Chrome users beware: Manifest v3 is deceitful and threatening
eff.org
eff.org
I did this as a technology demo, to demonstrate automated site background checking. The concept that you have to have a business address to sell online is almost archaic now, even though it's the law in the EU and California. So, today often the system often can't tie a web site to business records.
The concept of "legitimate business" is dead.
These trademarks can be represented in a domain name or TLD. IP offices that register the marks generally obtain physical mailing addresses for physical correspondence. The crux of the idea is that the domain name and TLD do not have to be issued by ICANN. As such, it does not have to follow any pre-established conventions. Trademark registration systems already have unique identifiers and classifications that can be represented in the domain name/TLD. Thus we can create a new, collision-free naming system that offers more than ICANN, e.g., a direct association to an IP office.^1 This leverages the work of IP offices to collect business addresses (or at least addresses of the registrant's lawyers/agents who would by necessity have the business address of the registrant). Under this system the perceived legitimacy of the business is reliant on the trademark registration, not a "TLS certificate". The legitimacy of the domain name/TLD becomes dependant on the trademark registration, not an unaccountable, known-to-be-corrupt entity such as ICANN. To put it simply, names require an associated trademark. The system favours businesses that want to enable consumers to trace a product back to an original, legitimate source. It is a naming system for real(TM) business. :)
Personally, if I were trying to assess the legitimacy of a business, I would rather rely on the records of a trademark office versus the records of a TLS certificate provider. But that's just me.
1. ICANN of course, to ensure its own profits, chose to allow disputes to occur and create quasi-legal dispute resolution systems instead.
Snail mail addresses intended for humans were the most useful. Although they could be spoofed, that's very rare, and tends to attract legal attention.
Whereas under the new system, the domain names unambiguously indicate trademark-protected names of companies or products, including their trademark classifications. This tells the searcher exactly what type of entity/goods the site purports to describe/offer and the source of those goods. No need for the search engine to second guess what the searcher is looking for.
For example, a name might be formed as something like productX.companyY.classZ. A user could search for URLs with subdomain "productX" and TLD matching "classZ", or a search for domain matching "companyY" and TLD matching "classZ", or perhaps a more broad search for domain under "classZ".
https://bugs.chromium.org/p/chromium/issues/detail?id=115225...
Example of breaking long-runnng classroom extensions used in education: (comment 63) https://bugs.chromium.org/p/chromium/issues/detail?id=115225...
And breaking a simple image picker: (comment 36) https://bugs.chromium.org/p/chromium/issues/detail?id=115225...
I crashed chrome by setting the incognito key to "split", and turns out there's no way to be sure that when you open an incognito page, your extension will be awake. What a mess.
I will postpone the "upgrade" the most I can, then I suppose I'll be forced to write a desktop app and pay hefty licenses to Microsoft/Apple. Google is just ignoring the complaints and the bug reports.
> Manifest V3, or Mv3 for short, is outright harmful to privacy efforts. It will restrict the capabilities of web extensions—especially those that are designed to monitor, modify, and compute alongside the conversation your browser has with the websites you visit. Under the new specifications, extensions like these– like some privacy-protective tracker blockers– will have greatly reduced capabilities.
One would think that the article would then go on to detail exactly what these "new specifications" are and how would they reduce the capability of ad and tracker blockers.
That never happens. We keep getting statements to the effect that Manifest V3 is bad but we're never told what makes it bad.
What aspects of Manifest V3 limit ad blocker capabilities? Since Manifest V3 has been introduced way back in 2019 and, since then, has gone through various changes, are the quotes listed towards the end of the article recent or do they reflect an earlier version of V3?
There was controversy over changes to the WebRequest API but that was two years ago and, I believe, changes have been made. Are there still changes that break functionality? What changes were made over the past two years? Have things gotten better or worse?
The article gives absolutely no details.
Thank you. What you wrote is information that needs to be in the article but is not mentioned anywhere. The closest thing is a quote from Mozilla regarding their extensions security review process.
The whole point is that there would be no reason to allow any ad blocking extension access to the WebRequest API anymore.
The replacement, declarativeNetRequest, does not require the user to give any permissions, so the days of granting ad blocking extensions full access to every page are gone.
If you think Google is doing this for their own gain, I guess you can simply ask if declarativeNetRequest will be able to block all Google ads, or if you really need a turing complete language for that.
From what I see, it also has some strict limits. My basic uBlock+ install has 82780 network filter rules. Chrome seems to "only" guarantee 30000 rules, and I don't know if these match 1-to-1.
And there don't seem to be dynamic replacements, which might be useful to trick adblock detection. Not sure how far in the cat-and-mouse game we are on that front, but I sure don't like the idea of giving the mice highly limited rulesets while the cats can do and do whatever they like.
So if we assume rules are 1-to-1 (and in fact fewer rules should be present in declarativeNetRequest because certain rules like element hiding do not factor into declarativeNetRequest, and would be handled directly by the extension), you could fit ~5 adblocking extensions the size of your basic ublock install, and most of a 6th.
Now there are some advanced capabilities of some adblockers that have no equivalent available, but for common multi-plugin rulesets like EasyList, declaritiveNetRequest will support pretty much everything contained therein, (except cosmetic rules, which the plugin must apply separately, since they are not blocking requests, but modifying the page, which is quite different).
The answer to that is "no". declarativeNetRequest is a more restrictive version of what Safari current supports, and Safari ad blockers don't do as good of a job of blocking Google ads as ublock origin does.
Great, but I want to give my add blocker access to every web page. That's kind of it's purpose.
Sure it could be abused, but not if you used one of the community recommended blockers.
> If you think Google is doing this for their own gain, I guess you can simply ask if declarativeNetRequest will be able to block all Google ads, or if you really need a turing complete language for that.
I am not sure if it will be able to block all google ads. Pretty sure it wont be able to remove their ads from search results, since you wont be able to remove/hide parts of the site. Also it wont be able to remove annoying pop up adds (sure it might remove the content of the ad, but popup will remain - well depending how its implemented.)
Also it is only limited to 30k max urls in a blocker. Nowdays my blocker has 80k+ urls. So i guess I would have to pick an choose (If i continued to use chrome).
Why not? What stops someone from buying (or stealing or co-opting) uBlock Origin and using the fact that it has access to every user's web browsing to do some serious damage?
The WebRequest API’s blocking functions, which are central to the functionality of uBlock, are still slated to be removed.
Seems like a pretty clear case of being two-faced, and a small page laying out the details would be super helpful.
Or that extensions can still inject javascript, observe and log requests, exfiltrate data? I mean the api docs will tell you that. Extensions can do all that because they couldn't do a whole lot without those capabilities...normally used for legit purposes, but the apis can't really glean intent.
