uMatrix has been archived
github.com
github.com
Now, obviously you could always write an ABP compatible filter that could block any combination of these two, but that's hard. What uMatrix did is present the underlying complexity in a way that's easy to intuit for a power user, giving you point-and-click request filtering power over both domains simultaneously.
For that reason, I'm skeptical that uMatrix can be replaced with a traditional blocker, not even one with an advanced mode like uBo, because it simply doesn't allow the specificity that a two-dimensional model like uMatrix did. That makes uMatrix's being archived incredibly tragic and a great loss for the web. I hope someone as trustworthy and competent as Raymond will pick it up in the future, and I thank him for all his work on it up to this point.
I don't think you can for cookies. You can block cookies in the browser, but I'd like a filter list so that it is possible to change across all my browsers by subscribing to the same filter list.
What I personally didn't like about it though are the tech specific parts (e.g. xhr and other both require script anyways, as not a single website will work with xhr disabled).
So for my browser project [1] I decided to split it up into "text", "image", "audio", "video" and "other" which I hope will make more sense for most people.
Back in February when the debate about the manifest and requests api started, I started my own semantic browser project which aims to filter out all UX-interfering CSS and HTML and probably won't allow JS anyhow.
It tries to focus on the automation and caching parts that are broken in current web browsers, so that everything is peer to peer, and that other trusted peers can be used to share bandwidth, content, or metadata with each other and that each one has a 100% persistent local cache that only gets refreshed once the user tells the browser to.
If there'll be a need to support webapps later, they will probably be sandboxed in a new window that represents a temporary cache located in /tmp/... in order to prevent abuse of local storage and cookies. I've learned to not trust any site these days, even my bank's website uses foreign overseas-located trackers, which is technically a GDPR violation.
That's total nonsense. I browse with uMatrix blocking everything by default and I rarely need to enable xhr to make a site work. Most of the time it's only used to bloat a site, not deliver the actual content. The same is mostly true of javascript as well.
This is particularly true on newspaper websites. A great many news sites are reasonable with everything disabled but utter cancer by (typical) default.
Well, maybe we have a different pool of websites we visit. But usually, in my case, pretty much all websites built with vue.js, react, angular and others usually don't have server side rendering implemented correctly.
Just as an example, what I visited just yesterday: https://portal.msrc.microsoft.com/en-US/security-guidance/ad...
Doesn't contain content, it's just a blank page without the XHR request. And all webapps I've seen so far basically just scaffold all polyfills and stuff, without any kind of content being delivered (or serialized) inside the HTML.
Additionally, all newspaper websites that I've seen in my country blank out everything with white-on-white if you don't allow JS with XHR. Either that or the article teaser is faded out with an overlayed blur image. Well, that is at least when you don't set the user-agent to Googlebot :)
Your example displays content for me just fine in my default config, because the XHR requests are to the origin. Yet it blocks useless requests for two dozen different resources on other domains.
Well there's your problem. Microsoft counts as one of the sites that uses web tech to invade your privacy. Many parts of microsoft-dot-com don't work without javascript.
umatrix -> reader mode -> read your article
Isn't serving different pages to users and search engines against Google's policies? They call it cloaking.
https://developers.google.com/search/docs/guides/dynamic-ren...
The content is served from a different URL. The simplest solution is to use that URL, not the "empty container" one. For example, to retrieve the content and extract just the FAQ part:
curl https://portal.msrc.microsoft.com/api/security-guidance/en-us/CVE/CVE-2020-1472|grep -o "frequentlyAskedQuestions\":.*</p>"|sed 's/\\n//g;s/frequentlyAskedQuestions\":\"/FAQ/' > 1.htm
firefox ./1.htmThis conversation is about browsing the web, not the strawman you've constructed. We're talking about websites that you go to and they don't render if you turn off JavaScript, of which there are many. Dragging it into the corner where you're using cURL+grep on an plain-text endpoint which happened to exist for the example provided is not a valid response.
It is probably a mischaracterisation to suggest the "plain-text endpoint" existed by chance. Many, many websites use the same or similar frameworks and "plain-text endpoints" have become commonplace. Regardless of the trends in web development, the solutions I use for text retrieval work reliably across almost any website, otherwise I would not use them.
When a page doesn't work, and I care enough to un-break it, I will first try enabling just js. If that doesn't work, I'll add XHRs, too.
