uBlock Origin works best on Firefox
github.com
github.com
Having said that I've also been fairly stunned recently to see how much difference a simple DNS blacklist system can make too. Not because it's a big technical achievement but because it isn't and in principle seems relatively trivial to work around. But as I've been switching all my routing from UniFi to OPNsense, I've gone ahead and tried out Unbound's basic built-in blacklisting. While it's no uBO, it works on every single device and browser including in apps and it seems like it really shouldn't, that more parties would just be proxying ads through their own infra and DNS. Been kind of an interesting illustration of technical vs economic influences in an ecosystem. I can see how proxying would add complexity and cost to setup so it must just be that few enough people do it the ad industry can't be bothered.
But should that ever catch on (and it could, Raspberry Pi seems fairly well known) I expect uBO to be able to keep up with the cat-and-mouse long after DNS has been left behind. This piece helps underline how incredibly important maintaining a critical level of diversity in the browser ecosystem is. Just shortly ago there were a bunch of complaints again about Apple not allowing Chrome to be on iOS because it "holds back the web", but what "holding back the web" looks like is certainly a matter of perspective...
Whereas the system for supplying software with IP addresses should continue to remain controllable by the user.^1 The online ad ecosystem has never had full control over that system.
1. If they so choose to exercise said control. As cited, probably most users are not currently exercising that control. This allows online ad tech to operate with relative ease, at relatively lower cost.
As much as anyone loves their ad blocker (to be clear, I think they are great), we really cannot dismiss the role of DNS in ad blocking. After all, it is DNS that is being used to bypass uBO on browsers other than Firefox. The only reason uBO can achieve a 70% success rate^2 blocking CNAME-cloaked ad/tracking on Firefox is because Firefox has a "DNS API". As such, uBO can check the results of DNS lookups for ad/tracking server hostnames/IPs.^3
Of course, a user who blocks ads/tracking outside the browser by controlling her own DNS lookups also has access to those results. No API needed. (Although I think it's a great project, I personally do not use Pi-Hole. I was using DIY DNS (without dnsmasq) long before Pi-Hole.)
One solution I can see to a future where ad blocking extensions are banned is a user-controlled proxy that performs similar operations, but outside the browser.
(I make most HTTP requests for recreational web use outside the browser, through a proxy I control. For recreational web use, I do not use a major browser to make HTTP requests to the proxy. The programs that I use have no financial dependence on online advertising/tracking/data collection like the major browsers and many mobile apps do.)
2. According to the paper cited on Github page that comprises the OP.
3. According to some uBO users sometimes the uBO-triggered lookups are undesired, e.g., when using proxies/VPNs.
I have a feeling that if Chrome (for instance) went that route it would quickly become Internet Explorer'd. If you recall, IE was the Chrome of its day for a good while until it slowly eroded away all its goodwill.
Today Chrome is a fairly good platform, tons of support for all sorts of html extensions, and a very strong commitment to security.
It’s a really nice product, except for the strings attached.
Alphabet should be broken up and Chrome (OS) spun off into its own business; the tracking should be made completely transparent and optional on a subscription base.
Also, you underestimate the effect of laziness. A company really has to do some atrocious thing to result in people leaving its services. Like, what would make the average person change from Gmail? He/she may not even know that 1) it is part of google which should be avoided now 2) what are alternative email providers 3) the whole change requires quite the technical know how.
It is simply naive to expect that “the market will solve it” to work in the general case. Competition only works when there are strict rules. Otherwise, the strongest/least fair player wins, and that’s why monopolies have to be broken up.
Referees, in comparison to governments, can be fired for doing a poor job.
Yeah and I will simultaneously work for google to not fk up the open web, for facebook to not disrupt democracy, and nestle to not goddamn force breastfeeding mothers on their shitty product.
How do you imagine a world without governments? The first thing they will do is put cocaine in their special food so you get addicted, add cheaper and more unhealthy components, even toxic ones, etc. Companies after a quite small size becomes the stereotypical paper clip AI, but instead of paperclips, it optimizes profit over everything else. A well functioning government with separation of power and without much corruption is good - it protects us from the cancerous outgrowth of companies.
You can't just leave a government the same way you can leave a job (and become unemployed) or a product (become a non-customer); you can only switch to another one. Why don't you try parking a vessel in the international waters and see how long it takes before it's sunk.
You advocated for the government to be broken up like a monopolist would be. I can’t really interpret that any differently.
> I was merely pointing out that there's a double standard.
Yes, it’s a double standard. Now, why do you imply that this is bad? Don’t you have to have special rules for the top level? Like, the root directory is its own parent directory, but nobody complains about “inconsistency” in file systems.
Your comparison is not apt. The root directory is merely a container for its subdirectories. In that way it much more resembles geography (a country being subdivided into regions, for example) than a government.
It's bad, because it's a blind spot. Governments, despite being at the top-level, have consistently grown since their inception. I'd expect the top level to be the leanest, not the fattest.
Decentralization and secessionism are highly unpopular ideas that don't look like they'll ever get mainstream acceptance. If anything, it looks like exactly the opposite trend is taking place (take the EU, for example).
Every day you read about new legislation being proposed and introduced. How often do you read about outdated legislation being abolished? Never. It's like writing an app and constantly adding new features but keeping all the existing ones. We all know how well that works out.
Even though HN shouldn't be about politics, when political rhetoric does get posted here (and it's far more common than one would expect), it's extremely one-sided.
The same is true in politics. Those who shout the loudest, win. A big wallet helps too. Ever heard of lobbying?
Jeff Bezos sure worked like crazy to get Amazon to where it is now, so he has every right to take it easy now that he's 'made it'.
While I can see some benefits to having a proportional vote that can be allocated to different issues, money isn't such a vote because it isn't equally distributed. Between this and your reply to kaba0, I have a very hard time believing that you are arguing this in good faith.
I never claimed everyone has the same hourly income. Nor should they. Some people work hard (on their career - not necessarily at their current job!), others take it easy. Both are valid options, but there will be consequences for the respective groups (both good and bad).
If you're against inherited wealth, I expect you to leave none to your own children. Respect if you actually go through with this.
> There's no such thing as passive income; there's only delayed income.
Wrong. If you have $500k in assets, that yields an average of $35k/year, market average over interest. You get paid money for already having money. This is not additional work. This is additional money as a result of having money.
> Some people work hard (on their career - not necessarily at their current job!), others take it easy. Both are valid options, but there will be consequences for the respective groups (both good and bad).
The difficulty of work is absolutely unrelated to the amount paid. Many low wage jobs, such as customer service, landscaping, or meat packing are absolutely ruinous on one's physical and mental health. They are high effort, and low pay. Other jobs are low effort and high income.
Edit: For comparison, Jeff Bezos is 57 years old, and has $192.5 billion. If he were working 24/7 throughout his entire life, that comes out to $107/second. That is 53,140 times the minimum wage. There is no humanly possible amount of effort that is 50 thousand times harder than a minimum wage job.
> If you're against inherited wealth, I expect you to leave none to your own children.
