uBlock Origin review
addons.mozilla.org
addons.mozilla.org
They don't accept donations. Gorhill you are a beautiful person.
ublock is almost required infrastructure on my machines. os, editor, mpv, browser+ublock
i'm so pissed that the courthouse admins didn't include it, our cripled network is filled with stupid ads that could have been avoided
And it's all thanks to people like Raymond Hill.
I also started using the YouTube mobile website instead of the apps after getting 2 ads before a 3 minute video.
Have you tried NewPipe? https://newpipe.net
Mostly the benefits outweigh the downsides for me, for a lot of reasons: data export is a big one. The ability to download videos/audio is another. Background listening is another. It's also way more battery efficient than any of Youtube's official apps for video or music.
One thing I would recommend, the version in the offical F-Droid repo works, but you can also install the direct source in F-Droid, which will get updates/bugfixes much more quickly.
Same sometimes happens for me with a single video if I come back to rewatch/finish watching the next day. I can live with it too.
Long story short, it tried to use my phone as a disposable phone number. For about a month I was getting messages from adult dating sites, verification numbers for all sorts of services, and a few phone calls from bitcoin banks trying to verify my ID. Had I given the app permission to read my text messages, it would have been a catastrophe. Fortunately, I didn't and nothing bad happened.
uBlock Origin is also more fully featured than Content Blockers, which don't have the on-demand whitelisting features and toggles. However, since uBlock Origin is only available as a browser extension, it can only be used with a browser that supports extensions. No browser on iOS is able to support uBlock Origin.
Safari 13+ on macOS also no longer supports uBlock Origin due to platform restrictions: https://github.com/el1t/uBlock-Safari/issues/158
It's interesting how Firefox Focus on iOS also acts as a Content Blocker for Safari, but I find AdGuard to be more comprehensive on iOS.
And unfortunately, on iOS the alternative isn’t ublock origin.
(Edit since I can’t reply): Firefox Focus does appear to implement iOS content blocker since it appears as an option under Safari settings for content blockers.
Firefox (standard and Focus) and other iOS browsers can block ads and trackers, but not as comprehensively as that API can. That API is limited to Safari due to platform restrictions, which I hope get removed in the future.
Firefox Focus appears under Safari settings > content blockers, along with more typical blockers like AdGuard. I think they both implement Content Blocker API.
WKWebView does not support the Content Blocker API. Ad blocking apps that use the Content Blocker API are only compatible with Safari and the SFSafariViewController component, which is very feature-limited and not suitable for a full web browser app:
- https://www.wwdcnotes.com/notes/wwdc20/10188/
- https://developer.apple.com/news/?id=trjs0tcd
As a workaround, Firefox Focus uses script injection to block ads and trackers within the browser part of itself, but the Content Blocker part of Firefox Focus only affects Safari:
- https://github.com/mozilla-mobile/focus-ios/blob/main/Blockz...
- https://github.com/mozilla-mobile/focus-ios/blob/main/Blockz...
- https://github.com/mozilla-mobile/focus-ios/issues/1761
However, both Firefox Focus and Safari (with the Firefox Focus Content Blocker enabled) score 78% on that test, so Firefox Focus might be good enough for web browsing on iOS if you're comfortable with its feature set and don't need the additional filter lists or custom rules that another third-party Content Blocker would offer.
Apple should still allow third-party browsers to use third-party Content Blockers, since this restriction is an unnecessary handicap for any non-Safari browser on iOS.
It is funny that Android has better adblock features (uBO on Firefox).
If you run your own server, you can get to 100% by turning on blocking for a couple of hosts not in standard blocklists that this test has highlighted.
The DNS setting applies to most or all apps, as far as I can see, as it's applied as a system level provisioning setting. iOS 15 gives more visibility of this in the UI, but it works in iOS 14.
I’m not sure if browsers apply height limits to these popups, but if not, almost every time there will be oodles of space for full labels and replacing the two single rows of buttons with columns. And even if scrolling is introduced, that’d still be better.
At least they now have tooltips - I remember when choosing "Advanced mode" (which you need for a lot of features) just disabled tooltips in the UI, on the theory that advanced users shouldn't need them! I (and likely many others) argued how crazy an assumption that was, that just because we understood how HTML and JS worked, we should remember a bunch of icons and what the dev decided they meant. Thankfully they were willing to listen and change the decision, and the UI is a lot better for it.
Also, Vivaldi has a fairly complete adblocker built-in, with custom filter lists and also scores a solid 100% on that test.
