advantage that Apple has done lots of integrations to macOS; it’s not just something like IE where Microsoft used private APIs to be the default browser; but that macOS users tends to have a big bias on native apps developed with the Cocoa API, with a native looking interface. Both Chrome & Firefox is a cross platform browser that really doesn’t really care whether the macOS version is integrated well, hence having a very outstanding look compared to other apps.
While Safari feels like home, Firefox looks horrible — seriously, what is up with that border-top-color on each tab? And the black border around white icons on the light theme?
Yes, you can fix anything using userChrome.css — heck, you can make it look exactly like Safari —, but each update breaks some pieces of your CSS file, which after a while becomes quite annoying.
Tab groups are the colored borders, very handy if you use containers. That's one of the killer features to FF, if I'm in a Google, Facebook or Amazon domain I'm isolated. Then when I click an exit link or anything not categorized, I'm in the default container. It's stress-free browsing for me as I got tired of seeing online entities pick up things about my life that it shouldn't have had access to.
I also like Safari (and Edge). I've been using FF since it was in beta (Phoenix) and never left, FF is the only browser popular with the features I think balance out the energy efficiency improvements of native browsers.
It doesn't invalidate the other motivation for wanting extensions to be published in the app store, of course, but I think the privacy use-case is sound.
Firefox stems from Mozilla (1998) stems from Netscape Navigator (1994, originally).
Chrome stems from Blink stems from Webkit (Apple's thing, 2001ish) stems from KHTML (KDE, 1998).
Amusingly, all the historical parts of the Chrome stack are basically still around. You can install recent versions of Safari and use Webkit, or install recent versions of Konqueror and browse the web with KHTML (although development has lagged since 2016).
However, I have recently become a power user of uBlock Origin specifically to curtail the general attention hacking on the web. uBlock Origin is already a very great ad blocker in its default installation, but I've recently got into using its powerful cosmetic filters to block out "attention hacking features", such as (all of) YouTube's recommendations, comments on various sites, and stuff like the "Hot Network Questions" on StackOverflow. Things I've discovered that are too good at distracting my mind. With a few uBlock Origin cosmetic filter rules, those website elements remain hidden when I visit them.
I wonder if it's possible to continue using Safari with my own distraction filters. It's a shame if I have to stop using it.
youtube.com##ytd-browse[page-subtype='home']
youtube.com##ytd-watch-next-secondary-results-renderer
youtube.com##app-drawer
youtube.com##ytd-item-section-renderer.ytd-comments
youtube.com##ytd-guide-renderer
youtube.com##ytd-mini-guide-renderer
youtube.com##ytd-topbar-menu-button-renderer
youtube.com###buttons.ytd-masthead
youtube.com##yt-icon-button
youtube.com##.ytp-endscreen-content
Note this is only accurate at the time of writing, only works partially on mobile, and may break some edge cases I don't use :)[1]: https://github.com/gorhill/uBlock/wiki/Static-filter-syntax
You can, and I’m working on making this. (No timeline, since I’m notoriously bad at getting things out the door.)
Edit to add: These solutions will not be as convenient as the current state of affairs, I contest that.
Nobody needs to wait on the internet - you can just go right ahead and type!
"there's EBay..."
You're saying that for a business to be successful on the internet they need to get their money from buying and selling goods on eBay instead of running adverts? Or that they'll sell adverts on eBay? I'm puzzled.
If ads are the only way to "make money on the internet" then we've created a monster whose only sustenance is advertising and it is its time to lay down and rest eternally.
If that means a third of the internet no longer exists... even sites I have at one time enjoyed, then so be it.
If I can't block normal YouTube ads, I mute the sound and avert my eyes for the duration of the advert. I don't do that for embedded static advertising.
Many of these sponsored ads ask for access to the YT analytics data for these channels, without which they wouldn't even consider a sponsorship. Add to the fact they all use a tracking link.. etc.. So yes, they're not personalised, but that doesn't mean you're not being tracked.
Idem with ads.
True, but you could also say same about state of advertisement on TV. I think this problem is quite far away, as most people don't use them. Also major players are/will be actively throwing obstacles for average Joe to install ad blocker.
Also consider impact of platforms like patreon, et al. A lot of small time one-person content creators are being supported mainly by it. So there are quite few people who are willing to support quality stuff (disproving idea that people are trained to get everything on the internet for free and ads are only way to make living).
Which would be a good thing.
The internet will be fine without ads and tracking.
Sites are free to block me if they want... plenty of other sites I can go to.
Beyond that I have no issue with websites having to move away from ads and towards a paid model instead. I actually welcome it. I want to be the client, not the product. I want more websites to offer me the possibility to pay for an ad-less experience.
No, it's a myth, the web doesn't work like that. There are many millions of websites, but only some thousands can actually make enough on ads to sustain themselves. And most of them can survive if everyone starts blocking ads. It's online advertising companies and adtech industry that are going to fold if everyone starts blocking ads, not anyone else.
Otherwise I'd be stuck in apps that have at least some vested interest in keeping ads reasonable.
I still use Firefox with uBO and enjoy being able to hide all those annoying headers, footers and overlays.
