Google Removed ClearURLs Extension from Chrome Web Store
github.com
github.com
The only filter list provider is the extension maintainer, so this information should be safe to share. I have not had the time to set up a PoC, but I'm confident that the filter rules are way too powerful.
At the very minimum, the current filter list should be included in the extension package rather than periodically updated from a remote URL. That way the filter list can be audited and must pass a review, without having a negative impact on the effectiveness of the extension, since the filter list does not appear to frequently change.
https://github.com/ClearURLs/Addon/wiki/Rules
https://gitlab.com/anti-tracking/ClearURLs/rules
https://kevinroebert.gitlab.io/ClearUrls/data/data.minify.js...
It has the idea that you can audit a website and only list the allowed parameters there, so that a website search or sorting order or filters can still work.
I built my browser on an allowlist based concept because it seemed too impossible to maintain all bad urls, domains, parameters on the web. Most websites have more tracking than content in them, so I decided on maintaining lists to select the content rather than the ads and trackers.
[1] https://github.com/tholian-network/stealth/blob/X0/profile/p...
Any vulnerability-prone system, will either fade away or end up with a centralized arbiter quite inevitably.
Not that Google are great at their jobs in that case, but it's something.
So it's not paranoia in this case, it's "we can't have nice things" because of real bad actors.
We do need to decentralize the decision making but the progress toward making the web safer for average folks is good.
Stop the helicopter computing. People keep saying they want the old Internet back, this is why.
Suppose our single maintainer decided to finally sell the extension, and the person who bought it made it so that all those links hijacked information or exposed you to malware. This would happen in one day without warning. How many people would be saying that was Google's fault for allowing this to happen?
You say people should determine for themselves based on risk, but most users of Chrome extensions are naive when it comes to understanding risk.
They wouldn't be making it about the description being too detailed.
While this may be bad, I think it is merely incidental.
You can probably do this in under 30 seconds, but it's enough of a barrier to keep naive users from doing it.
If Google wants to act like a platform, it should have some form of escalation with the developer to fix issues instead of complete removal without warning.
Of the defaults, I only override "cid, mbid" as blocking those on every site has ended up breaking some.
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32...
These make various requirements around how Google act, and include requirements around removing products from platforms.
As an aside, it seems crazy that we allow platforms to take action when in positions of such clear conflict of interest, but that seems to be the way of the tech sector.
This "just" sounds like the typical story we hear so often of an overzealous "app" reviewer waking up on the wrong side of the bed and just decided to delete someone's product and/or business (which is a huge problem itself!)
The primary reason Google has Chrome and Android is to maintain ecosystem control and to continue tracking users to support it's Ad business (or reduce the threat that other browsers will diminish it's business in these areas).
;;; The @b{urlskip} Racket library provides a function that translates some of
;;; the Web URLs that might be used to track a user across sites, by removing
;;; intermediate HTTP redirectors or information that might identify the user.
;;; Such a function might be used as part of a privacy-enhancing Web browser,
;;; or to canonicalize or un-obfuscate URLs for Web analysis projects.
;;;
;;; Note that @b{urlskip} is not intended to remove information used by
;;; ``affiliate'' referral programs to identify site operators that have sent
;;; users to a site. However, in some cases this affiliate ID information
;;; might be lost in the process of removing a intermediary URL that is used by
;;; a third party to track and profile users.
It had special-case handlers for various URL server authorities and the paths under them. So, for http://www.amazon.com/exec/obidos/redirect?tag=AAA&creative=111&camp=222\
&link_code=bn1&path=asin/b333
it was coded to preserve only certain query parameters, like: http://www.amazon.com/exec/obidos/redirect?tag=AAA&path=asin/b333
A lot of the cases it handled were redirectors, which usually meant only the target URL, which was usually in a query parameter, but might be in the path, and might or might not be URL-escaped. So, for example, http://www.google.com/url?sa=l&q=http://www.shopping.com/xGS-AAA_BBB~NS\
-1~linkin_id-111&ai=REALLYLONGNONSENSESTRING&num=3
would skip the redirector, to be simply: http://www.shopping.com/xGS-AAA_BBB~NS-1~linkin_id-111
I was going to link here to the code of `urlskip`, but it's no longer in the package repository where it used to be. (I added a lot of libraries to that repository, and don't recall whether there was some reason to remove this particular library.) It was a pretty niche library, and in a fringe language, so its impact might've only been as an example, pointing out that this could be done, and some rules for it.This move does well to reinforce my loyalty to Firefox as my main browser. Hopefully it has the same effect on others.