Complete non sequitur. Inherited wealth is an example of how money, time, and effort are absolutely uncorrelated.
Following up on that non sequitur, though, there must be limitations to inherited wealth such that society doesn't separate into a landed gentry. You are also ignoring the middle ground between being against a generational aristocracy and forbidding inherited wealth altogether, such as an estate tax. Even if somebody is morally against inherited wealth, it is not inconsistent to still give wealth to their children, such that they can use it to lobby against inherited wealth. It's the same reason why I donate money to groups pushing for economic and tax reform, rather than deliberately paying more than the current tax rate. I still spend what I consider to be my fair share supporting society that way, and it goes toward making sure that others do as well.
You get paid for already owning money... that you had to earn previously. There are many other examples of something similar. If you do a really good job on a particular month, you might still get the same wage at the end of the month. But you might get a bonus at the end of the year. Or you might be promoted next year when a position becomes available. However, you will not get a bonus and will not get promoted if you quit your job/get fired in the meanwhile. Do you also consider this unfair?
I never talked about the difficulty of doing a particular job, be it meat-packing or customer service; I meant the emotional difficulty of leaving a bad job and the mental difficulty of making the right choices and being excellent in what you do. Working not for others, but for yourself.
If there are indeed 'low-effort, high-income' jobs, why isn't everybody doing them? Why don't you personally those low-income workers that investing in the stock market (to give an example) is 'easy' and 'guaranteed' to yield high returns?
In fact, many manual jobs are already being replaced by robots/AI. Yet people are complaining about losing their jobs. If you took my high-effort, low-income job away, I'd be eternally grateful.
In the case of billionaires, they don't get to spend all their money, so the comparison between them and a minimum-wage earner is not apt. Jeff Bezos is surely holding lots of paper, but until he spends it, it has no value. Do you have proof his spending is out of line? Besides, when you're rich you overpay for everything, which means higher income (with arguably the same amount of effort) for those who provide goods and services to you.
And I've never heard of children using their inherited wealth to... lobby against inherited wealth. If anything, they'd be more in favor of it. But I see the point you're trying to make. You're not part of the 'aristocracy' (whatever you mean by that word), which you means you hold a grudge against them. Little do you know that people poorer than you hold a grudge against you too (you're considered relatively well off) and would use the first opportunity do redistribute your wealth amongst themselves.
While I entertained the idea of arguing with you, there is simply no point and I've come to the conclusion there are better uses for my time.
I'll just burn some points to point out how disagreeable I find your position.
Partly, the interface of Hacker News or any vote-based commenting system makes it hard to track comments overall. I can look up comment trees relative to my own posts, but that doesn't show me that the user "ilovepitchdecks" has been arguing along the same lines with multiple other people in sibling comments. Their viewpoint isn't in any way a community consensus, and is being soundly addressed by the community, but that wasn't readily visible just from one thread.
All in all, a bit of a ramble, but I wanted to say thank you for posting this and that sometimes I need to just downvote and move on.
Who exactly is part of this 'community' you speak of? This site is on the public internet and open for anyone to join. I don't remember being asked to accept some political ideology when registering.
And this is exactly the problem with consensus: There never is one. Just because nobody speaks up, doesn't mean everyone agrees with you. Nor should they. I have been to those kinds of meetings where the majority of people don't voice a dissenting opinion or, in fact, any opinion at all. To interpret silence as agreement is just bad faith.
In fact, your narrow definition of 'community' is elitist and closely mirrors its use in the mainstream press (such as in 'international community', which just means 'the West').
Many of your arguments are insufficiently defined. You make a statement, and then force others to assume what you meant from it in order to have any further conversation. When people do, you instead say that there was a different intended interpretation. For example, in the thread between you and me, the ambiguity of what you meant by time and effort earning money. Or, in your thread with "teddyh", your ambiguity about what you would like done to government.
In other cases, you ask questions that have obvious follow-ups or obvious follow-ups. They don't function as rhetorical questions, because the obvious follow-up works against the point you are making. Instead, they come across with the impression that you are deliberately wasting somebody's time by requiring somebody else to give the bare background information on a topic. For example, when you ask "If there are indeed 'low-effort, high-income' jobs, why isn't everybody doing them?". To me, the obvious follow-up is that there are structural imbalances that allow access to those jobs only to subsets of the population. We can talk about what those structural imbalances are and how they manifest, but needing to first establish that different people have different opportunities available to them is one step removed. That is what makes people feel that you are arguing in bad faith, because it makes the argument be on something that had been taken as given when entering the conversation.
Another part is that it is just so damn hard to tell the difference between earnest people and trolls. I know people personally who have your views. Heck, I had pretty close to your views for a while after reading Terry Goodkind's "Faith of the Fallen". But this is also the internet, where I don't know people other than by the few words in an individual comment, or a single comment thread. And depending on how far off somebody's views are from the Overton window of any particular forum, they can easily be the troll positions taken in order to rile up a crowd for their own amusement. Some people become desensitized to these attempts, and then assume that anybody with those views is automatically a troll. (See also, Brandolini's Law.)
I do honestly hope that you are sincere, and that this helps you to better express and examine your views in the future. It's hard to have conversation in a text-only medium, both because it is asynchronous communication, and because it doesn't have the side channel information of tone or facial expressions. Hopefully in the future, we can have more productive conversations and both come away the better for them.
have a good one...
Don't argue with me then - but you should at least explain how anything I've said was in bad faith if you accuse me of that.
This will never stop, and essentially defines the realm of "politics". Either you and people like-minded that share your views collectivize to protect your preferences from others forcing theirs upon you, or you lose.
This includes monopoly corporations that acquire power to restrict your ability to choose. And just wishing it weren't so, or asking people to stop achieves nothing. People won't, so your only choice is to protect your own turf however you can. "Libertarian" style abstaining from this fight ensures you lose, so is an impotent strategy.
For example, I could see a future, say in 10 years, where we have a vastly better way to browse the web and then we will look back on today and think that Chrome(ium) was coasting on its past success and only providing minor new features (while ensuring that ads continue to be as profitable as possible).
There's an alternate timeline where Microsoft leaned on anyone implementing it. We never would have gotten as far as Sun suing Google over the Java API because no one crossed Microsoft.
No AJAX. No web 2.0. No SPAs. It would be a different world.
Is it better this way? I'm not so sure.
Also, the mobile platform might be a good indicator of what ordinary people are willing to put up with. Chrome doesn't support extensions there, so everybody and their uncle is browsing the web with the full ad experience. I've never seen a non-tech savvy person use Firefox, or just anything but chrome (or the system browser), on an Android device, which easily allows to install uBO. Yet on the desktop somehow even those people somehow learned to install uBO or ABP. It appears that "apparently you cannot do this on your phone" is an acceptable answer to most people.
Chromium LoC: 34,900,821 [1]
Linux 2010: about 12 million [2]
It appears that Chromium has more LoC than Linux. (With LoC being a bad measure, Linux being GNU/Linux, blah). Browsing is hard.