So, I can say with confidence that there are a good deal of sites that fall into both camps. I cannot say the ratio with confidence, but there are enough sites that work enough with just js that I choose not to enable XHRs. Here are a few examples:
- Kotlin documentation gets collapsing menus and nicer code formatting: https://kotlinlang.org/docs/reference/visibility-modifiers.h...
- This person's blog gets inline/popup footnotes and, er, a functional "hard mode" (top right): https://mango.pdf.zone/finding-former-australian-prime-minis...
- https://represent.us/ renders about halfway without js.
The final example is the most relevant to this conversation, I think. Especially, there is a phenomenon, common enough that I've noticed it as a pattern of sites that display images with js (and sometimes content), and don't require XHRs to do so.
----------
Looking through my history to find these examples, two things become clear (about the sites I visit; I don't claim my browsing is representative):
1. Regardless of whether they also need XHRs, sites that require JS fall overwhelmingly into one of two categories: either I use them regularly and they're already on my saved whitelist (eg, YouTube), or I decide that I didn't care enough about them to bother enabling javascript
2. Yes, you're right; most sites that require js, also require XHRs. However, if we limit ourselves to the subset of sites above that I haven't whitelisted and don't want to walk away from — ie, the ones where I'm actually fiddling with uMatrix — it's somewhere around 50%.
In conclusion, I think the functionality is useful and should not be axed, but it's probably a also good idea to have a simplified mode like you suggest: combining js, xhr, and other into one column. Maybe also removes the "cookies" column — most browsers have built-in preferences for those; 3rd party cookies almost never have to be unblocked; and I don't know (m)any people besides me who block 1st party cookies by default.
[0]: Here's what that looks like when actually applied to the page. The keen observer will note that scripts are only temporarily enabled (I do this only when I want to use the collapse functionality). This (enable it when I want it) is a common browsing pattern of mine on sites that do progressive enhancement. https://smichel.me/hn/umatrix-hn.png
You're not going to allow JS? I don't know the answer, but I'm curious what percentage of sites are unusable without JS? It might be fine for basic browsing, but nearly any ecommerce or site with "interactive" content uses JS. Many video players require JS. It seems like a very niche solution that won't have mass appeal if you're not going to allow JS.
To me, the perfect solution would be something similar to uMatrix where power users can choose the settings they think are best. Anyone else can use simplified controls to indicate if they're seeing ads or if site functionality is broken.
Then there's some aggregation software that looks at all of those inputs and determines the best default settings for each site. If ads are seen then the blocking levels are increased toward the fringe of advanced user inputs, if functionality is broken then it walks back the blocking levels until broken functionality reports end.
This would be a never ending eb and flow for each site so it would be important to automate it as much as possible.
Turn everything OFF for all sites by default. I turn off third party stuff and all scripting.
Then visit a new site. Then opt-in until you either - decide the site sucks and leave, or get something acceptable and read your article. Then press SAVE to save the settings for that site.
It's worth mentioning that many sites do not render well without javascript, but reader mode renders a perfectly readable article.
but also it's much MORE prevalent that you turn on javascript and the site will do much worse things.
I enjoyed the ride.
uBlock Origin has blocking mode [1], it should be possible to start with hard mode and degrade with shortcut.
Disabling part of the page make it broken for one user and improves for another. No cookies - no previously viewed; no javascript - no interaction; no css - hidden content displayed; no media - faster load. Just like with Stylus a lot of opinions.
I can mark what works with my setup, but it does not necessary matches your accepted level of "brokennes".
Well, at least not in the "main app" of the Web Browser. I'd rather integrate an automateable sandboxing concept for webapps, so that users can choose to e.g. use Instagram or Facebook; but without having to worry that the localStorage and cookie quirks in there can be used for any tracking.
In my head it will be probably something along the lines of if "other" is activated, display a little notification under the address bar that asks something like "Do you want to bookmark this as a sandboxed Webapp? [x] Yes [ ] No" which will lead to a new window being opened that is sandboxed with its own WebKit cache and its own WebKit userdata folders etc.
Regarding video players: I'm also thinking about integrating youtube-dl (probably as a JS API/runner(?) as my Browser is implemented in node/ES2018) for video websites, but currently I'm not sure whether this will be an endless task to compete with, as a lot of video streaming sites work with mixed transfer channels such as WebSockets or chunked transfer encodings wherein the video chunks themselves are not transferred via 206 Partial Content.