Thanks Barbara Streisand effect!
I think the final nail in the coffin for Chrome for me was the decision to hobble uBlock Origin several year back.
Firefox is far from perfect, but at least it's not completely owned by Google.
Case in point: Firefox on mobile has a selected _whitelist_ of addons you can install, and that's it.
Many addons work already, but they're locked behind mozilla's vetting. Not only you need to jump through additional hoops, but you actually require an account on Mozilla's website as well.
This is like saying that Chrome is fine too, just use Chromium, get the addon from a github release and there you go!
Once those are implemented, which is expected soon (only in october did they implement the majority of the APIs so far) all addons should work, and it'll be open again.
The big issue with just opening it now is that it'd lead to dozens of complaints due to broken addons, so I can easily understand limiting it to people with enough understanding to go through these steps.
Besides, the chromium workaround used to be the official installation instructions for AdNauseam for Chrome, until Google markef it as malware. And Chromium doesn't even support addons at all on mobile devices
However, you can use Firefox Nightly and install any extension you want.
There's a billion dollar niche waiting for the right company:
- make a search engine that works
- show text ads clearly distinguishable from results
- play nice, and maybe even use use a cool slogan like "we're not evil" or something (it used to be someone else's but it seems they don't use it anymore ;-)
I wonder how the next disruptive innovation is going to look in the search engine market?
I think the search engine market will always be very closely linked to content distribution platforms. If the decentralised web continues to degenerate into an oligopoly of walled gardens then there will be no search engine market in the current sense. We will just use the search function provided by each platform.
I believe the question we have to ask is what the next disruptive content distribution platform is going to look like and whether that disruption can be anything more than yet another oligopolist stealing some share from the encumbents before getting bought by one of them (or not).
But IMO it is a far cry from 2007 Google and only holds a candle because Google has nerfed itself.
And sadly, much of it isn't because they don't have resources for AI or even larger index but because of the same QA issues that Google has struggled with:
- including results that doesn't contain my search terms / too much fuzzing
- ignoring double quotes
Both probably in order to please the mythical ordinary/average user I guess.
Guess what: techies got me to change to startup Google and I guess we will get people to change to another search engine as soon as one is ready.
In the meantime I use DDG. The difference is mostly negligible now and when it isn't it is 20 times faster (I don't think this is hyperbole) to mash in a !g at the end of my DDG search than the other way around.
FTR: same goes for browsers. For me Firefox has always been best, but they have nerfed themselves and keep ignoring us techies to such a degree that I will - if necessary - pay monthly to get a safe, supported version of the same with my old extensions working, but not to Mozilla Foundation, only to the Corporation (the ones who create the browser) or someone else.
- Our search engine works and has been doing so for >15 years. Our search quality needs improving but does so gradually. And it's independent; our own crawler, index and infrastructure
- We just introduced non-tracking search ads: https://www.mojeek.com/support/ads/
- We use "No Tracking , Just Search" and "Search without Surveillance"
We've been building for 15 years; here's our founder story: https://news.ycombinator.com/item?id=26502140
- simple and clean
- gives me exact results, i.e. empty set when I search for something deliberately misspelled or non-existent
That said it seems to struggle with hyphens, see the two last queries below.
Here are my test queries:
- https://www.mojeek.com/search?q=byggrybsgr%C3%B8t (misspelled, sent it anyway). Result: empty set, which is correct
- https://www.mojeek.com/search?q=byggrynsgr%C3%B8t (local porridge) Result: plenty of relevant looking results
- https://www.mojeek.com/search?q=elefantfelle (Norwegian for elephant trap) Result: empty set. (But DDG can find some pages.)
- https://www.mojeek.com/search?q=Honningsv%C3%A5g+ (town in Northern Norway). Result: interesting, but relevant. Nice card at the top with relevant information from Wikipedia
- https://www.mojeek.com/search?q=react+hooks Result: relevant results, two in a language that I rarely read (German) or cannot read (French?)
- https://www.mojeek.com/search?q=%22mat-table%22 Result: not a single relevant result on the front page (!)
- https://www.mojeek.com/search?q=mat-table Result: not a single relevant result on the front page
On Google, it's the first result. https://www.google.com/search?q=github+ruby+hanami
On mojeek, it's not even on the first page. https://www.mojeek.com/search?q=github+ruby+hanami
It's possible that at this point I (and others) have trained ourselves to know/do the kind of queries that work on Google, without even realizing it, which would be another thing making it hard to switch. Although in this case... I'm actually a bit surprised mojeek doesn't manage it. Just `github hanami` doesn't get it either. Is it just not matching on sitename at all?