[1] via Google since OpenHub appears down [2] https://commons.m.wikimedia.org/wiki/File:Lines_of_Code_Linu...
I agree that mobile is the direction many things are headed, but currently it's very easy to install any number of (sometimes shady) browsers from the Google app store that include ad blocking.
I don't want to have to self host a DoH server when it's so easy to edit a test file.
Furthermore, until every ISP has its own DoH server we are centralizing control of the basic internet infrastructure even more than now.
They are starting to do that. Therefore, better web browser must be written, with the user having full control, and not having things that the user cannot override (assume the user knows what they are doing; you must have enough ropes to hang yourself, and also a few more just in case).
"... there is nothing you can do."
I am typing this comment through a text-only browser. HTTP requests, with a bare minimum of HTTP headers, are being sent from a proxy I control, not the browser. Yet the comment looks no different than any other comment. It works. I have freedom to choose whatever software I want to make HTTP requests.
I try to avoid any software (not just browsers) that access the internet and bypasses the system DNS settings. The word "hostile" is a good choice of words I think to describe such programs.
Hopefully https://gioui.org/ quickly fixes that.
I mean, sure there is, some form of DRM is possible. It might be circumventable, but it would be a PITA.
The only danger is Google switching Chrome to closed source and adding lots of complex extensions that get widely adopted faster than they can be reverse engineered, but this seems an unlikely scenario.
The other danger would be general purpose computers or smartphones no longer available, but that also seems unlikely.
The final and most plausible danger is different and it is advertisers switching to ads that cannot be reliably distinguished from the rest of the page (currently it seems they don't do it because that removes any direct access to analytics by the advertiser and thus requires them to trust websites and they don't trust them).
Ads are obvious, they have to be for users to see them. You could probably use text classification and object recognition to filter ads effectively. And you could do it from the view layer where nothing on the page can tell they've been blocked.
This is also my tinfoily theory for why Chrome restricts the API's used by ad blockers. It's to prevent more effective blockers from being developed.
Ads are highly tuned for click through rates. Even if the model isn't 100% accurate, it would force advertisers to use less effective ad text to avoid filters.
That seems counterproductive to me. I mean, ads would still be annoying. And that’s why we block them.
The avoidance of annoyance is a just bonus.
I'm not so sure about that: https://static.seattletimes.com/wp-content/uploads/2020/10/g...
(See also: "native ads".)
In general, we've been engineering around bad user software install decisions for decades. Windows spyware, toolbars, spammy mobile apps, for example. The apis needed by an ad blocker are exactly the kinds of APIs that would be coveted by and used by nefarious ad products. In fact, the Firefox ecosystem took a big hit when Mozilla shut down a bunch of APIs that allowed for some pretty amazing ad blocking a few years ago. So why did they have to take those APIs out of the product?
Nefarious products that used those APIs. For example, on of the first things that happened with the original AdBlock was it was cloned and used to deliver and rewrite ads by a scumware company. All the warnings and pop-up scary messages in the world don't stop users from making bad decisions, and that at Google scale, may actually be a bigger problem. Ad Blockers may simply be collateral damage as the cost of dealing with app-drive ad fraud is petty staggering compared to the small number of ad blocker users.
That said, I'm on the side of giving users the power, even if they occasionally shoot themselves in the foot.
It's disingenuous to say "these API's are too dangerous to use" when the browser itself does all the things the API could. Why should people trust Chrome or Firefox more than their extensions?
Google/Apple got themselves in this situation by having their official stores. People assume it's on the store, it's safe. Now they take away API's because they don't actually police their stores, they just made them to have a captive market. Now they blame extension developers and take away API's because they don't want to admit they don't police their own stores enough.
Before the days of official stores most people were careful what they downloaded. And they would be again if it wasn't in these companies perverse interests to convince users that store apps are safer than non store apps. Because people would stop using the stores and take away the money train.
The right way to fix this would never happen. Decentralize the stores and let users make their own decisions. And take away all the api restrictions because once people realize the risk they'll be more careful. PC's are and have been an open market for decades, yet getting viruses is rare. I have no reason to believe it would be different for phones and extensions
uBlock Origin comes close, and surpasses in some ways (I used both for that reason) but lacks separate control of cookies, images, scripts, etc. So you can't accept a particular third party's images without also accepting its scripts, cookies, etc.
I mention it mainly in the hope that we can popularise its maintained fork 'nuTensor'.
After trying uBlock (as in attempting to also cover what I used to use uMatrix for) for a few weeks I think it's insufficient and nuTensor is the better option for me, but it quickly won't be if ~nobody uses it and it falls by the wayside.
Alternatively uBO could support the few details it lacks from uM? It seems like the problem basically was difficulty/time constraints in supporting both.. but I don't know why they were ever separate? There's plenty of overlap. If uBO had uM's granularity in 'advanced mode', that'd be perfect.
It can block separately a single script, image or any other request. I find it much better than umatrix which can't do many things that ublock does. If someone wantd to they can just install it and forget it also. Much more versatile.
It's a clunky interface with poor discoverability, but with the uBO logger open in a browser tab you can click on any request right beside the timestamp and define a new rule with the desired granularity. In the URL Rule tab, the unmarked left column sets the allow/noop/block behavior.
Edit: Found the wiki page: https://github.com/gorhill/uBlock/wiki/The-logger#creating-f...
It's just too painful to open a logger, find a request, craft something manually, etc. uMatrix is point and click and it's right there in the toolbar.
Is this true or not?
wait, here it is: https://news.ycombinator.com/edit?id=25920135
> umatrix is built into ublock origin now, just enable advanced mode in ublock.
I have advanced mode enabled and don't see anything remotely resembling the uMatrix source vs type grid. There's a couple overly cryptic { allow block other } columns with rows corresponding to the source and that's it as far as I can tell. No { css image frame etc } columns in my UI.
(Also I can never seem to remember precisely what each unlabeled colored box does. I never have that problem with uMatrix.)
It's just not as granular - you lose the 'type of thing to allow/block' dimension from the uMatrix matrix.
The uMatrix UI on the other hand was incredibly intuitive, and more granular. Then again, maybe that comes down to me not understanding what the hell is going on with uBO's UI.
[1] https://github.com/gorhill/uBlock/wiki/Quick-guide:-popup-us...
I also wonder about this. I still run both side by side. (I haven't noticed any problems with uMatrix so far ...) All I really use uMatrix for is quick coarse grained 2D filtering of various content types. I don't understand why that couldn't be implemented as an optional "first pass" filtering layer in uBlock.
I realize uBlock can mostly already do what uMatrix does, honestly I just find the 2D UI to be incredibly convenient and intuitive.
Well yeah, no, I don't want to do that. That's why I always ran both, (uBO in 'simple mode' cosmetic blocking only) and now nuTensor seems like a better option than diving into uBO alone. I gave it a go.
>This is not the case with Chromium-based browsers, i.e. tracker/advertisement payloads may find their way into already opened tabs before uBO is up and ready in Chromium-based browsers, while these are properly filtered in Firefox.