See things like onBeforeRequest for observe. Injecting javascript is called a "content script" in chrome extension terms. Exfiltrating data could be done in many ways, given that you can inject a "content script".
It's disappointing to see this sentiment again, as this has been Google's tactic in the past decade: feign innocence and initiate technical discussions, then move goalposts and start over until their opponents are exhausted.
When we first heard of Manifest V3, it took them months to find a ridiculous reason for no longer allowing proper control over requests in Chrome, and they kept jumping between performance, privacy and security, as researchers refuted all their technical arguments one by one.
By now there is nothing left to discuss, they'd just need to stop being malicious.
Heya, do you have any links for that? Haven't really been keeping up with this whole thing. I briefly looked at the Privacy Sandbox proposal page a while back in late 2020 to figure out what it was all about, but haven't really got anything on researchers refuting their technical arguments.
It will impact µBlock Origin negatively for example and I want this plugin to be able to access the page unrestricted.
The entire argument regarding security doesn't mention any of the reasons Chrome developers cite its security improvement, instead it brings up that Firefox "does good enough already" and that malicious extensions can still get past the review process. the review process is by itself improved with V3 as extensions that pull in code remotely can no longer get past the review process[0], especially with how many current extensions implement RCE C&C intentionally. They also say extensions are "usually interested in simply observing the conversation between your browser and whatever websites you visit" - that's 'usually', though; malicious extensions intercepting and modifying requests for their own benefit isn't unheard of.
Instead of only stating 'this is bad', it would be beneficial to include both (A) what they say (B) their basis for the decision, if any (C) why that line of reason is incorrect/deceiving.
0: https://developer.chrome.com/docs/extensions/mv3/intro/mv3-o...
Docs: https://developer.chrome.com/docs/extensions/reference/decla...
(Disclosure: I work on ads at Google, speaking only for myself)
If you're going to argue this is better, don't point us to such a clearly worse result.
[0]:https://github.com/el1t/uBlock-Safari/issues/158 [1]:https://adguard.com/en/blog/safari-adblock-extensions.html
It is not a question that V3 breaks the gold standard privacy protecting extension.
Therefore, it's not just about changing the mechanism, the end result is clearly a lot worse. One can say, they crippled ad-blocking which this change. Hopefully, once the millions of people using ublock origin start noticing what's happening, they will move away from Chrome. I already did, ublock origin is worth more to me than any feature Google puts in Chrome.
I understand the average user probably shouldn't be able to easily hand over so much control to extensions, but on the other hand, dynamic ads shouldn't be able to serve malware or cryptominers.
I'd be a bit more open to the idea of a locked-down manifest if we had seen more good-faith attempts from AdTech to change the paradigm that makes content blockers almost a requirement.
> I work on ads at Google, speaking only for myself
I'm doubtful about a person's ability to speak for themselves, when they have been consistently defending their employer on HN for years, at every occasion they got.
Today we know AMP was also a anticompetitive plot to kill off header bidding.
Why should we to believe a word of what Google says about Manifest v3?
I completely disagree, and I think this will become clear as information continues to come out.
I don't expect anything that comes right out and says something like "we must implement AMP to as a strategy to remove competition from header bidding". Instead it will mostly be just the standard talking points about user experience and load times.
I could be wrong though: plenty of things have been revealed in things like text messages where people don't think of them as being part of an official record.
In this case, it appears that multiple large orgs are involved: G and M. One provides the environment and the other appears to have dropped their drawers and crapped in it but in the end a telephone should always be able to make emergency calls regardless of what is installed or configured on it.
In the end this sort of thing might look like lack of responsibility due to arrogance due to lack of competition. I'm sure other interpretations are available.
Normally the above should be considered an example of whataboutery but I think your response deserves little else. If you have something to contribute then please do but not that sort of thing.
(1) https://www.theregister.com/2021/12/09/android_911_teams/
[Edit: weird formatting snag, content unchanged]
So if you weren't asked to, you're just astroturfing voluntarily. That's not better, it's worse: If one gives up one's integrity, one should at least get paid for it. Otherwise, one isn't acting just scummily, but scummily and stupidly.
This is somewhat debunked in the article of this post.
> the change is that it's now declarative.
In the App MANIFEST. To my understanding, each update of those lists will require an app update (going through Store approval process).
If only it would have been dynamic, the end result would have been much better.
And again, there is no reason to disable dynamic updates if they are only lists of blocked URLs.
Those serious "serious tradeoffs" made me completely stop using the web on my iPhone. Yeah, Safari content block can block roughly 80% of web ads, but those extra 20% are extremely annoying.
Web owners use all sorts of trickery to bypass adblockers and serve malware filled ads. Handicapping our current best defense tech against this is a sure as hell way to make me never open chrome again and completely purging it from any friends and family computer.
This is true, but I think overly performance-focused. It doesn't feel like that much time, so I think there's a valid complaint that it doesn't make sense to kneecap flexibility for speed.
> more private because an ad/content blocker doesn't need to be given such broad permissions
Sure, but this doesn't seem like the only possible solution for the people that own the browser. Why not only allow a restricted subset of JS that lacks any form of IO? Or if that's impossible/risky, why not something like Starlark or Lua?
I think this is based on a fundamental misreading of the problem. The privacy concern is that your data will leak, not merely that it's accessible to a third party. The cat binary can read my data, and I'm not at all concerned about that. So can my shell, and likewise on the concern.
Privacy doesn't necessitate this solution. It is one of the possible solutions, but I think is hard to sell as the best solution to the problem. It is likely the easiest.
Specifically, "we have decided to implement DNR and continue maintaining support for blocking webRequest. Our initial goal for implementing DNR is to provide compatibility with Chrome so developers do not have to support multiple code bases if they do not want to. With both APIs supported in Firefox, developers can choose the approach that works best for them and their users."
https://blog.mozilla.org/addons/2021/05/27/manifest-v3-updat...
[1] I am well aware that was not the original context of the quote, but it's a nice rallying cry of the sentiment behind the movement.
I didn't see dissecting the security details as the point they were trying to make. Instead it was to partially undermine the reasons Google said they were doing this.
Basically "here's why it's bad for privacy, and here are why Google's stated reasons for the update are insufficient to justify that"
It seems like this is the clear interpretation of what I wrote and that you may be purposely misconstruing my comment in order to level a soft insult and condescending language at me over an opinion you don't agree with.
To give you a little benefit of the doubt though and assume you may just be passionate about the issue and don't intend to be insulting I will address your other point: Users giving away access to their web requests without realizing it is a problem. It is also one that can be addressed without making it much harder for privacy-minded users and the providers of those extensions to get what they want as well.