I'm hoping that also solves the problem safari has where if I login to a site in one tab (in private mode), I can't open a second tab for that same site without having to login again. Chrome doesn't have that problem with incognito, but of course those cookies and local storage can be used for tracking across other sites then too.
Foreign overseas-located trackers isn't technically a GDPR violation. It's a GDPR violation if the trackers don't treat data in a GDPR-compliant fashion, and it's your bank's responsibility to ensure they do.
However, the tagging model seems so limited compared to what uMatrix can do. uMatrix has 8 different requests types, so you'd need 2^8=256 different tags to cover every combination of requests to a subdomain. And that's if NoScript can block cookie requests at all: 90% of even the domains I fully trust have cookies blocked in uMatrix, simply because the sites don't actually need cookies to function. Maybe I would need yet another extension for that.
Also, however, part of what I wanted to get at in talking about the brilliance of uMatrix was the way the interface made very precise controls easy, just a point and click operation. Maybe it's possible to get a similar amount of power with a tool like NoScript, but as far as I can tell the usability of the interface just doesn't come close.
Well, technically that is only partially true as the third dimension is the (sub-) domain scope or "*" which can be reflected behind the scenes with the first-party settings for the origin's domain for each request type because it has the identical effect.
But if you view the rules, you'll see its three dimensions spelled out:
* * * block
* * script block
* 1st-party * allow
stackexchange.com sstatic.net * allow
stackexchange.com cdn.sstatic.net script allow
This is full [source domain] [target domain] [request type] flexibility. The GUI will only show the stackexchange rules above when you're actually visiting that site; it doesn't mean the third dimension is fake.I'm not 100% sure on the reason why uMatrix wasn't available on Safari, but I think it's because content blockers aren't allowed to see any user data. Ad blocking plugins just send a list of content to block to the content blocking API, and Safari does all the blocking and doesn't send any data to the plugin. So uMatrix's intuitive UI that GP was talking about isn't possible.
Apple claimed that they stopped supporting WebExtensions and made the content blocking API in the interest of user privacy, but all it really did was drive users to other browsers. In typical Apple fashion, they decided what was best for me when (AFAIK) I've never had a problem with an untrustworthy plugin stealing my information.
It might technically be possible to functionally implement uMatrix with multiple plugins (one to interact with the DOM to figure out what to block, then generate the blocking list, and one to deal with the content blocking API) but all the plugins I've seen don't do it. Maybe it's not possible, maybe the extra development effort isn't worth it to support a single browser that has fairly low usage.
I’m not sure I’ve seen that - the number of Safari users had been pretty constant on my sites, and the main pressure seem to be the Chrome pushes on Google sites.
I think the UI challenges of Safari’s approach are a big problem but on the other hand there were years of people blaming browsers for ABP’s bad performance and users privacy was definitely sold out by unethical developers. As a user it definitely is easier to trust one over the other.
No, it's not possible to do performantly. You can't dynamically update your blocking list that quickly, the JSON rule list must go through WebKit and that can easily take multiple seconds.
I will never hand over development to whoever, I had my lesson in the past -- I wouldn't like that someone would turn the project into something I never intended it to become (monetization, feature bloat, etc.). At most I would archive the project and whoever is free to fork under a new name. For now I resisted doing this, so people will have to be patient for new stable release.
What would actually help is that people help to completely investigate existing issues instead of keep asking me to add yet more features. Turns out people willing to step in the code to investigate and pinpoint exactly where is an issue (or that there is no issue) is incredibly rare.
https://www.reddit.com/r/uBlockOrigin/comments/i240ds/reques...
it was taken over by the same people behind "AdBlockPlus" which is a shakedown operation. They're allowing ads to be unblocked if advertisers pay them money.
Some history; https://old.reddit.com/r/chrome/comments/32ory7/ublock_is_ba...
The adblockplus model is extortion. They're not incentivized to serve the end user well, especially when their primary source of revenue is the advertisers the users are attempting to block.
I don't have time to work on uMatrix -- it's a project large enough that I would be able to work on it only if I wasn't working on uBO.
Ayyyup
One of the reasons people just decide to rewrite everything instead...
Rarely are those potential reasons actually weighted up against the full cost of the rewrite
I even started installing it in my parent's computers (not advanced users), reducing to 0 the amount of time I had to intervene to fix their computers. The trick is to configure it in blacklist mode, instead of whitelist. This way it only blocks requests from domains in the blacklist and frame elements. Just with this change you get non-power users out of trouble in their surfing habits and impacts negligibly their use.