NextDNS takes the load off outside the network perimeter and concatenates all the many lists and trackers in one dashboard. I'm free to use other gentler add-ons in the browser if I so desire, rather than have the DOM split apart and my local machine do all the heavy lifting.
The best thing about using DNS-level blocking is that it's an elegant solution across all my devices, especially when paired with a VPN that enforces those resolvers.
It hasn't bothered me long term though. If that happens and I care enough about what made me follow the link then a quick search has always brought up another route to that content or equivalent content.
Often I don't care even that much in which case I click the back button or close the tab and get on with something else. In fact this "problem" might be saving me wasted time that I can use/waste elsewhere. It might even be saving money by reducing impulse purchases, if the links are ones I've followed to see what the sales pitch is for a product/service that has been mentioned in an article!
Heck, it has at least once saved me money, and not just because I gave up trying to get information on how to spend it: searching for the product when following the "direct" link didn't work found a better offer from another source (in that case if was an offer on the particular variety of running shoes that I currently prefer).
You can't, for example, block all Twitter/Youtube requests on third-party pages, but allow them on first-party pages. Firefox containers help a little bit with this, but only for cookies/session data -- not for blocking scripts outright.
However, if you're just trying to setup NextDNS you can signup for free on their website and within the account dashboard you'll find instructions for configuring your desktop and mobile OS, DoH in Firefox, router, etc. (screenshots of what this dashboard looks like are in the blog post if you're curious).
Until a content blocker can offer a right-click “block THIS element” feature, they won’t come close to the power of uBO. The UI alone for highlighting the exact offender in the document tree is brilliant. Every time a “newsletter” pops in my face, I can banish it forever. Every unnecessary floating space-stealing navigation bar, I can banish, returning the screen space that was stolen from me. Every scroll-with-the-article Facebook/Twitter gadget can be similarly removed.
"You're not the target audience (if you disagree with anything that Apple does)"
Firefox has gotten pretty good now, the only problem is no integration with Keychain which is a serious downside. On iOS I use Safari but with BlockBear and Firefox Focus as content blockers. So my experience there is pretty good. iCloud Keychain makes my password situation a lot better going between iOS and MacOS... I’m not sure I can achieve the same using Firefox right now.
But it burns through the battery!
Firefox will use much less power then, on par with Chrome (haven't seen direct comparisons to Safari). Unfortunately by the time it's released Catalina will be out for a month already.
If you want to practice self-defense and weaponry, don't do it at Dave & Buster's.
Exported the passwords and imported it into Enpass. That was the first step in liberation.
I then decided to keep my personal and work related browsing separate especially since both require a google account (Gsuite at work). I wanted an ability to open the browser of my choice based on the URL I click and work anywhere on MacOS.
I implemented a simple URL handler that I register as default browser and that opens the clicked URL in appropriate browser:
https://github.com/hackworks/chromer
It is not a very polished implementation but has been working reliably so far.
With that, I am now able to switch between any browser without any lock in.
One container per customer, and it's all neat and tidy.
Glimmerblocker is unique in that it doesn't use Safari APIs—it creates a proxy to filter traffic before it gets to the browser. Despite that, it's quite powerful; I remember using it to make an extensive Javascript patch for one site.
(I vaguely remember something about Glimmberblocker needing SIP to be disabled, but there's nothing about that on their website now, so I'm not sure. I keep SIP off anyway, so I wouldn't know.)
---
In the (somewhat) analogous case of antivirus tools, that change is from using heuristics to detect viruses to using fingerprints. I’m not sure that makes much of a difference there (but possibly I’m wrong)
Also, the risk here is lower, so not taking the risk to run arbitrary code in exchange for somewhat better ad blocking may be the better choice.
So, what are real-life examples that the uBlock Origin currently blocks that new blockers won’t be able to block?
I'm sure most people on HN would support legalization of marijuana even though it is arguable that smoking marijuana is bad for you. Same thing applies here, I should be able to choose what ad blocking technology I want to use.
True, safari may not be for you then (it's not for me either). But for many people, especially those who don't understand how to get good privacy online, safari takes that guesswork out of the process. Apple applies similar logic to other security related choices they make for users too. It's not for everyone, but it is arguably good for many.
Paternalism from software companies is popular these days.
The seems very sensible given extension owners could start injecting malicious content on the page. Nothing prevents them from selling out — it’s happened before.
I use uBlock origin and love it in Chrome but I can also see where Apple is coming from here. This will probably protect the greatest number of their users.
UBO also has the facility to delete/hide arbitrary nodes from the DOM in order to hide ads that might come bundled with the page.
None of those functionalities can really be used maliciously. At best you can break websites by denying them the ability to load stuff. The problem is that both functionality are bundled with other privacy-invading things (like injecting or reading). But that's of no fault of UBO, it's just the way Safari and Chrome decided to set the permission granularity.
You could have a secure, restrictive API without blocking the best features of UBO. Google chose not to because it's potentially damaging their business model, and Apple probably chose not to out of simplicity.