In this case we simply don't have the page in our index, though we do have others mentioning hanami. Our bot is permitted to crawl github.com and has a good number of pages in from that host, we'll evaluate whether we can increase crawling for github and similar large sites and hopefully before long that page will enter the index.
As a developer one of the main things I'm searching for is code.
Unfortunately (for competitors) I can pretty much count on Google having everything I ever want in the index.
Not having the thing I'm looking for in the index is another wrinkle on top of relevancy.
Queries related to Go seem to mainly work only if using Go and not if using Golang (unless "go" + term is popular outside of Go as well). Usually people use Golang in search (to avoid confusion with the verb & game), but pages generally refer to Go. "go package XXXX" seems to work better in many cases.
With a bit of lesser known technologies, it was hard to find a query that would get me to the actual site. e.g. Python SDK for OCI. Lots of links to examples with various queries (python oci, python oci sdk, python oci api), but not really any direct link to GitHub or the official documentation.
I think there's two ideas that come up from your feedback, one is index size. Our index is small but growing. A larger index increases the chance of having pages that satisfy your query.
The other aspect is boolean search versus something more akin to the vector space model. We've found a lot of people that are dissatisfied with Bing/Google searches tend to be unhappy that the search they actually enter is somehow modified to include what the search engine believes are relevant synonyms. In some cases, those synonyms may help in producing a better result when use of language is split between two terms used interchangeably, like go and golang. It's something we're looking into. We do value searches being based on what is actually searched for but also accept there are cases where assuming synonyms may be advantageous to the end results.
Great job so far, by the way, keep up the good work!
"Nothing to see here, you can't take photos of my mansion".
I tried last year, and honestly it isn't bad. But I use the Chrome "install this site as an App" functionality a lot and Firefox's "app tabs" didn't work nearly as well. Plus, I hear they've removed or are removing said single site browser functionality.
This might be a somewhat niche case but it makes it really hard to switch as much as FF does have some nice features (picture in picture for all video content is very nice).
It's called Add to Home Screen
>Recommended extensions are editorially curated extensions that meet the highest standards of security, functionality, and user experience. Firefox staff, along with community participation, selects each extension and manually reviews them for security and policy compliance before they receive Recommended status. These extensions may also qualify for promotions on the AMO homepage and other prominent locations. Developers cannot pay to have their extensions included in this program.
So, after explaining and linking to the source code, they usually reply with another canned response:
Thank you for reaching out to us. We took a closer look at your item again and found it to be compliant with our policies. Your item has been reinstated and will be available in the store shortly. We apologise for the inconvenience caused to you in this matter. We value your contributions to the Chrome Web Store and look forward to working with you.
So maybe there is some Hanlon's razor at play here, too.- A bad or gone-bad automated system;
- Outsourced incompetent people;
- A try to soft push out what they don't like (it still takes patience and effort to deal with this);
- Some mix in between.
For sure, malice or not, it's flawed.
> Among other things, it was claimed that the description of the addon is too detailed and thus violates the Chrome Web Store rules. The mention of all the people who helped to develop and translate ClearURLs is against Google's rules because it could "confuse" the user. Ridiculous.
> Also, Google has criticized that the description of the addon did not mention that there is a badged, an export/import function for the settings, a logging function for debugging, and a donation button. This would be "misleading".
> Last but not least, it was criticized that the "clipboardWrite" permission would not be necessary. But that's not true, and I've had a description for each permission in the Chrome Web Store Developer Dashboard for well over a year now. So the "clipboardWrite" permission is needed for writing clean links via the context menu into the clipboard.
Google should not be allowed to develop Chrome or have any say in web standards. Every play they make favors themselves - unsemantic HTML5, AMP, crippled and removed extensions, progressive removal of the URL bar, https everywhere (no more self-hosted blogs unless you understand cert signing and automated renewal - why did the web stop being easy?), cookie standards that favor their moat, "acceptable ads" policies, ReCAPCHA, etc. etc.
Here's a laundry list of things they did to YouTube to hamper other, non-Chrome browsers: https://arstechnica.com/gadgets/2018/12/the-web-now-belongs-...
Handing web standards over to an advertising company has been of the most damaging things ever done to the internet.