I have taught them that if a web is blocked or doesn't work properly is most likely not a web they want to use but that there is also the possibility to turn it off using the on/off button (that they should use very judiciously). In this mode it is not too different from setting up Hosts file but they can understand better what's going on and how to turn it off if needed.
EDIT: fixed typos
Or you can use it in whitelist mode, but with all things like Cloudflare and ReCaptcha globally whitelisted. It's good that way too.
But yes, for your parents, black list mode would be good. It would be like uBlock Origin.
those two specifically are always the first entries in my blacklist :D
Fuck any site that requires this hostile bullshit. 9 times out of 10 when I see recaptcha that site is dead to me. Very few sites are worth tolerating that sort of abuse from.
[1] https://greasyfork.org/en/scripts/382039-speed-up-google-cap...
Also, the web would be much more annoying to use without captchas. (Not necessarily recaptcha, but just the concept in general.) If you've ever been an administrator of a site that's prone to spam, it's usually one of the only effective options. Other trade-offs would generally involve blocking huge ranges of potential users, with tons of false positives, or laborious manual approval which isn't feasible past a certain scale if it's just you or a few people.
This is a non sequitur; we're talking about Google's abusive faux-captcha (which is not actually recaptcha; that's the two-word OCR challenge captcha they replaced with said faux-captcha), not about any actual captcha or captchas in general.
>Because fuck them. Recaptcha in particular
I think I read it at that moment as "because fuck [captchas]. Recaptcha in particular". But they meant Cloudflare and Recaptcha.
I will say, as annoying as Recaptcha is, I find hCaptcha a lot more annoying, difficult, and time-consuming. (Cloudflare recently switched from Recaptcha to hCaptcha.)
I failed 4 "select the motorcycles" yesterday after selecting like about 7 - 8 of 18 images per try. So that's minutes spent clicking 28 - 32 out of 72 squares, and I failed every time, because I don't know much about bikes/vehicles and they mixed in regular bicycles and other semi-motorized bikes (which were all wrong answers), and many of the images were extreme close-ups of possible axles or handlebars with no clear shapes, and others were just generally blurry, unclear photos. It makes Recaptcha's ultra-slow fade-ins seem like bliss. I got the fifth one when they switched from motorcycles to something else, but that one wasn't easy, either.
Ah, that makes more sense, and now I'm not sure that wasn't what they meant (although it seems unlikely because fuck Cloudflare).
I'm not familiar with hCaptcha, but what I've heard (including from you just now) suggests that it, like Google 'captcha', is also a javascript-using non-captcha, in which case fuck them too.
More generally, you can often find a domain that calls itself a cdl, and those are usually needed. And sadly, if the site doesn't seem to work at all it probably needs google.
Oh, and it is basically never something in dark red.
"* * * block"
This rule acts as a default blacklist. If you switch it to:
"* * * allow" it will allow everything by default (except the blacklisted domains, which overrule this).
Then in the "Assets" tab you can configure your blacklists, I can recommend Steven Black's lists. He curates and consolidates several of the most famous ones:
https://github.com/StevenBlack/hosts
He maintains several variants according to themes you may want to ban (adware, malware, fakenews...). Choose the combination that suits you.
uMatrix helped me realize how much of 3rd party resources are crap. Actual crap. Completely unnecessary. It also helped me get familiar with new 3rd party crap that pops up on the internet.
I'll use uMatrix 1.4.0 as long as it works. Many thanks
Chromium mobile doesnt even have addons because they are shit scared of adblockers.
Paradoxically, I'm kind of half-happy to hear this.
It means that finally a large number of users are using adblockers.
For many years the standard theme of many threads on adblockers was that companies like Google didn't care about them because too small a percentage of their users used them for it to matter.
Now finally there are enough adblocker users for it to hurt their bottom line, and that means that there are more people than ever who clearly just don't want to see ads.
That gives me hope that there will some day be anti-advertising legislation, and that we might not even need adblockers... some day... some day...
People dreamed of an Internet where sharing of information was free (as in freedom). Then DRM happened. And even if DRM cannot be 100% reliable, being broken by design, it's reliable enough, plus in the US at least it's a felony to break it. And as years go by, we see more DRM, not less. This happens, because the practice is normalized, and because small inconveniences are taken care of (usually by monopolies winning the market—e.g. you stop complaining that alternative e-book readers don't work, when everybody is using the Kindle or the Audible apps).