My fear is that if extensions are crippled and mainstream ad-blocking standardizes on those kinds of restricted "content blockers", it's possible for ad companies to implement an effective technical bypass for them, since they can execute arbitrary scripts, but "content blockers" can't, unlike extensions. You would need Apple/Google/etc. to play the ad-blocking arms race, and they probably won't have incentives for it.
I have used a content blocker for more than four years and I would have to disagree.
That will change if content blocking is the norm.
The declarative API takes control away from the user. Currently you can block everything except the useful content. With the declarative API you can block only trackers A, B and C, but not C and D, because C and D weren't added to the global list of trackers. Moreover, you won't even know that C and D exist. With the declarative api, trackers get a trivial way to bypass adblocking: they can just change the domain name. This is the true goal of declarative API, not performance or security.
Why does the declarative API still allow to monitor your traffic? This sort of contradicts the security selling point, right? Because corporate users need to monitor activity of their employees: they install a corp extension that monitors traffic. They don't need to block anything, but they need the monitoring ability.
The argument that adblockers can route all your traffic thru their servers simply doesn't stand. If this was a concern, the browser could refine the permissions model: an extension can monitor and block any traffic, but it doesn't have access to the internet. Just like in Android you can uncheck the camera and mic permissions for any app. Problem solved.
Why hasn’t the blocker community proposed such yet? It seems like it’s the missing piece: How little scripting capabilities are necessary, etc.
If you had MATCH expressions, CASE statements, and $1/$2/... capturing backreferences, would any of this even be a problem?
I'll give it on macOS a try, because the other day, I noticed that uBlock Origin didn't detect one specific tracking URL, but Firefox did (and it clearly was in the network tab of the Safari developer tools). Now it's clear why: uBO is outdated for Safari.
Anyways, thanks for the port and maintenance all those years when I could use uBO!
I’ve created one that is updated regularly, has a free option, respects your privacy and doesn’t take any $ from advertisers to let ads through the ad block rules [1].
Simply search on the App Store for a variety of alternatives.
uBlock Origin is good but it’s not the be all and end all of ad blocking especially on Apple platforms.
[1] More details at https://www.magiclasso.co/
Not great.
Pyhole vs uBlockOrigin:
- is hardware based
- works on a global scale, including the browser, apps, and the OS itself
- can only block domains, not full URLs
- doesn't have cosmetic filters
- works at home, not really on the go. there is a VPN, but it still uses your home connection
The intermediate solution would be hosts-based blocking.
Sure, it's technically possible for a JS blocker to use more CPU, but 1) it's a trade-off the user should be allowed to make (I'm happy to sacrifice some CPU in exchange for better ad blocking and privacy) and 2) I never had a case where a JS-based blocker noticeably impacted performance.
10 hours on my Chromebook using FireFox Focus and uBO vs 7 hours using Chrome.
Whatchoo talkin' 'bout, Willis?
Browsing the web today has become a dirty business, it's easy to be tracked, and users have the freaking right to defend their privacy when browsing, and to do it in whichever way they like.
I'm tired of these paternalistic and uningenuous claims from Google and Apple that sound like "but we do it for you, you know, adblockers really hurt the performance of your browser". Something hurts my browsing experience? Well, it should be my call whether the pros outsize the cons or not, it should my call whether to use it or not, not the browser's developer call. After all, the web browsing experience today is way more compromised because of the huge amount of third-party scripts that run on most of the pages, surely not by extensions, but browser producers don't seem to put the same emphasis on the need of reducing the use of third-party scripts and trackers.
To me decisions like blocking external web API calls in extensions just because "they may slow down your browser or put your security at risk" sound like if the Linux kernel suddenly decided to disable the support for network sockets because "you know, hackers might use them for backdoors, or you might end up connecting to an extremely slow server and hurt your experience": a complete nonsense bullshit.
Plus, browsers like Brave have recently proved, with its native content blocker developed in Rust, that it's still possible to use a traditional adblocker without compromising the browsing experience.
Time to uninstall Chrome. Time to uninstall Safari. Time to ditch away all the browsers that do their best to limit your freedom on how you surf the web. Extensions are among the foundations of a modern browser, and limiting their power to static lists of rules is an immoral decision that deserves a serious boycot act from users.
That being said, this post reminded me to install a replacement, so I just installed Adguard. We'll see how it goes.
Also I didn’t see anything flagrantly bad at first glance.
Edit: Looking closer you may be referring to the old extension and not the new “content blocker” version, which is sandboxed by Safari and didn’t need to ask for any permissions.
It launched on HN a while back: https://news.ycombinator.com/item?id=20012687
Interestingly I found this while looking around for the answer: https://github.com/uBlockOrigin/uAssets/issues/5184#issuecom...
I switched to AdGuard from uBlock Origin.
Any feedback on this?
It’s great, but I also use 1Blocker — have since its release, also use it on iOS — and I think it does most of the work. I’ve only recently added the blocklist to Little Snitch and I don’t notice much difference.
Of course Little Snitch is blocking all network traffic, including Firefox. I use Firefox as my dev browser and don’t have any blocking extensions loaded.
It’s in the category of ‘why not’ for me, I already have Little Snitch so I may as well load in these rules.