By threatening their self esteem, their very identity, by validating what the know deep inside them, that they work to do evil, without wanting to, they must strongly reject/defy such claims to reassert and restore their veiled view of themselves.
Having typed that, I sure hope there are people at Mozilla who would help ensure that Mozilla does no evil :(
Hopefully they don't go under :(
Albeit a neat skin they put on it, I'll admit.
If Google decides to make some fundamental changes to their core engine that would make, say, ad blocking a lot more difficult, would the other chromium-based browsers deep-fork the entire codebase to keep ad blockers working while at the same time integrating the new features as fast as possible in order to remain competitive with Chrome?
Microsoft has the resources to do it, but they may not care. Brave and Vivaldi would almost certainly care, but they may not have the resources to do it.
I could spend all day criticizing Mozilla but I'll use Firefox to the bitter end because of this. In the end there are only three engines in widespread use these days: Chrom(e|ium), WebKit/Safari and Gecko. As far as I know Safari is irrelevant outside of Mac world, so losing Gecko would be terrible for the open web.
I switched from Firefox to Brave in October and suggest others do the same. Personally, I believe Brave would indeed "deep-fork" the Chromium codebase if necessary, and I'd guess there's a significant chance that other Chromium-based browsers would use it in preference to a submarined upstream.
Let's Encrypt's with its certbot made it easy enough to get a cert and every major webserver supports HTTPS out of the box with good documentation.
I use dehydrated instead.
Is that even remotely true?
There are alternatives to Lets Encrypt - AWS has an equivalent project where they issue free SSL certs for AWS resources.
It is possible to host LetsEncrypt alternatives, though. The viability is another matter, though.
Just checked.
My hosting provider asks 2x more money for SSL addon (which includes unique IP, unlimited subdomains, and free certificate). They wrote on the support forum I need that addon regardless on which certificate I gonna use, the included free one, or any other like lets encrypt.
Not gonna switch hosting nor pay 2x more for it just to please Google.
Let's not pretend that HTTPS only exists to please Google. It has very real benefits for your users.
Furthermore, congrats on your site but you’re 0.01% of sites like that. Should we keep an insecure web because your hosting provider is ripping you off? TLS is easy and free in 2021.
It’s been possible for decades and doesn’t end up being a common problem. And even if it was the risk is just crap injected into someone’s blog.
https://news.ycombinator.com/item?id=3804608
This is far more common than you think. ISPs, hotels, cafes, mobile providers do this en masse far more than you think. Have you forgotten the NSA “SSL added and removed here”? That was a highly targeted attack against infrastructure. What we’re discussing here is 10x easier to achieve.
> And even if it was the risk is just crap injected into someone’s blog.
That “crap injected” has full control over the DOM, any authentication, and everything displayed. How many of your users would happily put their creds into a fake login modal that popped up claiming to be SSO for a popular identity provider?
It's up to web site owners to decide whether to implement encryption, and up to users to decide whether to use these web sites or not.
Users can decide: find a browser which doesn’t put importance on cert usage. You’ll find this hard to find because every browser manufacturer realizes that 99.9% of users cannot make sound security decisions, so they shouldn’t have to. Things should default to secure.
There’s a trade off between protecting users and having a 100% free and open internet. An insecure internet is untrustworthy and therefore not useful, IMO.
Thanks to the rise of the almighty platforms we've lost the will and know-how to do it ourselves.
> TLS is easy and free in 2021.
Only if you're relying on complicated cloud infra or (non-free) managed providers that do everything for you. It's a lot of work to set this up on your own.
It's impossible to be simple at this point. It's like the automotive industry which collectively decided to use computers for everything. You can't repair things yourself now. It's ironic, too, because now the industry finds itself with a chip shortage. I can imagine lots of scenarios where our complicated infrastructure requirements bite us.
There should always be the option of not using TLS. It should be first-class and not require expertise to access or use.
MDCertificateAgreement accepted
MDomain example.org
<VirtualHost *:443>
ServerName example.org
ServerAdmin admin@example.org
ServerAlias www.example.org # optional
DocumentRoot htdocs/root
SSLEngine on
</VirtualHost>
If you're using Nginx rather than Apache I believe it still requires an external script to handle certificate renewal, but the process remains fairly simple. The same scripts will also work with Apache if you don't want to use mod_md.There is no technical reason for asking 2x more money for encryption in 2021.
Here's a good lecture about why HTTPS everywhere isn't as important as people think. http://n-gate.com/software/2017/07/12/0/
https://www.troyhunt.com/heres-why-your-static-website-needs...