>Reliably blocking at browser launch is especially important for whoever uses default-deny mode for 3rd-party resources and/or JavaScript.
Oof. TIL. That makes blockers kinda crippled in chromes, if you expect them to actually block things.
Mozilla and Firefox exists because it's developers wanted to create the best browser possible. That's why it had extensions before Chrome was even a thing and that's why ad blocking extensions exist almost as long as extensions have been a thing. Adblock emerged somewhere around 2002 which was very soon after the first OSS releases by Mozilla reached the 1.0 stage. Also Phoenix, Firefox' ancestor became a thing around that time. Tabs and extensions were some of the early things that made that popular. Ad blocking always was the #1 use case for extensions.
Ironically, that's why Chrome has extensions. The only reason it supports extensions is that not having that would have made it impossible to grab market share from Firefox (and Internet Explorer). Having support for both extensions and ad blocking were a hard requirement for Google despite its business model. But now that it is the dominant browser, that feature is no longer as important as it once was. So, Google has been slowly making it harder for extensions to interfere with their ads and tracking. They can't make it too hard or their market share will evaporate. But they don't have to be particularly good at it. And now that they have Android, they don't have to worry as much about losing market share. Android exists for the exact same reason. Chrome is losing relevance as a revenue stream as users consume more content on Android via "native" apps running in a virtual machine compiled against mandatory proprietary ad & tracking technology.
For some people it is not just about annoying ads; for those people paid or unpaid work (or something else, I'm not here to judge) takes them to sites where you'd rather not be surfing with js enabled.
Remember: Client-side JS is a way for whoever controls the server side to execute code on your machine. Disabling JS instantly removes whole classes of nasty exploits.
On the other hand, I don't want random extensions, which could be misbehaving or poorly coded, to be able to indefinitely delay the browser's launch, even if it comes at the cost of one ad making it through. Imagine having dozens of extensions and trying to figure out which one is slowing down your launch because there's a bug.
What does break websites is turning on anti-tracking measures. The number of times a site won’t work till I enable third party cookies shows the sad state of the web. Developers, do you only test in Chrome on Windows with default settings or something?
Well, Chrome is removing 3rd-party cookies by next year, and they are disabled by default in Safari already (well, sort of, ITP is weird). So many problems which used to happen to very few users are now being quickly prioritized. There are lots of use cases for third party cookies (example: you have a centralized management platform for lots of websites which have unique mapped domains, and you want to be authenticated against all of them at once), so it’s not surprising that critical features can be broken. It’s very much backwards incompatible.
But I agree, overall removing 3rd party cookies is great. Though, it’s important that whatever advertisers think of next isn’t just as bad.
I really hate that firefox sets prefers-color-scheme: light with resistFingerprinting [0] even if the site is implemented in such a way that the color scheme selection provides no information to the server (no JS, no external resources loaded dependent on the color scheme). Even using no-preference would have been better - then the site could at least choose to make a dark theme the default.
> you're locked to en-US
Ugh, this will only lead to even more websites ignoring the Accept-Language header and just guessing based on location derived from the IP address.
To them, ads are part and parcel of "using the internet". Some of them hate ads. But not for technical reasons though.
Outside of complaining why they hate that annoying ad from company X, most people probably won't be motivated enough to actually do anything about it. For some, this is just how they expect the "internet" to work. An ad-free one would feel broken to them.
Ads are not a bother for most casual people.
Sorry for the rant.
Since a few weeks I use two 4k displays with my work laptop running Windows 10 and I with 4k it seems that Chrome is quite a bit faster than Firefox on Windows. With the FullHD resolution I used before I never noticed a huge performance difference. I don't know what causes it and on my private PC (different hardware) running Linux I never experienced performance differences of that dimension, but currently I have fallen back to using Chrome on the work laptop :-(
Anyone know what this extra permission is and why requesting this extra permission would cause friction?
Reproducible builds are non trivial.
And then what - the reviewer is now supposed to build your software and verify some Hash?
Or were you thinking something else?
I believe that is standard operating procedure for the chrome store.
That's true, but they aren't rocket science either. It's perfectly reasonable to require them for browser extensions.
When submitting to the Firefox store you need to send them your un-minified, un-obfuscated source, along with step by step instructions on how to build. If you get big enough they do review the code in surprising depth. The hash of the compressed file pushed for release, also needs to match that of the compressed file the reviewer can build.
When submitting to the Chrome store this is not the case. You can push up minified, obfuscated code and that's what the reviewers have to work with.
I'm not familiar with why WASM needs extra permissions for Chrome extensions. It might be that the increased complexity of reviewing bytecode does indeed introduce more risk for the user. The permission request might just be the Chrome store pushing acceptance of that risk to the user?
Minified maybe, but obfuscated is against the rules, for over 2 years now: https://www.zdnet.com/article/google-to-no-longer-allow-chro...
Chrome also does check the code manually, not sure if it's on the same level as Firefox though.
Code Readability Requirements:
Developers must not obfuscate code or conceal functionality of their extension. This also applies to any external code or resource fetched by the extension package. Minification is allowed, including the following forms:
- Removal of whitespace, newlines, code comments, and block delimiters
- Shortening of variable and function names
- Collapsing files together
[1]:https://developer.chrome.com/docs/webstore/program_policies/Presumably they are just really careful to avoid giving Google any excuses.
What I did was disable the overlapping functionality in uBlock Origin, and let uMatrix handle the rest.
I don't understand it, but I agree that unlock+umatrix on desktop and mobile has been the best thing about browsing for years.
I think maybe he wants to consolidate Dev effort and I completely understand. He's probably the only person I'm patriotic about right now.
Can you explain why you'd want to do this? At first blush it seems like a terrible idea to allow extensions to reload pages.
When you change the state a little refresh icon appears right behind the status icon indicating that the state of the page as shown doesn't match your setting. Clicking it reloads the page.
You could reload it automatically at state change but this might break whatever the user is in the middle of doing.
You don't have to have this feature but it is handy that the reminder that the page is out of sync is a button to fix this and that it is half an inch from your current mouse position.
I am relatively naive in this realm, but this is why I chose Firefox Focus as my iOS Safari context blocker.
Firefox Focus also seems like a great browser to have set as the default in apps like Apollo.
The way uBlock Origin and similar extensions on desktop browsers like Firefox work is by intercepting all requests, which means it can exfiltrate your browsing behavior and/or sell that. I’m confident that uBlock Origin doesn’t exfiltrate data, but the same cannot be said of other extensions in this space.
Apple, with its already restrictive content blocking model, will not allow a way for extensions to look at requests or manipulate requests. Chrome’s Manifest V3, whenever it’s adopted on the release version of Google Chrome, will also kill uBlock Origin (it allows requests to be seen, but not intercepted/modified).
Realistically, it's probably more security and battery efficient. I doubt they'll undo it.
Per the Apple app store rules, no one may publish a browser or javascript engine and any app that browses the web MUST use safari's webkit.
This is by design so that web feels very bad on iOS compared to native apps, so you'll keep using native apps and Apple will get their 30% of whatever you buy in app.