I know other browsers have their own built-in ad-blockers, but I prefer to use uBlock Origin across all my devices so, when I setup a new one, I can just import my existing rules & settings, built up and tweaked over many years, rather than start from scratch.
I've got simple rules to chop the ads from LinkedIn, but if you do an inspect on FB, they've been very sneaky about how the elements are set up, eg it doesn't just say "Sponsored" in a string, it's a weird mash that ends up looking like that when rendered but hard to nail down.
Then again I'm more of a backend dev, so maybe that's why I don't know what to do.
It is designed to be very hard to select automatically. It is also why I don't use Facebook more than 5 minutes a week - it is among the only services where ads annoy me.
> *Important News*: 4th September 2021: Sponsored Posts Issue: It seems Facebook have just changed their code for Sponsored Posts, so some people have started seeing Sponsored Posts in their Newsfeed again, I am working on fixing this, please be patient, thanks! *UPDATE* It seems for some people the sponsored posts are only getting through if your Newsfeed is set to "Top Posts", if you switch to "Most Recent", the Sponsored Posts should in theory disappear. The good news is that FBP has an option to keep you permanently on the "Most Recent" feed when you visit the Newsfeed, so that could possibly solve the issue for now, give it a try and let me know if that solves it for you. In the meantime, I will continue working on a more robust fix.
Under the "Further options" heading there is a setting titled "News Sort: Most Recent". Tick that option, then click the "Save and Close" button.
As mentioned above this is not guaranteed to fix hiding the sponsored posts, but a lot of people are reporting success with it, as Facebook seem to pepper the "Top Posts" version of the Newsfeed with more ads than the "Most Recent" version, and "Top Posts" is Facebook's default setting for the Newsfeed.
facebook.com##div[data-pagelet*="FeedUnit"]:has(div[aria-label="Sponsored"])
facebook.com##div[data-pagelet*="FeedUnit"]:has(span[aria-label="Sponsored"])
facebook.com##div[data-pagelet*="FeedUnit"]:has(a[aria-label="Sponsored"])
facebook.com##div[data-pagelet*="FeedUnit"]:has-text(Suggested for You)I don't understand why Firefox mobile can't be used to debug another Firefox mobile, I I'd love it if I could open devtools off to the side and see a live tree view instead of manually prefixing the URL with `view-source:` only to find out the html doesn't actually include any content.
I use Firefox only for work, which has helped me immensely to stay focused and not “just quickly check hacker news for the tenth time in an hour” (as much as I like to ;)).
It’ll make finding tips like this much harder.
It's really effective. I don't even know what to do with my phone any more.
I hear there's some way you can use an app on your phone to have a voice conversation with someone else, but apparently you need to know a magic number?
I'm told there was even a time when the number only addressed a location, so you would have to figure out who was talking on the other end through a complex linguistic handshake.
And it didn't even have identity authentication, past a basic voiceprint!
I used this filter, it makes twitter links look like normal text:
##a[href*="twitter.com"]:style(pointer-events: none!important; text-decoration: inherit!important; color: inherit!important)I've not taken to blocking whole sites yet. But sites with "recommendations" attached to every page are a real distraction. I block them on stackoverflow, otherwise I end up reading about the etymology of some obscure word or advice for a dungeon master in a weird D&D scenario =)
I wish the exception for add-ons not working on the addons site would only apply to the actual add-on download portion of the site, and they don't host random non-addon-download content on the same domain.
https://bugzilla.mozilla.org/show_bug.cgi?id=697436#c14
If there is an "obvious" problem, chances are it has already been addressed and you are not the first person to see it.
I'm very confused. How the hell does Mozilla have enough lobbying power with Google to strong-arm them into providing an option for every user to undercut the very data collection Google provides GA for?
Open a new tab. Enter about:config
Search for this specific line: extensions.webextensions.restrictedDomains
Remove any entries you feel offend. I personally clear the whole list out, no website should bypass my addons.
Source: https://forums.informaction.com/viewtopic.php?p=97010&sid=7f...
I'm gonna need sources if you're talking about something else
I love the seratonin rush of one-click "disable 1p CSS" on an ugly website, or figuring out how to fuck with a clever-but-stupid paywall for the first time. :)
Also, the uMatrix UX is absolutely brilliant (that genius 2.5D green/red matrix).
this is built in to firefox since it was netscape navigator, under view -> page style -> no style.
even the menu items have barely changed since then: http://www.alanwood.net/unicode/net7_encoding.gif
https://www.reddit.com/r/uMatrix/comments/onp0c6/umatrix_142...