We've seen everything from injecting tracking javascript, to injecting their own ads, to outright replacing content with unrelated content that the ISP wants to push.
So either Google must be trying to block a plugin for evil business reasons or Google is trying to improve the Chrome Web Store, making it less confusing for users and easier to search.
Improving the description will probably make more people install it, not less.
> Also, Google has criticized that the description of the addon did not mention <list of things> ...
So it was simultaneously too detailed, but needed more details.
Now if we could just get app stores to mandate useful changelogs… No, Google, "Bug fixes and performance improvements" doesn't cut it. Describe the bugs that were fixed and where and by how much the performance was improved. Justify spending the effort and risk of updating the software to the new version. There is no point in a changelog message that could be applied equally well to every release of every software product ever made.
This one does make me laugh more than the rest, coming from Google that names their apps in the Play store as follows: "Android Auto - Google Maps, Media & Messaging" "Files by Google: Clean up space on your phone" "Google Chrome: Fast & Secure" "Google Duo - High quality video calls" "Phone by Google - Caller ID and spam protection"
If this is a policy, perhaps they'll delist their own apps from the store?
Hopefully, removing this permission could help getting the extension restored.
https://github.com/ClearURLs/Addon/blob/master/external_js/c...
document.execCommand("copy");
I personally do not know, just going by what's stated within the URL in the adjoining comment (https://github.com/mdn/webextensions-examples/tree/master/co...).Clipboard APIs are in general pretty permissive in writing, any websites can write anything to the clipboard without requesting any permission, if it's done within like 1000ms or so from user interaction. So you don't even need an extension to write to clipboard.
> The requested URL was not found on this server. That’s all we know.
I suspect suspending an extension could be done with slightly more tact, if that was a goal.
It does happen to break some addons, e.g. Greasemonkey, but most work just fine.
Firefox's Sync appears to be just as secure if not more secure (there's no option to NOT have end to end encryption): https://hacks.mozilla.org/2018/11/firefox-sync-privacy/
I think sync is a pretty niche feature anyway.
(It should also be noted that this latter bit is not something new to Google, either. I remember how Opera complained about them doing exactly that with GMail back in... 2009, I think?)
All those browser engine speed ups are intetesting but I prefer the mobile web experience customizable as it was a few years back.
Btw if anyone here forks FF and enables customization also plz add bookmarklets! Would pay for that...
https://blog.mozilla.org/addons/2020/09/29/expanded-extensio...
Firefox Nightly for Android: https://play.google.com/store/apps/details?id=org.mozilla.fe...
Fennec F-Droid: https://f-droid.org/en/packages/org.mozilla.fennec_fdroid/
ClearURLs works with no issues.
Not all WebExtension APIs are supported in the Android version of Firefox at this time, but the developers are working on the missing features.
While it doesn’t solve the issue of add-ons, it has enough of a privacy focus to make me feel better about reducing my footprint on the mobile.
It’s a pity that development is not as active as it used to be, but looks like Firefox are still supporting the project: https://github.com/mozilla-mobile/focus-ios
Come on EU, step up. Google doesn't need protection here, they'll survive even if they cannot retain control over the development of Chrome, and in particular the authority over the extension store.
Edit: It seems that not even Silicon Valley likes the monsters it has created.
Money is actually a power (via buying other people's time and effort to spend on one's problems). The money is also behaves like the mass in Universe: it sticks together in large clots. So the power does too.
And in US, it was back in the day - but then, thanks to Reagan and Robert Bork, we effectively threw away all the anti-trust legislation that was functioning quite effectively for 80 years. The large businesses, of course, heavily lobbied in favor of that.
So, they have created the present environment - and now that we have seen (yet again) why anti-trust enforcement has to be proactive, they're complaining that it would be unfair to revert to old rules?
I don't know why people open restaurants - do they know the profit margins? They must, and they do it anyway.
So it must be for the love of it.
This idea that starting a business just to make money is a good idea, is tenuous at best. It's a sign of the times that people even ask the question of 'well, if I don't get rich, why would I do it at all?' It's a sign of how dysfunctional work has universally become, that people view it as suffering, to reach a promised land, rather than a calling to do your part as part of a larger community.
If it's suffering, maybe something is wrong. Taking away the idea of heaven enables you to say no to resistance you're experiencing now. That's a good thing - don't believe anyone promising you a heaven later on - how would they know and if they're in it, is mentoring you to suffer really a part of their heavenly experience?