After manifest v3 it will be worse off.
Ublock origin provides a lot of privacy benefits, so people like me are 100% worse off.
Well I switched to Firefox, only really use chrome for testing nowdays.
What Google says vs what's going on aren't necessarily the same thing, they have a long history of selling us the 'for your convenience' line while removing functionality that people depended on but that ultimately hurt Google's business interests: to be able to force feed you more ads.
They have long outlived their credit in the bank of the benefit of the doubt.
Installing random plugins is a security issue. But web tracking is by far the more significant threat.
When Google says "pull in code remotely" they dont mean from a remote server. Instead its 'code remote to Google' aka code you wrote yourself sitting on your hard drive. This kills greasemonkey/tampermonkey and all the other UserScript extensions. Google saw how great Apple is doing and fell in love with the concept of walled garden. Its their browser and they wont let you execute any code that wasnt approved by them.
User Agent no more, Its Google Agent now.
To say browser extensions pose a risk is true, but it hardly makes it in the top list of threats anymore. Malicious sites however still do and Google just restricted our ability to let third party tools provide essential services. Sure, these could be malicious, but that is generally not a wide spread IT problem of today. That should be also obvious to Chrome developers.
Accidentally they also restrict ad blockers? Come on, you are getting played.
Quoting from this update [1] from Mozilla:
> Google has introduced declarativeNetRequest (DNR) to replace the blocking webRequest API. This impacts the capabilities of extensions that process network requests (including but not limited to content blockers) by limiting the number of rules an extension can use, as well as available filters and actions.
> After discussing this with several content blocking extension developers, we have decided to implement DNR and continue maintaining support for blocking webRequest. Our initial goal for implementing DNR is to provide compatibility with Chrome so developers do not have to support multiple code bases if they do not want to. With both APIs supported in Firefox, developers can choose the approach that works best for them and their users.
> We will support blocking webRequest until there’s a better solution which covers all use cases we consider important, since DNR as currently implemented by Chrome does not yet meet the needs of extension developers.
[1]: https://blog.mozilla.org/addons/2021/05/27/manifest-v3-updat...
The problem is that orgs and companies stop caring once they gain the primary market share. They also start dictating standards to everyone and ignoring user feedback. It's symptomatic of our current software development driven economy.
I recall when as a web dev I had to ensure my code was best supported by 3-4 browsers and don't miss that era at all, but it would be much better if proper regulation, consumer protection, and ethical corporate behavior came into play before hostile competition, corruption, and monopoly-driven "dictatorware" do in software market dominance for a change.
1. History of installing and running arbitrary code on clients in the name of "Experiments" without user permission.
2. Full telemetry on by default.
3. Shoving their products like Pocket (added to the address bar by default, shows up as an advertisement on the page that opens after Firefox updates itself), Mozilla VPN (non-removable advertisement on every Private Window you open) in the name of revenue, while their clueless leadership enjoys fat paychecks for whatever value they bring to the organization.
4. Forcing undesirable changes down people's throat (removed the "Compact" density address bar after a redesign, hiding it under about:config).
Feel free to pile on.
5. Ignoring any and all negative feedback.
6. Taking more and more control away from users.
7. Being funded by their competitor and never really looking for an alternative.
8. Firing a good chunk of their engineers when needed most.
Final straw was the dedicated search bar not working with keyword shortcuts for other search engines. While the settings page claims those are supposed to work in the address bar and the search bar, they only work in the address ("omni") bar.
Too many features removed. I'd rather just go to my native browser and all the inherent advantages to it at that point, which as mentioned is MS Edge. I love it. In fact, their unnecessary additions (MS Shopping) actually opened my eyes to things I didn't know existed, like the Honey extension. I have no complaints about Microsoft Edge on Windows 11 or iOS. After 19 years of Firefox.
Browsing the internet would be an extremely bad experience for me if I just relied on a DNS sink.
Count:Type:Blocked Domain
4154:DNSBL_A:browser.pipe.aria.microsoft.com; 445:DNSBL_A:googleads.g.doubleclick.net; 421:DNSBL_A:www.googleadservices.com; 414:DNSBL_A:app-measurement.com; 356:DNSBL_A:in.treasuredata.com; 283:DNSBL_A:incoming.telemetry.mozilla.org; 254:DNSBL_A:reports.crashlytics.com; 239:DNSBL_A:config.inmobi.com; 146:DNSBL_A:telemetry.sdk.inmobi.com; 125:DNSBL_A:www.googletagmanager.com;
I find those leftover empty spaces extremely annoying. Imagine being interrupted by a big portion of nothing in the middle of an article. uBO hides those empty spaces as well.
And no, I don't use or like Reader Mode. It's yet another click I need to do to just read an article.
> Finally, scripts are blocked from even getting loaded - e.g. stats for the top scripts blocked today (2 hours in) for me:
That doesn't look like individual script blocking to me, you're just blocking domains. If the script you want to block is part of the first party domain itself, you can't just block it using a DNS sinkhole.
At this point, I'd go as far as to say that a web browser which doesn't support the complete capabilities of uBO, considering things like CNAME tracking exist, is a user hostile web browser. This includes all Chromium based browsers.
https://blog.apnic.net/2020/08/04/characterizing-cname-cloak...
I pay for IntelliJ so why not pay for the just as important browser if I can get one that I like?
Just don't increase the pricing to Jetbrains level until you have Jetbrains level features.
It might be great but for now refuse to support anything that further strengthen Googles grip on the market.
The question then becomes: "What else even is out there?"
Because if you're looking for something that's even remotely feature complete for browsing the modern day web, the majority of the current browsers out there are indeed based on Chromium, as expressed in this article, "Firefox is the Only Alternative": https://batsov.com/articles/2021/11/28/firefox-is-the-only-a...
Here's the table from the article in text format:
Browser Based on Chromium Open-source Market Share (desktop + mobile)
Chrome Yes No 64.7%
Chromium Yes Yes -
Edge Yes No 4.0%
Brave Yes Yes -
Vivaldi Yes No -
Opera Yes No 2.4%
Safari No No 19.0%
Firefox No Yes 3.7%
To me it seems like Firefox is the only viable alternative and putting all of our hopes on a singular browser and the company behind it, especially given that there has recently been some controversy around it, seems risky. For example: https://itdm.com/mozilla-firefox-usage-down-85-but-why-are-e... and https://arstechnica.com/information-technology/2020/08/firef...Today, Google and Microsoft and Apple are fighting Browser War 2, and it looks as though Google is winning. However, Firefox is still fighting, but not to win. But to prove that we don't have to put up with the monopolistic behavior of Google to browse the internet.