Recently Safari on iOS has changed how the back button works so pressing back now takes me to the top of the previous page rather than the location I was at before I linked away.
More recently Firefox on iOS also behaves this way.
The reason is because the WebKit engine on iOS is heavily optimized for battery life and can make use of private APIs that further that goal.
Safari and Chrome are essentially the same engine under the hood, the web wouldn't "feel" better if you had one over the other.
I'd add security too here. Also, if they allow native Chrome on iOS, Google domination in web standards would be complete and irreversible.
If you dig into some settings and follow tech news, I have begun to question some of Mozilla's controversial settings, deals with 3rd parties and their political blog posts. I also have a problem with the CEO making $3m per year yet a continued market share decline since she came on.
Just a few of the things off the top of my head that I feel betray my trust of Firefox (all of these pertain to default Windows install):
1) Enabled by default all of your website DNS requests going to Cloudflare with a "promise" this information is not being used or sold. We all know how solid this promise has been for other large tech companies. All under the promotion that DoH protects you from your own ISP.
2) Upon install, FF installs a scheduled service that runs daily. From what I've found out, that service is sending back to Mozilla what your default browser is on YOUR PC (why is that their business). This scheduled service remains on your PC even after uninstalling Firefox and continues to run daily.
3) Enabled by default are Browser Studies and testing a clean install one is already installed and active called "F100 Snippets". Studies allow the Firefox team to install stuff right to your browser whenever they want, to gather telemetry .
4) "Recommended extensions" enabled by default. Got a nag for a recommended extension after few days of browsing. So FF must be scanning your browsing history in order for this to work?
5) this result: https://brave.com/brave-tops-browser-first-run-network-traff... . While it was from 2019 so needs to be updated, but upon first-run I was shocked at the results for FF here.
6) Firefox on Android has a known tracker embedded and enabled by default called Leanplum. From Mozilla's own website they state "Leanplum is a mobile marketing vendor"
I'd love to support and use FF solely again, but I think they need some serious shaking up, starting with a new CEO (who allows this stuff).
This is shocking to me. More information, if anyone is not aware yet: https://firefox-source-docs.mozilla.org/toolkit/mozapps/defa....
> The Default Browser Agent is a Windows-only scheduled task which runs in the background to collect and submit data about the browser that the user has set as their OS default (that is, the browser that will be invoked by the operating system to open web links that the user clicks on in other programs).
> 1) Enabled by default all of your website DNS requests going to Cloudflare with a "promise" this information is not being used or sold. We all know how solid this promise has been for other large tech companies. All under the promotion that DoH protects you from your own ISP.
AIUI, this is only in the US, where for practically everybody the alternative is indeed that they're going through your ISP, with a promise that the information is being used and sold. Kind of a rock and a hard place situation.
> 4) "Recommended extensions" enabled by default. Got a nag for a recommended extension after few days of browsing. So FF must be scanning your browsing history in order for this to work?
To clarify, it's not the extensions themselves that are enabled, but the recommendations, right? If so, yes, Firefox is analysing your usage, but that is your local Firefox install, i.e. the thing that already has and uses your full browser history. AFAIK the rules for when to recommend what are the same for everyone and run just on your computer.
The article states: "Firefox remains one of the chattiest browsers during a first run. At 117 requests, it lead the pack with individual requests. It should be noted, however, that this isn’t the browser itself making all of these calls, but another page that is present during startup."
So it seems that the initial page is the thing making most of the network calls, and not the browser itself. Wouldn't this mean that we can simply disable the wi-fi/internet temporarily to load the browser initially, closing unnecessary tabs, and customizing it as we needed?
In general, this seems like a good practice for opening up apps in general, even though it's a minor inconvenience and we theoretically shouldn't have to do this. Anyway, I don't mind the telemetry if it will help and not be used against us.
I never used uBlock, but I did use uMatrix (discontinued, but still working) which allows you very fine grained control over scripts and other resources based on the domain. Unfortunately it was a pain to get some things to work with that, especially online payments which use many subdomains and redirects. Paying for anything online was a game of enabling 10 domains on average, reloading the website, re-inputting payment info, etc. Some websites (like twitter) simply didn't work even if one enabled all the domains which appeared in the matrix.
Brave is pretty decent at blocking JS. Not as fine grained as uMatrix, and it apparently doesn't remember that you enabled things (at least in private browsing). I think it doesn't perform what uBlock calls HTML filtering, because it still makes requests to websites which were completely neutered by uMatrix. All in all it's more pleasant to surf using Brave than Firefox, because fewer websites are broken by the blocking.
I wasn't pleased with Safari's native tracking protection + a simple Safari blocking extension which only looks at URLs. Websites work the best, but it's making requests to many unwanted domains still. Maybe it's blocking cookies and scripts, no idea, but I'm not happy even with the simple requests for resources going through.
(Except for CNAME cloaking. However, their CNAME uncloaking only applies to their built-in tracking protection. AFAIK, if you use uBo on Brave it will be still unable to uncloak CNAMES.)
> In version 1.25.0, uBlock Origin gained the ability to detect and block CNAME-cloaked requests using Mozilla’s terrific browser.dns API. However, this solution only works in Firefox, as Chromium does not provide the browser.dns API. To some extent, these requests can be blocked using custom DNS servers. However, no browsers have shipped with CNAME-based adblocking protection capabilities available and on by default.
Brave does have a few intriguing privacy features, like plugging WebRTC IP leaks while still allowing use of WebRTC (Firefox is off or on while Safari's always on AFAIK), so that's not excluded.
The main problem with Brave is that they're building on a browser which is designed to leak privacy like a sieve. It seems that they're being careful and monitoring all the anti-features Google's adding, but who knows.
Only for extensions. Brave Shields is implemented in natively compiled Rust and C++ (which is even more efficient than WebAssembly), is able to load rules before making any network requests, uses a compressed filter list data representation, and prefetching is disabled entirely in Brave. The only thing currently missing from that list is HTML filtering, which is fairly rare in practice and generally has fallback rules in popular lists anyways.
Don't get me wrong, I miss Chrome as it just felt like a_smoother_ user experience, and I fear for Firefox replaying Opera's history given that the rest of the industry has standardized on Chromium... but I love how pro-privacy Firefox is.
> after one year of Manifest V3 actually shipping to users in mainline Chrome:
> - Assuming that Manifest V3's declarative API is not significantly changed from its current implementation.
> - If you visit each of the top 10 publishers in the US (including open publishing platforms like Twitter/Facebook/Youtube) [...]
> - Firefox will block more web trackers (65% likelyhood).
> - Firefox will block more visible ads and popups (55% likelyhood).
It's debatable whether or not the December rollout of Manifest V3 "counts" because Manifest V2 is still going to be available for about a year, but it's also increasingly looking like it won't matter -- the prediction might end up being proven right regardless of whether or not Manifest V2 is removed.
I would probably raise these likelihoods if I were to revisit the prediction today. I think it's reasonably unlikely that CNAME masking is going to go down in popularity, and I think it's reasonably unlikely that Chrome is going to put in the effort to catch back up. The one thing that gives me pause is that the original prediction specified looking at the top 10 publishers, and I'm not sure if any of them are using CNAME masking yet.