Are you suggest we should instead cater to megalomaniacs that wish to run maximally large companies and rule industries?
Broadly speaking, the big regulations tend to create conditions where disruption is harder. Regulatory compliance is often a substantial investment, and a rather big one, thus a barrier to entry; it's a lot easier for big, profitable Google to hire a team of regulatory compliance officers and GDPR architects and the like than it is for a small startup.
However, the reason for those requirements isn't, ostensibly, to make disruption difficult - it's to protect the society from problems that can be caused by companies of all sizes equally easily. For example, safety regulations about medical equipment. Or data protection regulations. To the extent these laws make disruption difficult, it's often unfortunate cost of safety.
(I understand though that the real world isn't perfect and big players tend to influence these laws to their benefit. But perfect being the enemy of good, and all that.)
Perhaps not. But public choice theory is chock full of unintended consequences.
While in this case, Google is very likely abusing its dominance to coerce the whole ecosystem beyond their own platform in their favor: if the web becomes “works with Chrome” everyone is (probably negatively) affected.
1 : ten thousand
2 : a great number
The Apple/Google duopoly does not constitute a "myriad of competitors".
Epic says this is not a real factor for consumers, despite it still harming them.
Not only did Apple invent the modern smartphone, they created the first modern App Store. This, combined with their high cultural cachet, allows them to define by their actions what an App Store "should be" in many people's minds.
Personally, as a lifelong Apple user, I'm both concerned about Apple's singular control over the iPhone app market, and concerned what would happen if that singular control were broken.
DNS over HTTPS is another example of Chrome trying to workaround means of blocking tracking.
Now if they start to force it where you have to use their browser to access their content it may be an issue depending on how much competition is in that space.
Or worse, they use their influence on standards committees to effectively lock out other browsers. That would be worth taking them to town over.
Google is no more the internet than any other company. You never have to use google or their products for anything but many do because its just there and it just works
For the same reason you are allowed to make this comment or I am allowed to reply. There is no explicit law prohibiting them from providing a free browser while also being dominant in the content space.
Also - Google is the natural result of the Silicon Valley business model. You got what you wanted!
Google acts as their own police, judge, jury, executioner, and bank.
Ditto Apple, Facebook, Twitter, etc, etc.
The pro-capitalist position is to protect markets. We need tort, fair and impartial adjudication, and right to appeal.
a) don't know the extent of Google's digital invasiveness
b) know but don't care
c) care but either not enough to leave it or don't have a choice really
I don't know anyone from these groups that are aware of ClearURLs or what is solves - they probably would have never installed it.
On the other hand, tech folks who know and care about what Google is doing, are perfectly capable of installing Firefox/Opera etc and get around it. Removing this extension doesn't do anything to affect these people.
What does such dick moves actually achieve? Its just makes most people either be indifferent or hate them more.
It doesn't remove all trackers from the URLs yet, but at least you can copy what is displayed at the status bar when you hover over the link. It's useful since a lot of tracking sites (like FB) substitute that status bar link for the tracking one before clicking.
I think I'll add some cleaning process in the future.
Google could write and publish the rules, and then get a third party to decide if each app/comment/video meets the rules or not.
There could even be the option to appeal to a real court if you disagree with the third party.
Google still gets effective veto since they could change the rules anytime, but it would still be a big step up over what we currently have.
See how to install manually here - https://github.com/ClearURLs/Addon/issues/102#issuecomment-8... and I don't mind manually checking for updates from time to time.
Studies have shown that people just don't change defaults, as a rule. Only a small minority of people change them.
Interesting. I haven't had much trouble with Firefox yet, even with uBlock Origin. Any idea what kind of sites?
> Webcompat.com is developed by volunteers and supported by Mozilla.
No difference with real sites. A developer may notice some difference in latest features support (not always in favor of Chrome).
> Faster for some things.
If your PC is new and fast. Otherwise it's much faster for most of the things.
I use Firefox (desktop and mobile/Android). You sound like a Firefox evangelist. There are real site where Firefox is buggy or slow. Youtube is one of them. I know it's not technically their fault, but the average user can't fix the site. They can (and do) change their browser. So they use Chrome.
So do I.
> and mobile/Android).
I found it unbearably slow on my Galaxy Note 3 with uBlock. The only reason I tried it was uBlock. So I rarely do. I've switched to Brave.
> You sound like a Firefox evangelist
Kind of, but an honest (if not say cruel) one - I always say Firefox is slow. I also use Chrome on slower machines.