Similarly, for the open web — the action has been moving on mobile devices. A majority of people now consume content via mobile devices. So what do you see? More websites? Or more apps? And for all ad-blocking happening at the DNS level (e.g. Pi-hole), how long do you think it is before apps start doing DNS over HTTPS on their own, bypassing the OS's stack?
This is a wack-a-mole game, and the big publishers have enough resources to push for both technical and legal changes for outlawing ad-blocking. I'm actually surprised that content blockers remained legal thus far. But the writing is on the wall IMO.
---
There's also another side of this coin. I see more and more people on HN complaining that articles are submitted from publications that are setting up paywalls.
People also hate paying for content. And even those that pay for content, they don't recognize what an incredible privilege it is to afford it.
Either content is monetized somehow, or the only content that we get will be content created by hobbyists, in their spare time, for free, while working a regular job.
Well I for one don't want a world in which the poor don't get access to online resources, or a world in which people can't make ends meet doing what they love.
I've been chewing on an alternate narrative.
Firstly, I don't think any of us anticipated preferential attachment. Even despite the popularity of "six degrees of separation" and other graph related notions. Clay Shirky's essay about Power Laws was my first exposure to the idea. Here's Kotte's meta entry: http://www.kottke.org/03/02/weblogs-and-power-laws
Everyone complains about how "the web" we got is broken. It wasn't until very recently that I understood that Ted Nelson's Xanadu vision, an often imagined alternative timeline perfect web, requires centralization. Um, is this really what we want? Because that's what we're getting. Incrementally, fitfully, inevitably. Your warnings about DRM times infinity.
Also the libertarians, anarchists, technophiles behind "the web" thought we'd have micropayments. Instead, we got advertisements and freemium. I don't know if micropayments, or prepaid wallets, or subscriptions, would be less toxic. But it couldn't be any worse.
Yes, that's why we need to make it impossible to monetize content.
Also Google is going ahead with deprecating the necessary APIs in Manifest v3, going with a Safari-like model for content blocking, which is far less capable. Soon uBO, uMatrix, Privacy Badger won't be possible at all on top of Chrome.
[1] https://www.zdnet.com/article/opera-brave-vivaldi-to-ignore-...
> Anyway, as it is, I've archived uMatrix's repo, I can't and won't be spending any more time on this project, and neither on all such issues [linking to all issues closed as invalid].
https://github.com/uBlockOrigin/uMatrix-issues/issues/291#is...
So it's really confirmed then. Very sad news.
Edit: there's also a glimmer of hope:
> Whoever is free to fork under a new name -- I may re-open and resume development in some future if ever I feel for it.
Unless you have trademarked the name, you don’t get to reserve it for a rainy day, anyone should be able to pick up the torch and continue the project without having to start from scratch with a new unknown name.
gorhill stopped doing uBlock and passed it to others, who subsequently took it in a direction he didn’t like, so that he resumed maintenance under the name uBlock Origin (since the name “uBlock” had been transferred).
So this time when he stops maintaining a project, he’s avoiding the same thing happening.
> I will never hand over development to whoever, I had my lesson in the past -- I wouldn't like that someone would turn the project into something I never intended it to become (monetization, feature bloat, etc.). At most I would archive the project and whoever is free to fork under a new name. For now I resisted doing this, so people will have to be patient for new stable release.
1. https://old.reddit.com/r/uBlockOrigin/comments/i240ds/reques...
Contribution graph for the original uBlock project during this time frame: https://github.com/uBlock-LLC/uBlock/graphs/contributors?fro...
and now compare to the 'personal fork' that is uBlock Origin: https://github.com/gorhill/uBlock/graphs/contributors?from=2...
So if 'squatting' the name of your own OSS project is considered 'user hostile' then let this be a lesson to people considering giving up their project: the person you give it to may abuse your trust and the trust of the community in order to further their own agenda, in this situation it was all just pretty harmless petty drama but it might not always work out so well.
Random Github projects aren't organisations with funding and staff with rules and responsibilities to keep the project running, it's okay to archive the project and let the community decide what to do, giving the project to the first person who asks may end up achieving the same thing as archiving the project or it may come back to bite you in the arse damaging your reputation in the process.
Not a lawyer, could be wrong about this.