I think you can get that granular in the manual/text based rules edit of uBO in settings, but I stopped looking into it / considering switching fully at that point (I'd always used it in simple mode in addition to uMatrix, just to block cosmetic DOM stuff that uMatrix doesn't do) since I need it to be far easier and quicker than that, as it is jn uMatrix.
So switching to nuTensor (a light-touch security/necessary FF updates only sort of fork) has been on my to-do list.
* * 1p-script block
* * 3p block
* * 3p-frame block
* * 3p-script block
* * image block
* * inline-script block
CSS, media can be blocked if it has extension:
*.css
*.webm
*.mp4
*.mp3
*.aac
I don't like gifs, so I used to block it through *.gif, which I'm not sure if umatrix can do.
In uMatrix that's one click in the appropriate column per domain's row, in the toolbar drop-down.
My uMatrix default is all cookies blocked; third-party media, scripts, XHR, frames, other blocked. Of course I often then have to allow some third-party script, and I can do so in one click without also allowing XHR or frames to/from that domain.
uBO doesn't allow that (in the toolbar UI, 'advanced'/'more' mode), because it's missing the columns from the 'matrix', so you either allow/block a domain wholesale.
We all owe a huge debt of gratitude that gorhill is a principled character and has stayed on to guide uBlock Origin all these years.
The developer is a saint, and it just occurred to me that I should donate to their project.
That's a reason why I strictly install very few addons.
VLC should get a special award for not sucking after gaining popularity.
Absolutely. Thank you gorhill!
Thank you so much for your work, Gorhill. I tell everyone I know about uBlock Origin and they love it.
https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b...
UO started blocking or makes a lot of widely used french websites, hosters and services unusable since one or two year. Thus generating lots of requests and taking lots of time. Common webmail functions from french ISP and public services are impacted.
Had sadly to switch back to ABP.
Did you try disabling all uBO filters to see if the issue persists? If you can narrow it down to a specific filter list you can find the rule that is causing the issue and either disable that one rule or, better, raise a bug report so someone can look into what's going on and fix it in the filter list proper.
The state of web browsers is absolute and pure insanity.
Because the maker of your Web browser is funded by advertising money.
This a really interesting point I never considered, but Mozilla isn’t being paid by a ton of different advertisers to not implement blocking - are they? How would we know?
Side note, I would absolutely pay for a browser that rolled everything in without setting it up myself.
Any browser beside Chrome or Firefox seems to only be installed by power users, who also know how to install an adblocker.
(And ABP isn't what it once was, anyway, that's for sure)
To answer your question - it's because the major source of revenue for browser makers is search engines. Google, Yahoo, Bing etc. pay browser maker money to bundle their search engine in the browser, and also share a small percentage of revenue with them. Search engines make money from advertising. So obviously they discourage browser makers from including ad blocking tech in browsers. (Look at the money involved - Google Said to Pay Apple $15 Billion to Remain Default Search Engine on Safari in 2021 - https://gadgets.ndtv.com/apps/news/google-apple-default-sear... ... and you can understand why it is so difficult to say no to it).
Also this accounts a burner so I guess I do fall for the trap but downvote away if you like.
And absolutely insane is a dig at this distopia where we’re allowing advertising companies to drive the technology which would arguably be more valuable than currency.
But sure, off to Reddit I go, just because you don’t like the way I talk.
I’m all for data privacy and freedom of speech, but i also think we need to place revocable trust in other parties to curate our data in a way that improves signal to noise ratios while not impeding on actual freedoms (lest we revoke our trust).
But also browsers should just disable auto play videos they’re damn offensive.
In the case of Brave[1] and Vivaldi[2], it is.
[1]: https://support.brave.com/hc/en-us/articles/360022973471-Wha...
sloccount gives 34516 LOC for the src/js directory. As the sibling points out, you can also verify the code yourself.
Pi-hole should be the easiest for family members, they don’t need to do anything at all.
On most sites, it simply leaves a blank space in where ad supposed to be.
Pi-hole has a nice temporarily disable blocking feature on its dashboard to help in those cases. Simple click to whitelist is also available.
I use a fairly aggressive Pihole list that breaks stuff reasonably often, there may be less strict lists which are “safer” in this regard.
To solve this I setup a Shortcut on her iPhone so she can simply say "hey siri, stop pi-hole" and it will turn off the pi-hole for 5 minutes using a simple web request. The pi-hole turns itself back on after 5 minutes.
A bookmark works just as well but she prefers to use Siri as she never remembers where the bookmark is lol. It is mostly on her phone anyway that something doesn't quite work right so Siri was the best solution.