> There are real site where Firefox is buggy or slow. Youtube is one of them
I don't know a single site where Firefox would be buggy but it indeed is slow - on all of them. On YouTube in particular yet still pretty much usable. On a modern PC the difference is easy to ignore. I watch a lot of YouTube in Firefox Every day and I enjoy the "picture in picture" mode. I have hardware decoding enabled and high-FPS and high-res (above 720p) modes disabled as I don't appreciate them.
But yes, browser profiles and computer multi account support are tools that would solve this problem if they worked for the particular problem description - which fair to say they weren't really designed for that scenario so no reason to expect they would work.
Just an option to keep in mind in case you decide to get rid of Chrome in the future.
It's really a parenting issue, I could stop her doing it but I don't care enough to do so, and if I don't stop her via parenting there will always be ways she slips through the profile guards.
On that note, here's a regular reminder that Slack still doesn't support calls on Firefox for over 3 years now: https://twitter.com/slackhq/status/958645632620748800
I was first a Firefox user, switched to Chrome, back to FF and finally to Chrome once I got a smart phone and they added sync
I don't think it has history sharing, that sounds useful.
Firefox syncing can also be self-hosted if you're into that..
Chrome's just works, every time.
Oddly, it sorta worked for me in FF the other day, but it took me to the minified source, which wasn't terribly helpful in an app that I'm writing.
I still use Firefox 99% of the time, but it really pains me that that one feature is so broken.
I left Chrome for Firefox about 2 years ago because Chrome was becoming slow (I was more likely the reason) but Firefox was always “just okay” in many regards. No automatic omnibox search that I enjoyed since probably 2010 in Chrome, for example. That feature alone makes navigation a breeze.
Then last summer probably I switched to Safari. Nice browser, but very barebones if not for the beautiful Reader view, reading list and iOS Keychain integration. Generally smooth but extremely sluggish on the new Facebook site.
I don’t use Chrome because my dislike for Google grows by the day, but I recognize that Chrome is still the best at what it does, and that’s why many still use it.
If Edge supported the keychain I’d probably consider it.
The browser itself is fine, it’s the company that isn’t — and that’s why I don’t use it myself.
I recently moved back to a Chromium based browser (Edge). Even on a fairly powerful system (16 logi cores/4GHz) it's just noticeably faster. SPAs are actually usable again. Video decoding is hardware accelerated and I can now play 4k videos without every interaction with the browser lagging like crazy.
Firefox is great, theoretically. But even then, Mozilla keep making inane decisions - lately their plans to remove compact mode [0] were in the news. Why?!
[0] https://www.ghacks.net/2021/03/14/mozilla-plans-to-remove-th...
general.smoothScroll: false
mousewheel.default.delta_multiplier_y: 300It's not the most central thing a browser has to do, but every user does it so often and it's a constant annoyance when it doesn't work the way you like/expect it to.
general.smoothScroll: false
mousewheel.min_line_scroll_amount: 60
I'd never given mousewheel.default.delta_multiplier_y a try. But now with both mousewheel.min_line_scroll_amount: 60
and your mousewheel.default.delta_multiplier_y: 300
it's a little too much for me. But ymmv.mousewheel.default.delta_multiplier_y and mousewheel.min_line_scroll_amount seem identical in function.
One thing I hate about most websites is the backward compatibility issues most websites tend to have from time to time that break pre existing functionalities. Almost all websites have them. EG copy pasting photos through clipboard doesn't work anymore on gmail using firefox which forces me to use chrome.
But if you don't trust Google Chrome, how can you trust Google Android?
On Android he has a free choice to use and support Firefox (with Addons), which on iOS he can't do by the decree of the platform holder.
(The platform holder which told us, developers, that writing the complaint that's linked in this very article would cause us to be removed from the AppStore.)
You can uninstall any app by using adb shell:
1. sudo apt-get-install android-tools-adb
2. Connect phone using usb, choose file transfer
3. In terminal type: adb shell
4. On phone allow dialog that appeared
5. In terminal in adb shell type: pm list package
6. Find which app is it and uninstall it, eg: pm uninstall -k --user 0 com.facebook.services1. Install firefox
2. Settings->Apps, set firefox to be the default browser.
3. In the app setting for Chrome, disable and stop the app.
4. Remove the Google search/assistant widget on your homescreen/desktop and use the Firefox search widget instead.
Not much can be done about the Chrome-based system webview, as far as I know.