Our children have grown up on a, largely, ad-free Internet; and it's all thanks to people like him.
Will we ever get enough traction on either blocking mechanisms or stop shoving ads everywhere? Will the general public experience the pleasures of an ad-less internet?
P.S. I'm on an iPhone, blockers failed me so far. Thanks for the suggestions fellas.
Keep that in mind next time you go to buy a phone!
I do also use uBlock Origin on Firefox Mobile though.
Back in the day Opera with Turbo (or whatever it was called) was the peak of mobile browser usability for me.
I’m surprised to hear that Firefox doesn’t have the option to do so.
I don’t know if it’s just muscle memory, but Safari on iOS is still my browser of choice due to the way you open and close tabs in it.
Also for Safari, Magic Lasso AdBlocker does a very good job.
I don’t notice any difference between Firefox or Chrome + ublock origin and Safari + Wipr/Firefox Focus.
The biggest benefit is that as every web view on iOS is Safari it means you get content blocking in all apps that use a web view (providing they don't disable it which I'm sure some do but I don't know of any that actually do it). E.g. in the third-party reddit app Apollo any website you load within the app also has all ads blocked.
I paid for full version of AdGuard Pro late last year after my 6 month Android/Oneplus phase ended and I went back to iOS. It has worked REAL well and allows me to just use native Safari. I'm happy with this setup. I used to use free Firefox Focus as the content blocker before, but it would go long time between updates.
The only annoyance with Adguard Pro on iOS (and probably the same for all app based content blockers on iOS) is it is clunky to whitelist a site as they aren't integrated with the browser. You have to open the app itself, dig into the whitelist area and then manually type in/paste the domain name to add it. Brave and FF Focus you can do it right from within the browser, same as it was with FF/ubo on Android.
Also, AdGuard on iOS doesn't acknowledge specific pages only within a domain. For example; mlb.com is loaded with ads, their highlight videos show a 15 sec ad for literally every highlight. I have AdGuard enabled and the experience is so much better. BUT the "Standings" page doesn't load with AdGuard enabled and I can't just disable it only for that page.
Regardless, the small price to pay for AdGuard on iOS is well worth it.
I don’t care at all about any of this. Give me the time they boil for ffs.
I don’t know if it’s sites paying by the word, or SEO, or some “value added” psychological trick. It is getting worse.
Of course, the time spent is cursing, and skimming and hunting to find useful info. No one is finding the story interesting, but it looks good on metrics?
I wonder if the above is accurate or not.
So forcing you to scroll through an essay on the complete history of nutmeg before you can see any of the ingredients in a chocolate chip cookie recipe may improve SEO
I guess I avoid the junk because I have good instinct, I can usually tell if something is going to be bad based on the ingredients. Also if I'm looking to make something "basic" I'll specifically look for Alton Brown's recipe for it or sometimes Chef John's recipe. I also sometimes just use recipes for "inspiration" too - just to get a basic idea of what the ingredients are.
If there was some better mobile integration of the extensions or built into the browser itself to be perhaps less intrusive adds allowed it would be appreciated.
From that, are browsers legally allowed to implement an adblock/ublock directly into their browser ? Seems like something that would be considered against fair use or something along those lines.
Yeah, they follow every dark pattern in the book, especially on mobile. 90% of the time, I'll see a video at the top that autoplays, and then if I scroll down, it will make the video hover over the 75% of the article I'm trying to read. Who is this supposed to benefit?
Alternatively check out "Paprika" which bills itself as a recipe manager but actually will scrape webpages and extract out recipes for you.
This ecosystem is now so advanced that new copycat recipe sites are based on existing copycat sites. You can easily tell if a recipe website is a copycat by comparing the supposed author bio to the quality of the English. If the author bio claims these are recipes by a born and bred Louisiana native who wants to share Southern cooking with the world, but the actual text is full of grammatical mistakes typical of Eastern Europeans or South/Southeast Asians, it is clearly a rewritten copycat site.
Then, as you note, when people do inevitably copy the recipe, they churn out new replacement text.
You'll notice, for instance, that a recipe 'database' site like allrecipes doesn't have these massive text blocks associated with user-posted recipes, because there's no need or desire to have those be copyrighted.
There are fundamentally 2 types of content, although the line is getting blurred : The hobbyist blog, and the publishers magazine.
The first exists for joy, the second only exists to deliver adverts.
THe blurring occurs because some of the blogs became such hot property the founders sold up.
Remember how cable was supposed to replace ads on over the air tv? It was about minutes before it was all ads too. Streaming services are starting to get there but then the shows themselves are ads. And you have a scenario where Netflix and YouTube couldn’t exist in scenarios that didn’t rely on our bandwidth models and massive anti-competitive models.
... so IDKMAN... I don’t know how we get to an internet where people making things aren’t expecting to get paid for their submissions, especially now that we’ve jumped in there with both feet.
I personally would pay for a no-bullshit internet, but it’s just cable tv’s promise all over again isn’t it? As great as something would start out, soon would come the influencers and the narrative pushers and the censorship and the “forum sliding” and the downvotes / echochambers / bubbles / power tripping moderation...
I’m wondering if the solution isn’t just to give it all up and use the tools only when you need them. A cabin in the woods, but a spotty dialup connection for when you need to find something.
The money is in selling you ads, on a revolving basis. Not in you ponying up a subscription fee to not see those ads.
If it's not the ads, it's the usual FBI or whatever government surveillance program tracking you.
You are right on the solution however. Some ads and tracking are so pervasive (e.g smart TVs) that the only truly effective way to mitigate against them is to cut down on or eliminate your exposure to these devices.
I was a noscript user from 10+ years ago (I guess?) and I’ve been using uBo for as long as I can remember but isn’t Firefox on iPhone just a wrapper? Is it battery efficient?
As a workaround I use a Pi-Hole (except, not on a pi).
Mozilla has Firefox Focus for iOS, it does Ad Blocking but it's main selling point is No Tracking, No history and No synced bookmarks either
On Android, Firefox supports a subset of extensions that includes uBlock Origin. Chrome seems to be the dominant browser on Android but regardless of how good it is, I can't imagine not using Firefox there.
I personally tend to use Chrome for "logged-in" internet use, and Firefox for "logged-out" use like browsing, news, etc. True on both desktop and mobile. Partly this is because Google's password vault has great UX across Chrome and Android apps.
Sadly ios devices don't seem to have that option.
If people try to encourage too much radical change with how ads are distributed, I fear that the advertising agencies will panic and all start to do what YouTube does, which is to serve the ads from the same domain as the content, rendering all domain-based adblocking useless. At that point, the only thing between the general Internet and ads will be uBlock, and if Google obtains complete control of the WebExtension standards, I'm not sure there would be anything else we could do.
I run FF+uBlock on my S21 Ultra. Works just like the desktop.
Half a thousand bucks for this frustration, no thanks! No amount of content/entertainment is worth this.