Firefox has had it's ups and downs. But "winning the war", in my mind, isn't the point of Firefox.
It is an open-source project fighting a good fight, and the only one at that.
Vivaldi always seemed to hold the most promise but was buggy for me and still missing strong iOS integration that the competition has in place. Having used FF for so long, I was ready to go to a larger provider. So mainly, MS, Apple, or Google. Native browsers have big advantages so resisting those no longer made sense if I'm making a switch.
But Brave in my testing, did not completely convince me. Reviewing my testing notes-
Brave- no dedicated search bar option (important for privacy / prefetching and not having to continually retype your search query). Didn't get to mobile support and crossplatform sync. No dedicated extension store.
Of course, I had to give up on my dedicated search bar requirement, because FF's has been gimped by Mozilla, and Vivaldi had other unrelated usability flaws. So Edge it has been, and being completely honest, I've been thrilled with it. There's plenty other good here to overlook that and I haven't missed it as much as I thought I would.
All that said, I'm now going to keep Brave in mind, moving it up a notch. I always liked Eich which doesn't hurt. I don't fear a Chromium world, and never used FF because it wasn't, in fact I mostly resented it. I just don't see eye to eye with the anti-Blink crowd.
I think Firefox should've morphed into Brave, rather than be a separate project. A Brave that has Vivaldi's feature set would be perfect. Only thing missing then is major vendor support, and it'll always be non-native on all platforms, but at that point it could be overlooked.
For Firefox to fight its way back will require more than anti-Blink monoculture advocates supporting it. Blink has become the same as the USD, and isn't to be feared. For me, that's like saying you're resisting using the US Dollar because you don't want monoculture. Yet look at how much you can do with the USD. It enables quite a bit, embracing it just enables you to get other things done with less resistance. Users benefit. More important missions are at play. Like perhaps privacy, transparency, both things that Brave clearly focuses on. Or whatever one's chosen priorities are.
I legitimately love MS Edge, and I always keep Tor installed for the best privacy, but Brave is now my #2 pick for a daily driver and will be advocating for it for those that don't want to use their native browser.
When I switched to Vivaldi I felt like it's 2003 again, and I've just switched from IE to Firefox. Every single thing Mozilla removed from Firefox over the years is here, and most of the stuff I used hacky addons that would often break is here too! In the core browser, as first-class features, without the need to fiddle with userChrome.css or look through obscure flags. It really is a breath of fresh air and it puts into perspective how many excuses I've made for Firefox over the years. It's not worthy of being my browser, simple as.
Mozilla took my fundamental addons that separated Firefox from other browsers, they took my RSS reader, they took my cool Torrenting and Email clients that were a part of the browser itself. The TreeStyleTab requires you to go through obscure and hidden config files that often break with updates and the extension itself is not stable and fiddly. On top of that, I had way more Firefox extensions that aren't even different from Chrome extensions in major ways. In Vivaldi, I just get a nice panel with RSS, Calendar, Translator, Email client, Notes, whatever I want! The adblocker is built-in, the privacy features are built-in, you even get to put your tabs wherever you want. It has theming support that is as good as Firefox Colors, and it has custom search keywords that replace DuckDuckGos bangs for me more often than not. It even has the dark mode among other page filters, a screenshot tool, web page tiling! All the things that would turn my Firefox profile into a slow extension pile that barely works and longs for death.
Mozilla's "goals" of removing key features meant for people who actually would want to use a "google alternative" are laughable, and it's as bad on "privacy" axis as Chrome is because you have to use something like LibreWolf to get the actual privacy from it, very much like you have to use ungoogled-chromium with Chrome. If they think that turning the browser into a Chrome clone with some bumper stickers that say things like "Proud not to use Blink" and "We do say privacy a lot", then it's already dead to me.
Vivaldi also has an amazing history page.
Vivaldi generates revenue from partner deals with search engines. Every time you search using one of the pre-installed search engines, you’re helping us grow, one search at a time. Currently, we work with DuckDuckGo, Ecosia, Startpage, Yahoo!, Bing, and Yandex. The only exception is Google – we don’t make money when you search with Google. However, we know that some of you use this search engine daily, so we include it in Vivaldi.
(Source: https://vivaldi.com/blog/vivaldi-business-model/)
The other other source of revenue is bundled partner bookmarks (see again the linked document).
Not affiliated in any way, just thought if someone wanted to, they might donate.
As for privacy containers - you can easily switch profiles in Vivaldi. It's not integrated to the same degree where you'd get tabs from many profiles in one window, but it works for me. If you like Firefox Containers you should also know that, ironically, unlike Chrome Firefox doesn't have proper site isolation. [0]
[0] https://madaidans-insecurities.github.io/firefox-chromium.ht...
It was never the point of Firefox to offer them. Firefox originally started to be the slim alternative to the fat Mozilla suite.
> The TreeStyleTab requires you to go through obscure and hidden config files that often break with updates and the extension itself is not stable and fiddly.
What are you talking about? TST is very stable since years now and except for hidding the original tabbar, there is no need for using any config files. And even this is a stable setting which barely change every some years or so. Obviously, the first months in their transition to the new extension-system TST and Firefox were quite unstable and busy with filling the missing gaps. But that was 4 years ago. There still are some features missing, mostly for comfort, but it has settled down now and is very stable now. And still better than anything other browsers have...
Not OP, and unlike him still use Firefox but:
I lost a lot of functionality/workflow that I depended on. It worked one day until Mozilla deliberately made it not work.
It pisses me even more because it made that decision to be more like Chrome. If I wanted to Chrome I would just use Chrome.
If you don't see why people like me are upset when thing like this happen, we will just have to agree to disagree.
EFF doesn't want to give you the other side of this story, because they're not an honest interlocutor.
If you had the other side of the story, you might still think Manifest v3 was a bad deal. Random ad blockers are very dangerous, but there are ad blockers that everyone trusts, and you might not want to make it harder for them to maintain their projects.
But EFF doesn't trust you to make that decision on your own.
We are constantly handing over power to big tech in the name of security, and they inevitably end up using that power against us.
Yes there are shady actors out there, but that doesn't mean we have to give the tech monopolies a monopoly over what are the capabilities of the internet and who can be trusted.
Speaking of reputation EFF has been doing this shady speak for last few years and my respect for them is quite diminished. I suppose they can still do it because they have practicality a monopoly to "protect privacy online" with Apple being a distant second player.
What have they done this last year to change? Is there another organization you could recommended supporting?
Safari only allows extensions installed via the apple store, but every single adblocker there is a scam.
I'm not kidding you, I audited most of them. Chances are it's either a three years outdated list of adblock plus that doesn't catch anything or it's an extension that replaces all google analytics identifiers with their own to make money (even when it's a paid extension).