I also have Wire Guard setup and our phones configured to connect to it always for mobile data and unknown wifi so all our connections are routed via our home internet connection and via the pi-hole. As I have stupidly fast home internet (10Gbit EPON with free.fr) it works fantastically.
I use both but I don't think the network level blocking will work forever.
But to win against “surveillance” you need to make a smart, conscious decision about who you want to give your browsing history to.
For me, I’d rather my ISP sees my DNS, than all that data is sent to some American mega-corp keen to hoover up every last datapoint about me they can.
My ISP can for the most part look at HTTPS SNI field and see all the domains I access anyway. So switching to say, Google DoH, only means that now Google have that list as well as my ISP.
That's a really good description of both Comcast and Verizon. Not so much of Cloudflare though - they seem to actually care about people's privacy.
> My ISP can for the most part look at HTTPS SNI field and see all the domains I access anyway. So switching to say, Google DoH, only means that now Google have that list as well as my ISP.
Isn't this just an argument to hurry up and get eSNI/ECH rolled out everywhere?
Sure Cloudflare are better than those other big US ISPs.
But for those of us in the EU, where such practices are illegal, we may want to think twice about giving our data to Cloudflare (who are subject to requests from US govt for instance.)
And I already use trusted DNS providers (over TLS) so it's not really an issue. My provider can't see my DNS lookups. Also, in the EU providers are not allowed to use deep packet inspeciton so they only know your queries if you use their own DNS.
Hardcoding an IP is really difficult to do for adtech providers for 2 reasons:
1) They usually subcontract to cloud providers that don't guarantee IPs
2) It breaks SNI (Server Name Indication), also heavily used on cloud services
There's better ways to do secure DNS than DoH, like DoT (DNS over TLS)
I like secure DNS but I still want my own server to be the middleman. With DoH this isn't easily possible, especially on mobile due to the root CA issue. DoH is normally implemented using a major player like CloudFlare. Sure, they promise not to look at it. But the phrase "Don't be evil" still is pretty fresh in my mind.
But anyway, it's a moot point. Even if we could block DoH somehow (we can't due to certificate pinning and Android no longer allowing to add a global root CA since Android 7), app providers could just implement their own lookup system or something. Whether we like DoH or not it's here to stay.
Sure, but that's only because your computer can't distinguish your Pi-hole blocking DNS to block ads from an evil ISP blocking DNS to censor you. And if your device supports DoH, can't you just point it to one of the many publicly-available DoH servers, or set up a DoH server on your Pi-hole and then point at that?
> It breaks SNI (Server Name Indication), also heavily used on cloud services
They can just hardcode the IP in the hosts file, not in the client program. Then SNI will still work normally.
> There's better ways to do secure DNS than DoH, like DoT (DNS over TLS)
Then the people who want to do censorship and surveillance will all just block port 853. It's a feature that DoH is hard to distinguish from other HTTPS traffic.
> I like secure DNS but I still want my own server to be the middleman. With DoH this isn't easily possible, especially on mobile due to the root CA issue.
Can't you set up your own DoH server with its own domain name, get a Let's Encrypt certificate for it, then point your mobile device at that?
> DoH is normally implemented using a major player like CloudFlare. Sure, they promise not to look at it. But the phrase "Don't be evil" still is pretty fresh in my mind.
Isn't the alternative that your ISP is definitely looking at it?
Yes. But what’s the angle here? You trust “ISP(s) hosting your DoH server” but not “ISP providing phone connection?”
Might be a legitimate reason for that, but ultimately as with all these discussions it’s just a matter of who you’d rather give the data to.
And your ISP will still be able to see from SNI for the most part so… it boils down to “my ISP can see anyway (via SNI), should I also let someone else see (DoH provider)?”
Your own DoH server could just do the filtering you want and then hand off the work to another real DoH server like Cloudflare's.
> Might be a legitimate reason for that, but ultimately as with all these discussions it’s just a matter of who you’d rather give the data to.
True, but in most of the USA, your ISP is the least trustworthy choice for who to give your data to.
> And your ISP will still be able to see from SNI for the most part so… it boils down to “my ISP can see anyway (via SNI), should I also let someone else see (DoH provider)?”
So let's hurry up and deploy eSNI/ECH everywhere.
Not an issue here in the EU. Alternative DNS is not blocked. Providers sometimes block the pirate bay but they're never obliged to block alternative DNS and they're not allowed to anyway as they're not allowed to do Deep Packet Inspection.