Trademarks don't need to be registered to be enforceable. Registration makes things easier for everyone by stating the registrant's intented scope of the trademark and makes a few things easier for the owner. However, the enforceability of a trademark rests on its awareness by customers, active use by the owner, and active defence of the trademark by its owners. uMatrix certainly is certainly a trade mark, however, the two latter criteria are probably not met.
I'm also not a lawyer, just interested in this stuff. This is not legal advice. And of course the details will be wildly different in different parts of the world.
Again, I don't know anything, but I'm surprised that uMatrix would count as having been "commercially" used. And as you point out, these two criteria probably wouldn't be met if the project becomes inactive:
> active use by the owner, and active defence of the trademark by its owners
It's also still used by the owner, as it's still listed in several extension stores.
Trademark protection also doesn't end over night. Trademarks are generally protected for a few years after the owner ceased to use it. Also, one should keep in mind that trademarks aren't primarily an intellectual property concept like patents and copyrights. Their main purpose is to protect consumers from copycats and fake products.
As uMatrix was distributed to users through the extensions platfrom, this is already sufficient to classify as commercial use.
μMatrix
Obviously "anyone should be able to pick up the torch" has the issue that the "anyone" may well be a malicious person who is seeking to defraud the users for monetary gain.
https://blogs.findlaw.com/free_enterprise/2017/05/4-defenses...
https://www.forbes.com/sites/oliverherzfeld/2013/02/28/failu...
You already have the right to copy all of someone's years of hard work, add a tiny patch, and pass it off as your own project with a new name. The very least you can do is give respect to the original author by allowing them to keep their original name.
Then there's potential for libel. Let's say you fork a project, keep the original name, and then pepper the project with Nazi propaganda. The original author is trying to get a job, and his resume has the name of the original project. A prospective employer searches the name and finds the new project (with the old name) full of hate speech. If he gave away the old name, a libel suit to change the new project's name may fail, and his reputation might be forever tarnished.
Case in point: keepass -> keepassx -> keepassxc, where both keepass and keepassxc are maintained and are essentially separate projects.
Perhaps the activity was slow, I guess you could call it "maintenance mode," but I've been using it all this time and uMatrix works fine in its current state, so all it means is that there were no new features being added.
It looks like the immediate reason for the repository being archived was somebody opening one issue too much.
1. Copy-and-paste the repo, rather than using Github’s forking mechanism, because Github “forks” don’t have their own issues/PRs (being something more equivalent to multi-branch workdir collections for an upstream repo);
2. Copy all the issues over from the origin repo (manually, or by writing a script against Github’s API/CLI);
3. Sadly, likely lose all the original conversation on those issues.
These problems would be obviated if issues were just data files committed inside the repo — with any branch that contains the open issue file meaning the issue pertains within that branch; and any branch that closes the issue meaning that the issue is solved as of that commit. A fork developer could just fork the repo in the traditional fashion, and end up with a fork of all the issues alongside.
Does any git hosting service/software handle issues in this fashion, i.e. as a layer of web-chrome and backend indexing over files committed to branches of the repo (where you’d always have to be looking at the issues as they exist within a particular branch)?
For that matter, does any git hosting service have a sane high-level set of workflows for “forking” in the sense of creating a competing (or replacement) maintained-upstream-repo for people to contribute to?
1. Agree with the original author that a fork/take-over is the right thing to do.
2. Create a GitHub organisation for the project, where rights and repos and everything can be re-allocated/delegated as needed.
3. Make original author transfer his repo to this organisation.
4. Done. No more steps.
It also includes magic redirects for all requests to the old repo, including issues and also git-request, so down-stream projects won’t even have to know.
It’s really very simple, and it works well.
I think this is a clear deficiency of git and many other VCSs, which fossil avoids. It's clear that bug reports and commits will frequently cross-reference each other, so they should be tracked in the same system. Git only implements one half of the puzzle, leaving the other half up to others which ultimately facilitates vendor lockin.
You can enable issues on forked repo, and any forked repo may receive PRs.
Still, manual repository is preferable as deleting repo will delete also its forks created using Github interface (at least it was happening some time ago)
I haven't observed this to happen - in my experience, the first fork becomes the new "upstream" for all the rest.
Their point was that issues in the new repo are completely separate from issues in the old repo. A new issue created in the new repo will be issue 1, and to browse the old repo's issues you have to navigate to the old repo. If the old repo is deleted all those issues will also be deleted and history will be lost.