The only thing worse than Chrome is Safari at the moment. And Apple doesn't give a shit about anything there, I reported the malicious extensions to no effect at all.
So when thinking of the other side and "removal of choice" I don't have a healthier, audited ecosystem in mind...I have Safari in mind, which right now is a worse attack surface than IE6 back in the days when it comes to Privacy or Security.
Malicious extensions (as answer to comments). DONT install any of them, as I think they're scamware.
[1] AdBlock for Safari and Adblock for Mobile, which is an outdated AdBlock Plus fork: https://apps.apple.com/de/app/adblock-for-safari/id140204259...
[2] AdBlock Plus (which is the same scam model as other eyeo GmbH products): https://apps.apple.com/de/app/adblock-plus-f%C3%BCr-safari/i...
[3] Stop Ads https://apps.apple.com/lu/app/stop-ads-der-ultimative-ad-blo...
[4] 1Blocker https://itunes.apple.com/app/id1107421413
[5] Wipr doesn't do anything, literally https://appsto.re/us/thAB9.i
[6] Ad blocker https://apps.apple.com/de/app/ad-blocker-remove-ads/id153692...
I updated my previous comment with more details, hence the comment was written on mobile initially.
Unless they didn’t test everything or were exaggerating that is.
Unless you were exaggerating and actually don't use MacOS or Safari anyways.
And now you’re calling me a scammer for criticizing your statements…
As somebody currently using Wipr and not seeing any ads, would you mind bridging the gap between your assertions and my reality? Genuinely curious how we could be truthfully so out of step on this.
Explain yourself, or are we supposed to take your word for gospel?
Not gonna waste more time on this tbh, as I'm building a competition to those products. If you don't believe me, stay in your walled garden. I've given you hints, start checking them for yourself or don't.
If I would post screenshots of MITMProxy, Little Snitch or something else, people would try to discredit them as fake anyways.
There's no need to be so confrontational. You made the claim, you'll probably be asked to show the technical reasoning behind your statements on a forum called Hacker News. But since you're working on competition, it's in your best interest to discredit similar products.
> If I would post screenshots of MITMProxy, Little Snitch or something else, people would try to discredit them as fake anyways
Sounds to me you're not prepared for people to show you might be incorrect. Honestly, I never doubted your position, I just wanted clarification for my own intellectual gratification. But you sound really defensive for some reason.
(By the way, I do not work in ad-tech nor in ad-blocking tech and I have no stake in anything slightly related to the matter at hand.)
Much better to waste everyone else’s time, right?
But neither does google on the other hand, and they're the ones that can actually do something more about it than writing a blog post.
That's kinda what we are paying them to be, no?
Google is just a for profit company.
Switch to Firefox.
* Chrome destroys ad blocking
* Advanced users now suffer the same internet as everyone else
* Advanced users will find a solution, and that solution can't be chrome anymore
* This starts an exodus of advanced users .
* Advanced users configure the browsers for everybody else, hence everybody else also joins the exodus
The end result is less of a monopoly.
This is the same mechanism that ultimately killed of IE and moved everybody to chrome: The monopoly of the time got so arrogant they didn't listen to their users, so users fled to a better alternative.
The strange thing is, groups of people have more or less the same tolerance for abuse, know their limits have already been violated for a while, and learn alternatives from each other. As a result, It takes a long time of abuse to trigger an exodus, but when it started, it starts everywhere at the same time. Then the abuser tries stopping the exodus by rolling back only the last change, but that's not enough anymore.
Hopefully someone will decide to come up with a totally new browser. I remember times when BitKeeper told Linus that they will somehow try to charge for using their tool to keep Linux kernel source code (can't remember the story, but they managed to irritate Linus, delicately speaking).
Linus sat down and started coding... and created Git.
Unfortunately browser is a more complicated piece of software, but maybe this is also a problem we should solve.
The enormous complexity of browsers these days makes this almost impossible.
A better solution would be for Mozilla to direct all funding directly to Firefox and try to find other ways to monetize the browser.
Brave is trying one approach but now they are also tied to the underlying Chromium engine. I am not sure what the effort will be like to try to maintain a fork that ignores Manifest v3.
As long profits from Firefox does not goes back into developing Firefox, a monthly subscription wouldn't change things.
And if you're a webmaster, add some crippling/inconveniencing logic if user agent equals chrome.
Yet I oppose your suggestion. Lets be above that.
> Google throttles the load time of non-AMP ads by giving them artificial one-second delays in order to give Google AMP a “nice comparative boost.”
The worst privacy offenders are ad trackers and I don't think it has to be explained that Google has an interest in putting constraints on them. How much that influences Manifest v3 is everybodies guess of course.
But your framing is dishonest as Manifest v3 does take away user choice. A choice that allows you to install bad addons with all the implications. But turning that around and saying the EFF tries to take away choice is just false in this context.
I also fail to see hyperbole, I think this is the usual relativization that puts users in a worse spot than before.
> EFF doesn't want to give you the other side of this story, because they're not an honest interlocutor
And who would that honest interlocutor be in your opinion?
The best and most user oriented ad blockers will be affected by this and this is the actual security issue here. No other scenario comes even close.
Technology changes means nothing without outcomes, or else it is just changes to electrical potential of positive and negative state. If extensions like uBlock Origin are crippled or forced to leave than the outcome is crap, which is what occurred when safari did a similar "step in the direction of privacy, security, and performance". I wonder if google was aware of this when making the decision.
The answer to "Random ad blockers are dangerous" is not: Let's cripple all adblockers to safeguard our "users".
The obvious answer is create a review process similar to what Firefox did. Maybe Google should use some of their 0.0001% annual income to contract a full time review team to protect us against rogue extensions.
I think an honest interlocutor would look at what's behind Big Corp double speech:
Google: Protect ad-revenue while pretending to protect users.
Apple: Protect Apple against government pressure while pretending to protect the children.
Apple has normalized the "we know better" approach, and has enjoyed great success doing it. Google is simply following that same philosophy. They know better than you, what's good for you and what's bad.
We need a fully independent browser, open-source, and built on modern technology. That way, users who care about this can get what they want. And users who trust Google to get it right, can use chrome or one of its derivatives.
Firefox has (had?) that potential, but for whatever reason Mozilla seems unable to execute effectively. The result is that Firefox has become a follower, doing the same things Chrome is doing. Thus defeating the original motivation for users looking for an alternative.
Brave looks promising, but given that they build on top of chromium, I am not sure how long they can resist fundamental changes in the codebase. Or whether they even intend to provide the needed alternative.
All in all I feel this represents a sorry state of browsers, and consumer software in general.