> Isn't the alternative that your ISP is definitely looking at it?
No, this is not allowed in the EU. They can see it if you use their DNS. Otherwise not.
I understand the feature that hiding the DNS traffic among other HTTPS traffic brings, but this is mainly a feature in countries without strong privacy laws. For me I would prefer to separate the traffic so I can control it myself.
And really if I'm in a country with such invasive censoring I would prefer to use a VPN and avoid their prying eyes altogether. DNS is only part of the equation. IP endpoints still tell them a lot. Especially on IPv6 as there's no more need for SNI.
I'm just not sure if it's a good idea to obfuscate core protocols of the internet, just to avoid an issue in certain countries that is not very well solved by this anyway. At the same time I have to give up a lot of valuable statistics, troubleshooting data and validation about whether apps do as they claim.
However like I said I can't stop an app doing this, precisely for the reason it's obfuscated. I won't use it on my own network however.
> Can't you set up your own DoH server with its own domain name, get a Let's Encrypt certificate for it, then point your mobile device at that?
I don't want to bother with getting public domain names and validate their IP with Let's Encrypt just because I want to use them internally. The renewal process is really complex for something that doesn't have a public IP and I don't want to have my internal DNS available on the internet (it also contains local domain names only available on my LAN and P2P VPN)
In fact encrypting that traffic on the local segment doesn't really add any value for me. I just encrypt the outbound part (from the pihole) with DoT.
> They can just hardcode the IP in the hosts file, not in the client program. Then SNI will still work normally.
How would that work? I control my host file. Apps can not mess with it. Not on my computer and not on my phone.
> And really if I'm in a country with such invasive censoring I would prefer to use a VPN and avoid their prying eyes altogether.
Those countries block VPNs.
> Especially on IPv6 as there's no more need for SNI.
I can foresee CloudFlare offering a single-IPv6 shared endpoint for the sole purpose of making eSNI/ECH remain effective.
> At the same time I have to give up a lot of valuable statistics, troubleshooting data and validation about whether apps do as they claim.
Can't you get this information directly off of your endpoint device, whether or not the traffic is encrypted over the network?
> How would that work? I control my host file. Apps can not mess with it. Not on my computer and not on my phone.
I was thinking more about IoT appliances when I wrote that. For programs on your phone or computer, they can tell their TLS library to use whatever SNI you want, so even if they did hardcode the IP in the client program, SNI could still include the right hostname.
Once the system, or network admin would set the DNS servers up and everything on the system would use those. There is no reason why that paradigm couldn’t continue and move to DoH.
The other change is that applications are now bypassing the system-configured DNS and sending requests (and thus data about what you are looking at,) where the application wants. The “centralisation” issue also comes into this. But again, the change from a system-level to per-app setting could happen with regular old plaintext DNS.
DoH is part of the discussion in both cases, which clouds the debate.
By contrast, browser extensions work wherever you are -- at work, in a bus/train, in a hotel, etc.
Ublock origin can block much more content than a pi-hole…
So, use both.
Even if a third-party list you've added blocks something you don't want to block, you have an overriding whitelist.
What am I missing?
( https://blog.mozilla.org/addons/2021/01/20/extensions-in-fir... )
Shows what I know..
If you run into repeated problems you can set permanent rules allowing certain domains. Overall it's a very minor hassle in the scheme of things.
Anecdotally - I've visit only few sites that were totally blocking their work, all of them were piracy related sites.
https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b...
visiting a particular page on the new reddit.com yeilded 27 blocked requests
visiting the same page on old.reddit.com with the same uBO set up yielded only 4 blocked requests
https://blog.mozilla.org/addons/2020/09/29/expanded-extensio...
Alternatively, you can use Fennec F-Droid, a fork of Firefox that supports a "Custom Add-on collection" by default: https://f-droid.org/en/packages/org.mozilla.fennec_fdroid/
I'm not sure why Mozilla is refusing to allow these extensions on the Beta channel, since the WebExtensions support is definitely stable enough for Firefox Beta.
Heck, I can only partially understand the "click many times over crap" to enable experimental features, which should have been _enough_ to begin with (and certainly not a requirement in a beta build). How many hoops do I need?
After reading this, I was really /hoping/ Fennec would remove the requirement of having a Mozilla account, but no, you still need to create an account and an useless "collection".
TBH I use (and ever used) Firefox just due to the available extensions. The value proposition has decreased quite a bit with recent FF versions, and on Android uBlock is pretty much the only reason I stick to it.
I wish I had more alternatives, because clearly the browser duopoly isn't working.