That's why they mentioned the workaround of using the Github API to export the old repo's issues and re-import them into the new one, which would not be needed if issues were git objects and thus trivially copied into all forks.
uMatrix is an essential part of my everyday life.
Will it still work? If not, is there a trustworthy replacement?
I don't want an "ad blocker" with blocking lists etc. I just want to see the page I navigated to. And then allow it to load additional resources as I see fit.
If uMatrix goes out of existence, then that would be the biggest loss due to discontinued software in my lifetime.
Firefox add-ons can be installed from third-party sources as well, and in the case of uMatrix it's worth doing it anyway, since the latest version (1.4.1b6) is on GitHub only:
https://github.com/gorhill/uMatrix/releases
It's a beta but seems to work just fine. Mozilla is still at the last stable version (1.4.0):
But most importantly, uM also allows you to filter cookies with the same fidelity, which is the number one thing I would miss if I had to rely solely on uBO, because it means I can default to blocking even first-party cookies from sites I don't want leaving cookies on my machine. FF by itself gets close, by letting me set a policy that says "block all cookies except for cookies from these domains", but that doesn't let me filter which site is allowed to access those cookies.
Frankly, I find uBO redundant if one has uM installed but for two things: uBO can use the usual content-blocker lists (I personally don't need them because my router's DNS server does filtering using those same lists already, but it's useful for people without such a setup), and uBO can block remote fonts whereas uM can't. It would be great if uM's kind-based filtering was merged into uBO and remote fonts were kept as just another kind of request that can be filtered, but I don't know what gorhill plans to do.
$script $image $subdocument $stylesheet $first-party $third-party $xmlhttprequest $csp $inline-script $inline-font ...
So it looks like the equivalent of this uM rule:
github.com raw.githubusercontent.com xhr allow
would be: @@raw.githubusercontent.com^$domain=github.com,xhr
... or something. (I have to spend some time RTFMing.)So then, like I said in my previous comment, it seems it would be the best of both worlds if gorhill took the UI from uM and put it in uBO.
> What would actually help is that people help to completely investigate existing issues instead of keep asking me to add yet more features. Turns out people willing to step in the code to investigate and pinpoint exactly where is an issue (or that there is no issue) is incredibly rare.
That said, this is clearly a useful tool and I wouldn't be surprised if the user base was 10,000+ which means that if you'd make it $3 monthly to use as a commercial product, the revenue (after attrition) should be enough to pay for at least one part time employee to do the maintenance.
I would also expect that releasing this as a paid product, as opposed to open source, will actually reduce entitlement by users. Or at the very least, you can always just issue a refund and be done with it.
I would still hope for source code insight to make it transparent how this tool works. But that is not necessary a hindrance towards productizing it. Unreal Engine 4 is a commercial success, despite shipping with full source code.
That is the very opposite of what I’d expect and have observed personally over the years. The folks who’ve paid a small amount are virtually always the most demanding and refunding them and asking them politely to go away just fuels their indignation further.
The best way to “mourn” a lost software project is to ask yourself what you will do to maintain the software ecosystem. How many things do you use for free? How many things have bugs you never bothered to tell anyone about? Has each of you contributed something (even a short E-mail thank-you) to some software project?
> uMatrix is a blocker(cookie,css,image,plugin,script,XHR,frame, and other) you can control what you block and what you want to allow(like uBlock Origin dynamic filtering but way more flexible and can be way more strict) uMatrix just blocks ads through the use of host files, uBlock Origin blocks them more deeper per se then uMatrix because of cosmetic and patteren-based filtering like adblock plus. I use both of them together just uncheck the malware domains in uBlock and peter Lowe's and the host files. Also you have more privacy and security when running uMatrix because of the switches(user agent spoofing and referrer spoofing, clearing blocked cookies, blocking hyperlink auditing attempts etc.) and also if you run uBlock it gets whatever ads uMatrix does not get from its blocking) Look at my sig to see how I run them. If you need help just PM me.:thumb::):cool:
I personally run ublock origin and have been super happy with it, never even think about it these days, if I was supposed to switch to uMatrix at some point (I know uBlock and uBlock origin are different now and origin is preferred) I must have missed it.
[0]: https://www.wilderssecurity.com/threads/ublock-vs-umatrix.37...
I hope this isn't due to browser vendors making things difficult, but it wouldn't surprise me. Since the concerns are similar, it would be great if there was a way to marry the two. uBlock - advanced interface mode or something. Just a thought, not a feature request.