I don't know about how it is in the latest phones. But at least for older phones apps which are bundled as part of the OS have a version of the program in the read-only system partition which is used to do factory resets.
So disabling deletes the latest version of the software, and stops it from running on the phone.
- don't use Chrome
- don't use Google Search
Problem was everyone had IE, websites were written for IE, activex, vbscript, etc
If it worked in Netscape fine, but large numbers didn’t.
On top of that, Netscape was a right resource hog.
Even tried Bing, lol
I’m glad ddg exists, and it’s nice to see them improving over time.
- use DDG
- if I can't find it, attach !g to my query and be instantly on Google
- either confirm Google can't find it either
- or found it
this way DDG get important data to improve their technology, I avoid being tracked most of the time and I get the same results for the cost of a few seconds here and there.
Yes, DDG isn't exactly amazing for anyone who used Google before 2009, but neither is the "Google" lookalike we see today ;-)
Even ignoring privacy and data collection, I find personalized search problematic. Unreliable across computers / VMs, broken across browsers / OS reinstalls, and most importantly not portable across users, you can't tell other people how exactly you found stuff.
Prevent short link services from tracking you. Unshort.link i s an open source webservice removing tracking parameters from short links and displaying where they point at.
It has the option “Block all hyperlink auditing attempts” enabled by default.
uBlock is NOT an alternative to this specific case.
That being said, I'm a very happy uMatrix user on Firefox.
1: https://github.com/uBlockOrigin/uMatrix-issues/issues/291#is...
How exactly does the tracking via URLs work for Google?
Before:
http www.phoronix.com/scan.php?page=news_item&px=Ioquake3-Auto-Updater&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Phoronix+(Phoronix)
After:
http www.phoronix.com/scan.php?page=news_item&px=Ioquake3-Auto-Updater
It removed unnecessary, known tracking code from URL before visiting the URL so origin of click isn't known to advertisers and trackers.
So, they're not always useless ;)
https://addons.mozilla.org/en-US/firefox/addon/bypass-paywal...
https://gitlab.com/magnolia1234/bypass-paywalls-firefox-clea...
https://gitlab.com/magnolia1234/bypass-paywalls-firefox-clea...
Bypass Paywalls Clean releases: https://gitlab.com/magnolia1234/bypass-paywalls-firefox-clea...
Bypass Paywalls releases: https://github.com/iamadamdev/bypass-paywalls-chrome/release...
Currently, the Clean version has 13,750 users while the original version has 9,864 users on addons.mozilla.org, so the fork might turn out to be more popular.
I'm not too much into using extensions, but this is definitely a positive one.
I hope you get this reverted.
I'd like to see more small sites have a donation (not subscription, unless a decent micropayment solution shows up and they give up on the "it's just the price of a Starbucks coffee" crap) instead.
But from the reader side, how many subscriptions can you have? It may feel good now because there are only a few options and any one person only likes a small percentage of those few options enough to give them money. But what happens when every site you click on on HN asks for a subscription? Will you pay for all of them?
Frankly, I see two googles: the people who make a lot of decent or great stuff, and the upper decision makers who act against the interests of the other group and the consumers.
Humans also handle disputes, and Google's staff that handle them are borderline incompetent and don't respect developers or end-users.
You can say "upper management sets the policies" but I think that's giving people with some degree of control a pass. A highly-compensated SWE definitely has the option to not just go with the flow.
Nevertheless i searched for it at fdroid, and nada.
Are you implying that we should just treat Google's decisions as inscrutable facts of nature that we must accept with resignation, and just be glad that the extension is still available somewhere?
In fact we, the advanced privacy-concerned users, are not interested in such extensions being on the store front and becoming too popular. Let Google use simple methods to track people who don't care about being tracked (many people who I tell about tracking really don't care, they say I'm a paranoid weirdo complicating things instead of just using them the way everybody does) enough to find a workaround.
When AdBlock was only used by a bunch of superusers nobody cared to counter it, everybody was happy.
Discoverability also isn't a thing such extensions should seek. As soon as too many people discover it Google and others will invent a smarter way to spy.
Flow 2: user wants extension, searches in Google, finds a third-party website, clicks download, downloads file, runs file, gets warning that the exension is untrusted, clicks install anyway. Repeat for every update.
Still don't think the average person wouldn't truat Flow 2 less? Or, to look at it from the other side: wouldn't the fact it was removed by Google make people suspicious of the addon? What was it doing that was so bad that even a garbage pile like the Chrome Store dropped it.