There's also a Lockdown, an open source firewall implemented using iOS VPN capabilities (though it doesn't send your requests through an external server). Lockdown is able to block trackers in any app, not just Safari.
It's not perfect and difficult to customize but works well for the most part. It even gets rid of YT video ads (mostly anyway)
I also combine it with NextDNS
If Firefox made their browser the best at ad-blocking instead of performance (which also might go hand in hand) I would consider using it again.
IME Firefox is much more of a battery hog on MacOS, Chrome's history page is much better, and some sites (Glassdoor and Google Meet come to mind) don't work properly in Firefox. And I don't really use the developer tools in either but I've generally heard that Chrome's are better. I still use Firefox as my daily driver but it's not flawless.
The dev tools in Firefox are better for working with CSS [1], about as good for everything else. I only resort to Chromium when working with PWAs.
Chrome is just too hostile to its users. Between incognito mode tracking users around the web, this extension/API hoo-hah, among other things, I'm just not excited about it as a browser anymore.
You did a lot for us, Chrome, but it's time to loosen your grip on the browser market.
IMHO they seem to be losing focus on their technical strengths - making a browser their audience wants to use. Over the past year I'm seeing a lot more problems with addons, specially on Linux. Several popular addons like umatrix and ublock origin make the UX sluggish, interacting with the addons UX are hit and miss, and such operations are often unresponsive for me. I'm seeing this on Ubuntu, PopOS and Mint.
Mac and windows variants work reasonably well for me, but it's come to a point where I've reluctantly switched to Vivaldi for day to day personal use.
My thanks and appreciation for Raymond Hill's excellent work. Though the technical aspects favor Firefox in theory, the extension / addon works far better with Chromium based browsers in practice for me.
I cant find the link right now, but there was a nice timings done where Chrome was using less CPU at lower tab counts, but when it increased count, the CPU utilization was considerably higher than FF.
I'll be giving it a fair shake for a few months.
Or more specifically, I'm wondering what change you could be referring to. We've had incremental GC for many years now, which does exactly what you describe. It's true that we keep splitting up more of the uninterruptible pieces into smaller chunks, but I don't recall any major change there recently. (I'm not very good at marketing, am I?)
And according to telemetry, the incremental slices have been working quite well for most people, at least within the last dozen releases or so. We have a budget, and it's rare that we go over it. Not that I fully trust telemetry; if you have counterexamples please file a bug. (I'd love to have a nice set of scenarios that are problematic for the GC. Our telemetry errs strongly on the side of privacy, as it should, so I can't get URLs automatically.)
At a first try Sidebery looks and feels more modern/slick! Might be what I was looking for!
Go to: about:telemetry#scalars-tab
Then look at: browser.engagement.max_concurrent_tab_count
(Pretty clever to use telemetry for this, though.)
But that's the fault of Firefox.
I'm always astonished how bad/slow the mobile web experience is without Ublock with JS blocked by default.
For example, I prefer the address bar at the top. Firefox doesn't like that, so the new tab button stays on the bottom, meaning I have a six inch stretch between where my finger was to hit the tab manager and where it has to go to open a new tab. It's full of little things like that where the only explanation that comes to mind is that Mozilla decided they couldn't do it the best way because Chrome was already doing it that way.
Which phone / OS do you use?
Btw, to search for something I open Firefox and type in the URL bar.
If you have a good keyboard, you can even use DDG !bang syntax. I find this very helpful for finding what I want fast.
There are some quirks though, minor annoyances that every so often get introduced in updates. For example, when closing the last private browsing tab it doesn't automatically show the regular tabs any more, but instead requires three more taps. But I'm happy to ignore those for the sole reason of having fully functional ad-blocking.
How? Is there a hidden about:config?
Then I started to think about what kind of tracking google was doing with it, so I tried out firefox... which was just as snappy and just as memory efficient.
Then I deleted chrome.
That was also an era of websites crashing all the damn time - in firefox it was crashing the entire browser.
Chrome was a significantly better browser for a while. Now it's just "why switch?" to your average consumer.
- command+d will save a bookmark to the last folder used
- command-y will open the history in a new, full tab
- bookmark manager also open full by default
- Recently closed shows windows and tabs together without separating them
- I can actually see and edit a list of all search engines I have registered that use the tab to autocomplete. Firefox's keywords don't
That sounds pithy, and it is, but Mozilla burned every ounce of goodwill they ever had with me over the last 5 years or so.
I also recently started using Firefox full-time on my work machine despite IT strongly mandating that all our tools only work on Chrome and everyone should use that. Have had zero problems (and we use every Google service under the sun).
Really? It happens to me all the time. I can't log into my U.S. Bank account in Firefox, I can't submit a delivery order on Doordash in Firefox, and (just this morning) I couldn't validate a credit reporting form in Firefox.
Now, despite those and many other examples, I continue to use Firefox as my primary browser, because Chrome has bigger issues in my opinion. I don't blame FF for this, I blame the websites. I just think it sucks that places do not test in or support Firefox better.
"Access Denied You don't have permission to access "http://www.costco.com/" on this server."
Is this from running NoScript? Or does it affect all Firefox users? (Also the URL is https://, not http://, so the error message doesn't match the URL).
I also have some "unusual" settings in about:config that I mostly don't even remember, for instance disabling service workers outright.
The question becomes, why not disable them?
I am not aware of any attack vectors specifically related to service workers -- it's just normal JavaScript, but with more restrictions.
Before I disabled them, I saw a ton of service workers registered from sites that I visited once and likely will never visit again, so even if there are no attack vectors, it seems like it's at the very least, "stuff that I don't need."
> cache a web app locally in order to make it load faster
Uh, isn't there already a browser cache for this?
> run entirely offline
No thanks.
> push notifications
No thanks. :)
Like I said I've had them disabled for a long time now and haven't had any issues, so at this point I'm not going to think about it again until and unless stuff I care about starts breaking.
[0]: https://support.mozilla.org/en-US/kb/troubleshoot-firefox-is...
Clearly not a universal thing then I guess.
uBlock Origin just happens to be so incredibly important and trusted that an exception should be made for it.
There are other things I consider superior about Firefox that Chrome has yet to implement:
- Multi-account containers is a killer feature IMO. I have different containers for banking, Facebook, a container for every email, a container for every Google/YouTube account, and so forth.
- The option to enable canvas permission prompts and canvas obfuscation. (though there are some arguments that those make you *more* trackable)
- Autoplay blocking and permission prompt
- Pop-out videos (aka picture-in-picture) are awesome and make it easy to keep videos on screen while browsing other tabs and apps.
- Built-in anti-fingerprinting
- Blocks tracking cookies by default
I simply won't use a browser that doesn't have these things.What I always give as an example, is how to add custom searches (Amazon, Reddit, HN, etc), you save the query url and add a keyword. Works very well to type `rdt something` and have the results. But: there's no option in the menu to see all keywords/search engines you have registered.
Imperfect, but the convenience is worthwhile for the dozen-or-so keyword searches I use.