I don’t understand why Firefox needs to adopt Mv3 for “cross-browser compatibility”. Is this to save extension writers time and effort or is it a mistake in the article?
Some of the extensions I maintain will no longer work, or have reduced functionality for no acceptable reason, and some of the projects that I have been preparing to release have now been abandoned, because they rely on having proper control over requests in the browser.
At some point they disliked something in our extension that had been live for months, and disabled every release in the past year. At another point they found something wanting in a 2 year old release (not a recent one) and threatened to remove it from the store, our attempts to continue that conversation or just allow it to be pulled to save everyone some time met with crickets.
I really want to like firefox but I hate it more with every release.
It is just - for me at least - not lovable anymore.
As the developer of extensions that are impacted by Google's anti-competitive actions, you can report how this impacts both you, and the market as a whole, to the competition and antitrust divisions of the government. I've posted links to forms and sites that you can use to report to the relevant state-level and federal-level regulators on HN here[1].
If you aren't in the US, the US also has antitrust legislation that applies to US companies operating in foreign countries, as well as a myriad of antitrust treaties and agreements with other nations. It might be worth it to also report it to the government of the country you reside in, as well.
I used a ton of very useful extensions then. Nested tabs were one of my favorites. These days I've got a password manager, a bookmark checker, and a tab manager I wrote myself.
They're just not allowed to do anything too useful these days - I know what they have access to, I write Chrome extensions. A lot of them should just be standalone desktop apps.
Like most things, normies came in, shot themselves in the foot, made a fuss, and now we can't have nice things.
Case in point: With some limited maintenance and a compatibility shim for loading them, a number of old add-ons are still working on current Firefox versions: https://github.com/xiaoxiaoflood/firefox-scripts/tree/master...
It's written to be extensible/introspectable, and the extension language is Common Lisp.
Extensions systems which don't have very clear cut boundaries like XUL are just add a very hefty maintenance burden and make review extremely hard.
It's not really about "normies".
This doesn't really apply to the current change, as extensions already have clear boundaries and and as the article pointed out problematic apps likely won't be too much affected as they often already do things which bypass the constraints to avoid detection by the reviewer... (assuming I understand the topic correctly)
If adblockers (and other classes of legit and common extensions) can be migrated to a safe API, it makes the unrestricted and dangerous API much more manageable since what's left is much less likely to be legit or something people actually care about. For example you can have enhanced review processes, warn users more forcefully about the danger, start limiting the power of the API, implement new safe APIs for some of the remaining use cases, etc.
EFF are smart people. They know what the actual security benefit is, and choose to instead argue against a caricature.
How is that scary?
The browser by definition has unlimited access to read and modify (and monitor) anything I do in it.
And I trust gorhill a million times more than any Google employee, past, present or future.
How much do you think NSO Group would pay for this kind of access?
If you ran uBlock Origin, would you like to retire early?
Jbk from the VLC project has a lot of stories about turning down 6, 7 figure payments to bundle malware in VLC. Not everyone has the strong morals and unlimited stamina to withstand that.
Manifest V3 is created to solve a real problem. I have had browser extensions go rogue on me before (Stylish), and i would like it to not happen again. At the same time, uBlock Origin is a hugely important extension for making the web usable for hundreds of millions of people. A compromise must be found that moves their safety out of a single person's hands.
The only real complaint is that Chrome did not anticipate how large these lists need to be in 2021, and the limits are too low.
Not sure if it removes the ability for the user to on-the-fly add any blocking, but I suspect it does.
Use Stylus (https://addons.mozilla.org/en-US/firefox/addon/styl-us/) instead.
I think browsers should be moved away from for profit organizations to separate non corporate stewardship. With that you remove the overall susceptibility to fallout and can try to give more freedom over the features a browser has or how deeply extensions can integrate, for everyone. You also obviously remove the immediate monetary incentive to restrict freedoms.
If I was truly insane I'd go the Steve Gibson route and write a completely different browser from scratch. I'm aware it would take the rest of my life (or longer) at this point but the engine options are so few, and the ability to avoid the owners' restrictive BS limited enough, that I'd be happy as a clam to see a whole new reboot.
I'd jump onto even an alpha of that, just to bump numbers out of hope that ANY group could get together and get out from under the advertising trap.
I should not be able to write a JS popup that looks like a browser dialog - that would be a pretty good start to improving security of the platform. Instead they remove the APIs that run the ad-blockers. Then give the MAIN APIs used by scammers/ad networks to deanonymise, track and trick you, free access to your system without your agreement.
Talk about having your cake and eating it too. Its Prohibitionist rhetoric all over again.
Sure, but Manifest v3, doesn't have such API. It has a very limited API, that can't do a lot of things uBlockOrigin does.
I am not even taking about way too small limit for filtering (30k urls, my current are at 80k+)
I mean in manifest v3 you can't hide various banners or fullpage overlays and similar. That to me is one of the more important parts of what uBlockOrigin does for me.
So at best I will get half of the functionality (that is if google raises the limit)
> EFF are smart people. They know what the actual security benefit is
yes. Chrome with manifest v3 + uBlockOrign (assuming we even get it for v3), is less secure than chrome with manifest v2 + uBlockOrign
EDIT: Almost forgot. You also cannot block, adds on google search, any more.
Can't wait, but that's a very good opportunity for Firefox as Firefox will become more powerful than Chrome
https://github.com/MicrosoftDocs/edge-developer/blob/main/mi...
They recently baked in a "feature" to hijack online shopping with some Pay Later garbage:
https://gizmodo.com/microsoft-keeps-making-its-edge-browser-...
Now they're running gross little popups if you browse to the Chrome installer in Edge:
https://gizmodo.com/seriously-what-is-going-on-with-microsof...
> “Microsoft Edge runs on the same technology as Chrome, with the added trust of Microsoft.”
> “That browser is so 2008! Do you know what’s new? Microsoft Edge.”
> “I hate saving money,” said no one ever. Microsoft Edge is the best browser for online shopping.
A bit tit for tat in my book.
From that viewpoint, the new restrictions could actually be a good thing.
Certainly nothing firm as far as it looks, but at the very least they're thinking about it, even though that change is somewhat problematic, too.
I’d suspect a majority of users isn’t even aware that browser extensions are a thing.
Google is cutting down on the extensions ability to read and modify your web requests on the fly. As a side effect adblocker type extensions need to pass their blacklist patterns to chrome which will enforce it on their behalf. Chrome cites improved privacy because users won't need to give random extensions full read write access to pretty much all their online activities and performance gains because arbitrary adblocking code cannot run anymore and it needs to be in form of a blacklist patterns. Lastly Apple Safari has been doing the same all along.