Thank you Gorhill for all your work. Sad to see it go, I actually can't fathom how I'll surf the web without it.
This describes uMatrix perfectly. I didn't understand a single thing after installing it, but one day, I spent 20 mins reading the wiki on Github and then understood what to use each tool for.
https://github.com/gorhill/uBlock/wiki/Blocking-mode:-medium...
https://github.com/gorhill/uBlock/wiki/Blocking-mode:-hard-m...
This was on all my browsers, with ublock origin, the first extension I install. Now what?
I'm not a good enough programmer to take this on but I suggest 'uMatrix Reloaded' as the new name.
Only the repo has been archived. The extension is perfect. Just think you haven't seen this post and continue to use it.
>they're also still in the process of developing the API
The API is there. They are just whitelisting addons.
You can't use it currently if you have a release version of Firefox after 68, yes. The API is buggy and in fact quite a few extensions don't work, even if you force-install them. It's still unclear if they will ever whitelist stuff that's outside of their "recommended extensions" program, and presumably the best chance it would have of getting whitelisted is if it were actively maintained and bugs encountered with the new FFA could be worked on in coordination with the developer.
After some time, it looks to me as if no real change has happened. The webextension model is still too weak in several areas to allow for some old extensions to function properly (keyboard handling is a major, major PITA), and at the same time a lot of work is still being spent to support cross-browser (and to a lesser extent, cross-version) functionality.
Forward-compatibility on the same browser seems to be the only good point, until you realize it's also how chrome can pull the plug on request filters and kill extensions on a whim anyway.
I didn't even know you needed mozilla's blessing for extensions on android. Not so different than Chrome here, Mozilla. Not at all. First, the useless signing requirement, then this? :(
[1] https://nullsweep.com/why-is-this-website-port-scanning-me/
<link rel="stylesheet" href="http://127.0.0.1:42">
followed by an <img src="http://example.org/?port=42">
The <img> won't be requested until the stylesheet has failed to load, which takes a different amount of time depending on whether there was something listening on that port, or not.uMatrix won't allow the request to the local machine to go through.
Yeah! I switched to ηMatrix year ago without any issues ;)
Pale Moon + µBlock Origin + ηMatrix = <3
For more safe browsing just use Links2.[0]
Links2 is my default browser for the first time visit unknown sites & Pale Moon is my second browser for browse the Web.
Has Firefox too, but I'm using it only for few specific sites.
[0] https://github.com/gorhill/uBlock/wiki/Blocking-mode:-hard-m...
https://github.com/gorhill/uBlock/wiki/Why-don't-you-accept-...
On another note, how does uMatrix even work internally? I guess the bulk of its functionality is based on the webRequest API and I think it uses some kind of CSP hack for inline scripts and workers? (And is it only my perception or does uMatrix have to resort to a lot of hacky workarounds to implement some of its features?)
TL;DR: gorhill didn’t have time to maintain both extensions, and won’t transfer the repo after having been burnt once already.
If the author, Raymond Hill, ends up reading this: thank you Sir, for all the (probably unpaid!) effort you have been putting into this extension for years. It's certainly an inspiration to actively contribute to the open source community.
I don't have the time to do it justice, and I expect others will do a better job of running a project, but it's something I can't work without. Fingers crossed it's just version bumps when new FF versions come out.
I hope this addon keeps working without patches for a long time, I absolutely love how it has improved my web experience. So easy to use.
The fine grain controls on uMatrix are so powerful and quite intuitive, especially once you get oriented. You can see (and block) websites trying to load in crap asynchronously, see the problematic iFrame that's loading in a scripts, see all the trackers and even the cloudflare endpoints that may be responsible for bringing in malicious content.
Gorhill's uBo project is nice, but geared towards simplicity and it's too simple, even with the advanced interface, imo.
Although Gorhill never accepted donations, someone forking uMatrix will hopefully use something like github.com/sponsors to ensure it's sustainable.
I'd love to see uMatrix around for the long haul.
It is said that 20% of the ads on the web are malicious so browsing the web without a dependable script/adblocker is just asking for trouble.
And until the adtech industry finds a way to stop malvertising I will continue blocking scripts and ads.
Separate question, is there somewhere can we can read from the author about this decision to archive uMatrix?
Can someone link to a tutorial or a detailed review for it?
There are numerous explainer videos on YouTube:
Incredible tool, sad to see it go.
I hope whoever forks the project can work on the UI and onboarding experience.