A non-sanctioned way to mitigate this might be achieved by editing containers.json, but I'm wary of inviting sync shenanigans.
Out of all my computers the only one I have is a Thinkpad T60, manufactured in 2006 if I'm not mistaken.
Chrome has this.
I know it sounds silly but I've used it for SpaceX launches to keep an eye various official and unofficial streams.
Umm...you can do all of those things. You might have to right click the video twice to get the picture-in-picture option (to get around the contextual menu of many video players including YouTube) or you can use the official extension that you click to popout whatever video is on the webpage.
Now how do I get Chrome to stop auto-installing itself in my login items on macOS everytime there's some kind of update.
Edit:
Also, if you're on Android, set Firefox Focus as your default browser! It's amazing to not have to think about the tracking consequences everytime you click a link somewhere on your phone. It's basically a new "container" for every link click. If you need the cookies, then there's a handy "Open With" menu to let you re-open the page with regular Firefox, or Chrome.
And uBO works on the regular Firefox Android browser.. Again, game-changer for me.
Even with multiple containers, it still means logging into AWS SSO multiple times and selecting the right account.
It’s unfortunate. Plan to try it again but it was borderline burdensome that x containers or place settings wouldn’t sync or that the Mac mini or linux box would start sounding like a jet engine.
Not sure about the container connection, but Firefox also now has 'about:performance' which is pretty much like 'top for browser tabs'. When things start getting bogged down I can now find the culprit and nuke it.
about:memory is also useful, it allows you to force garbage collection on the browser as a whole.
(There's an experimental sidebar extension that works better and gives a graphical history, but I'm pretty sure it's unfinished and unavailable for general use. Hopefully it'll come out sometime.)
Was not aware of those. My observations were mostly noted while trying to figure out why one specific browser wouldn’t simply not sync any custom containers. And then I noticed my fans spin up on my macmini. I only used system monitors at the time before just disabling the add-on.
I’ll definately look at those in the future. Didn’t even know they existed.
Agreed on all points. It's funny, I've been using Firefox 20+ years and when I saw them recently boasting about PiP I thought "another useless feature".
Until I decided to try it out. Now I use it constantly.
I get the situation is different, but my parents escaped from two civil wars in Central America in the 70s and the stories they told me about political persecution were scary enough to make me distrust organizations that don't seem to understand nuance when it comes to politics.
I remember that post, and I think you're mischaracterizing it. The point wasn't that "deplatforming is a good start, but we need to go even farther"; it was "deplatforming is not the right solution, we need something better".
As for trying to block harmful content -- Mozilla is already doing that, all the time, so you're certainly not going to get any promise there. Firefox blocks malware, sites with expired/mismatching certificates, things on the (un)safe browsing list, 3rd party cookies in some configurations, etc. Whether any of those constitute censorship is up for you to decide. Right now, it feels fine to me, but I agree that there's reason for concern. All the browsers have all the mechanisms necessary for censorship, and there's no way to crisply define "harmful".
I still use Firefox not only because the browser is not necessarily the same as the foundation, but the alternatives are organizations with far, far worse track records. (putting aside the advantages I mentioned)
It's been fine so far. The biggest annoyance is that Firefox on iOS struggles a lot with form autofilling, and I don't think credit card autofill is allowed at all. You'd think this would be a minor annoyance (don't most sites save your payments methods?) but it's honestly been a big issue. So many sites are so broken on mobile that I actually can't create an account from mobile, and barely function well enough to get through the guest checkout flow.
Examples: Jersey Mike's (sub sandwich shop), and another local deli place that's too local for me to name without letting everyone know I live in a cornfield.
I would consider this a feature, not a bug.
So I am an FF user by ideology, but sometimes do use Chromium (basically only to not have to run electron).
1. Those test convey any useful information leading to
2. The average user is able to notice the difference in the real world
I think that things that are not js execution time for actual site functionality are much worse for the overall web experience, namely js execution time for ads/trackers and overall latency caused by bad connection quality or bandwidth. The overall experience on firefox with ublock is en par with chrome with ublock for your average mom.
What technically do you find missing in FF?
Can’t Mozilla “just copy” the look and feel of Chrome or Safari while keeping FF’s internals untouched?
Saying this as a former uBlock Origin fanatic.
I don't see Firefox competing. Mozilla doesn't seem to believe that monetizing a browser is possible, whereas I pay thousands of dollars a year at my company because of Chrome's integrations with these other systems.
Until Firefox can compete like that, and maybe they just can't, I can't switch.
> I use GSuite for management
Using FF would break existing MDM/DLP policies that they themselves have set up.
a) We're a small tech startup. We use Chromebooks exclusively because it makes corpops/corpsec and compliance trivial.
b) Why not Firefox? Maybe Firefox could work, but I'm not sure - with GSuite we can manage Chrome extensions via policy, we can manage Chrome versions, Context Aware Access, etc.
Being able to log into any Chromebook and immediately have all yours bookmarks/apps/tools/passwords/etc. that you use on your desktop and laptop is pretty useful.
As great as Firefox is, if you use Chromebooks then you're gonna use, well, Chrome.
Most people use browsers for facebook, gmail, youtube, and things like banking, taxes, etc. It's common that, when facing any issue when using Firefox - with banking and government sites, you are going to be told to try using chrome. So, for the end user, chrome is the better browser, as more sites work properly on it.
Why is that?
Firefox was big between 2004-2010 if I recall. Chrome came out in 2008, and needed a couple of a years to really dominate mindshare. The growth of Android helped as well.
Classic google/chrome “Yeah I know you’ve got these setting, but I’m just going to ignore them because this website wants to do it”.
How did sites survive before the ad infestation business model?
On top of that, much of the tracking that does go on is actually blatantly illegal in how it's done, at least in the EU. It's just too small-time to enforce at scale. Doesn't mean I have to take this as a given.
If the only thing that website provides of value is a billboard, it doesn't deserve to.
I'm perfectly happy paying for high-quality ad-free services.
It’s annoying how self-righteous HN is about Ads.
Because it's extremely easy to disable the ads.
> Surely you could avoid them and stick to your high quality paid options?
I don't want to avoid the websites, I want to avoid the ads. If that at some point necessitates avoiding the website then sure, but fortunately it doesn't at the moment.
I don't want to use containers to manage the different work/personal profiles I have and the lack of easy way to toggle between the two (a keyboard shortcut) has been a deal-breaker every time I tried to switch.
The profile manager in Firefox is long overdue a revamp.
This doesn't explain why the Chrome version doesn't use LZ4 or better by default. There are native JS implementations of LZ4 available as well that don't require WebAssembly.
1. Scrolling. 2. Save to PDF.
The best way to avoid ads is not to visit sites that have them.
I really wish ubo wouldn't disable pre fetching. It has nothing to do with blocking ads. It just slows down the browser.
Should I be using one, either, both? Are they competitors or complementary? What does each do best?
Example: Allow domain foo.com to run scripts, but domain bar.com cannot run script, no cookies, but css and images are okay.
But either way, I take this wonderful tool for granted since I have been using it forever (and its predecessors).