The opponent arguments (expressed in the article and by many people leaving comments here) are that this kneecaps some AdBlock extensions because they need to run arbitrary code as the declarative API is not flexible enough for them and this is part of Google covert plan to kill adblocking.
I personally agree with the Chrome team's argument here
Given that one of the biggest performance hogs are the ads and tracking scripts on a page, the argument for performance seems sketchy too.
I don't use adblockers myself, as I actually like seeing ads, but Google's arguments are very weak here.
I've learned of a new kind of people today. What about the "ad experience" do you like?
https://github.com/w3c/webextensions/issues?q=is%3Aissue+is%...
First, there's the risk of Chrome Web Store simply not being available to non-Chrome flavours. Next, the extensions APIs and ecosystem could head in any direction Google wants.
I use about 6 extensions, 3 of them self-compiled and sideloaded (JSON Viewer, Dark Reader, Violentmonkey).
I wish services like Pushbullet would open-source their browser extension. Isn't all the secret sauce on the server-side anyway?
A few others, including myself, were like... um guys, this browser is created by a company that makes its money from advertising that shows in browsers, do you really think this is going to turn out well?
So, what's the alternative here? What can people actually do to improve on things?
Chrome is hard to get away from!
The google of old might have been OK, but at this point its as tedious to hear that they are "responsibile" as it was to hear that Microsoft Windows was "more customizable" than a mac and therefore somehow better. (I still know a lot of so called geeks that are ms fans for this reason).
A generation of socially unaware engineers got too popular and laid the groundwork for a behemoth that we let get too large...
Don't worry, FAANG still exists and is a major problem, the lesson shouldn't be that we need another player, just that monopolies, or things approaching them like big business, are always bad.
Thank you to the author for getting to the point: conflict of interest. Google cannot represent ("protect") users and sell to advertisers at the same time. No amount of blog posts/marketing/propaganda/arguing in forums can change that. Advertisers are paying Google for services, users are not. Google's entire racket has become heavily dependent on these conflicts. Google believes it must gain/preserve "user trust". Google wants users to believe it is on their side. That is what con arists must do.
Remember when other browsers announced they would not adopt FLoC. Websites also announced they would disable it as a courtesy for users through use of the Permissions-Policy response header.
https://wordpress.org/support/topic/add-interest-cohort-to-p...
https://github.blog/changelog/2021-04-27-github-pages-permis...
https://paramdeo.com/blog/opting-your-website-out-of-googles...
https://scotthelme.co.uk/what-the-floc/
DevTools still warns this is an "unrecognised feature". Does interest-cohort=() even work. Perhaps it does but in some jurisdictions FLoC is enabled by default in Chrome. The user has to manually disable it. Assuming the user evens knows what it is.
https://github.community/t/i-have-no-idea-what-the-interest-...
I found the CFTC, for example, has a nice usage of the Permissions-Policy header, better than the Guardian.
www.cftc.gov
permissions-policy: accelerometer=(),autoplay=(),camera=(),clipboard-read=(),clipboard-write=(),fullscreen=(),geolocation=(),gyroscope=(),hid=(),interest-cohort=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=()
www.theguardian.com
permissions-policy: camera=(), microphone=(), midi=(), geolocation=(), interest-cohort=()
But really, how much can anyone rely on something like this. Users have no meaningful control over this browser. It is changing all the time, and "features" are tested on different groups of users, without ensuring their informed consent. Sure, a user extension may work now, but whether it works in the future is not within the user's control and, most importantly, Google's interests and the user's interests are almost certain to conflict.
"Google's efforts to limit that access is concerning, especially considering that Google has trackers installed on 75% of the top one million websites."
I have learned to enjoy blocking Google's incessant attempts to phone home. Google is curiously obsessed with TLS, so substituting a self-signed certificate for Google websites can actually be one of several ways to stop these connections, letting them fail at the proxy. It seems Google really does not want users to see what data Chrome is trying to send to Google. I wonder why.
Someone recently showed me an interstitial page they got while logging into Gmail, asking for their date of birth. It was very deceptive. It asked the user to "help us comply with the law" or some such. Of course, it was optional (the cookie had already been sent and the user was already logged in, unbeknowst to her) but there was no indication to that end. It appeared to be mandatory. The user was led to believe she could not proceed without entering a date of birth.
A company with millions in cash reserves behaves like con artist who cannot get a real job. It is impossible for me to take this seriously as business. A massive con. Yes. An honest business. No.
Make the new manifest optional.
Point out that malicious extensions keep using the old manifest (which is more powerful and allows far more evil things).
Allow web developers to set a "disallow less secure extensions" http header. That allows banks and stuff to ensure an insecure old-manifest chrome extension isn't redirecting all your funds to North Korea while you do online banking.
Before long, ad networks will realise that setting this header nerfs adblockers too.
Most of the web will set the header to get more ad revenue.
In the press, it will be the evil people misusing the secure header rather then Google's fault.
I know websites track me. I know I get tons of ads. I know websites popup questions about cookies. I know they play videos that follow me around when I scroll. I know sometime in the past that shit would've been under my control. But I suppose I have rose-colored glasses on and that's just the way it is. After all, I remember blink tags.
Going forward extensions in the Chrome Web store will have to use Manifest v3. Which has less capabilities than previous version. Which will stop ad blockers working.
tl;dr. Ad blockers will not longer be possible in Chrome.
This is not completely true. Ad blockers like uBlock Origin that allow specific elements to be picked and blocked wouldn’t be allowed. All the requests (like ads) to be blocked would have to be declared in a list (like Safari Content Blockers, and presumably have a limit on the number of rules). The actual blocking will be done by the browser without the extension knowing which rules were applied to which pages.
* https://spyware.neocities.org/articles/firefox.html
Off the three, brave seems the least worse one in terms of telemetry and the best in terms of respecting it's users' wishes. All are considered spyware by that site.
Calling firefox marginally better than chrome is just dishonest, and frankly ridiculous.
Extensions are forced to use a small subset of JavaScript with no dynamic code execution. Eval() is banned. Function is banned. Embedding a scripting language inside JavaScript to circumvent this is banned. This is a mere ghost of JavaScript left over. Google claims it's to make it easier for them to insure extensions are safe & protect users, but just as much, to me, this is to protect Google from capable & competent extensions allowing users to expand their agency: now extensions have to be narrow, fixed use, specific extensions. Tools like GreaseMonkey are all dead. The web becomes no where near the hackable medium it is, all for a little convenience for Google. https://github.com/w3c/webextensions/issues/72 https://github.com/w3c/webextensions/issues/139
A lot has been said & discussed about MV3's declarativeNetRequest; this is where the visible war has raged in MV3 for a while now. I'm not a huge fan but it's also one of the more minor side-shows in this debate, to me. High impact on ad-blocking, but ultimately there's enough compromise & wiggle room here, enough possibility to make this not awful, and if things are left truly bad, there will be enormous hell to pay & this will blow up. DeclarativeNetRequest feels like a side show to how much real ruin & savagery is being wreaked by the first two issues I outlined, being wreaked upon the most powerful & interesting & defining software humanity has, that we augment ourselves with as we do software: our user agent extensions.
I generally find Google to be quite a good steward for the web & am so happy they advance so many different initiatives & capabilities. But this is something that is extremely near & dear to me. The web is different & better than all other software, to me, because it is malleable, because the user-agent gives us power. MV3 is a radical curtailing of us the users. A radical shift towards a web that we have to simply accept, as is, that we cannot bend & shape as we want. Everything happening here feels abhorrent & disgraceful.
The process also feels totally goofy. Google is simply flipping the switch next month. They built what they wanted to as a new spec, debated some about feedback, leave comments that oh yeah, we maybe do need to do something about GreaseMonkey, maybe we do need to fix some of the missing use cases, but we're going ahead with Apocalypse Now anyways. This is the most hostile use of standardizing to destroy that I have ever witnessed.
If Google is having such a hard time hosting extensions as is, they need to stop. They need to close the Google Chrome Web Store for Extensions & stop trying to moderate it. Create a 3rd party store model, let other people serve as the agents of trust. They absolutely positively cannot be allowed to come along & standardize a much much much lower powered form of extension than what we've had, purely because they've had such a (sad fiddle) hard time running an extension store. Their justifications & pleading that these amputations to us are for our own good ring so very very false to me. Google needs to give up being a regulator of this power if it's too much for them.
I don't. Especially not with FloC[0][1].
[0]: https://www.eff.org/deeplinks/2021/03/googles-floc-terrible-... [1]: https://developer.chrome.com/docs/privacy-sandbox/floc/
As for FloC, still trying to understand FloC's implications & make a position on it. Hearing it proposed, it sounds enormously stupid, but I'm not convinced it's in fact bad. Part of me even thinks it indeed sounds like a significant privacy win over where we are.
Rather than discuss FloC though I'm wondering what other efforts you would malign.
I think my main alternatives are Brave, Vivaldi and Firefox.
And while Brave might be based on Chromium, it is distinct; in addition to not crippling nativewebrequest as chrome will, it's native adblocker is compatible with the same lists as ublock origin. So I would go with Brave :)
EDIT: Except for MSFT... that would be interesting for sure.
Ironically, though, the larger Firefox's market share, the more Google will pay to be the default search engine in Firefox. Yes, it's perverse and a little gross that we depend on Google to such a large degree to keep Mozilla and Firefox funded, but having more users increases Mozilla's leverage over Google.
Anyway, your point isn't really relevant. Unless you believe Google is dictating nefarious things to Mozilla and has subverted Firefox (difficult since Firefox is open source, but not impossible), you should still be using Firefox. If you care about not continuing to give a giant, monopolistic advertising company control over the web, anyway.
The smaller Firefox's market share, the more Mitchell Baker gets paid.
Example: https://aur.archlinux.org/cgit/aur.git/tree/PKGBUILD?h=chrom...
Not sure about other OSes, though.
> We will support blocking webRequest until there’s a better solution which covers all use cases we consider important, since DNR as currently implemented by Chrome does not yet meet the needs of extension developers.
I often have a month or more long streak between every time I have to use Ch#%!e ;-)
Bonus point for devs: If it works in Firefox it usually works everywhere since Firefox had always been reasonably standard compliant.
Thanks for saying this.
I don't really get how the extension ecosystem works anyway -- extension developers are usually just sharing something they use to be helpful/make a point, and then some tack on donations thing, right? Since nobody is doing this to get rich I suspect they won't chase marketshare.
Back to IRC DCC style sharing and distributed computing with VPN
No need to follow the money to do interesting engineering and computing. Interesting is subjective and wrapping a white paper in the cruft to host it as a service in the cloud isn’t interesting engineering
Part of me wonders if the chip shortage is real or just a way to hide big corp hoovering them up for DC hosted services.
This is not the reason for me at least to not use it as my main browser.
I recently tested and the speed is good and it is absolutely wonderful to have true full fledged extensions and complete themes.
My reason is that I'm worried if their security is good enough. If we could somehow be sure about that I'd actually happily leave modern Firefox behind for it.
Personally I'm hoping for someone to create a patch set and bulld binaries based on it to re-enable the old stuff, not by letting extensions muck around in the internals but by providing defined extensions points like:
- enable / disable tab bar
- provide your own tab rendering code
- etc
There is really no need to use Chrome anymore.
Additionally, if a solution like Pi-hole was ever sufficiently mainstream, more sites would start serving their ads from the same hostname as the page. It's not difficult to do with the CDN providers most media sites already use.
Embedded devices are already "game over". You don't own them (even if you paid for them).
Controlling name resolution on your own network (and MiTM'ing HTTPS) makes you the same as a hostile nation-state actor. We can't have that.
Ugh, seriously. I have a Chromecast, and couldn't figure out why it wouldn't play things on my local network (via DNS names set up in my router's resolver). Turns out Google hard-codes their own DNS servers and doesn't allow you to change them.
The fix was to give the Chromecast a reserved IP address, and then set up some iptables rules on the router to redirect requests from it to 8.8.8.8 and 8.8.4.4 on port 53 to my router. I'm surprised that Chromecast is using old-school port-53 DNS and not DoH.
https://developer.chrome.com/docs/extensions/reference/decla...
A lot of the changes in v3 are actually pretty sensible, it's just 10% of the stuff shoehorned in creating 90% of the friction.
https://blog.mozilla.org/addons/2021/05/27/manifest-v3-updat...
Chrome is additionally planning to remove support for manifest V2 as well, Firefox can't start to do this because they don't support V3 in their store yet.
Who cares? Just use Brave and kill Chrome off.
That's because Group Policies are a Windows-only thing.
You can get the same (and more) control with an Enterprise subscription from Google which seems to cost about $50 per year, per device.
My guess would be that your family members got social engineered into installing that crap ("this web page only works with X, click here to install"), ort their browsers got exploited and hacked (very unlikely!). You'll probably need full MDM to prevent these websites from getting their users to enable extensions.
The problem with disabling extensions is that whatever has the capability of pushing extensions into your browser also has the ability to change the settings for addons. The only solution I can think of is to create a Chromium build that cannot run extensions at all.
And as a non windows user it took me a while to realize that this notifications come from the browser as desktop notifications and disable them. Its still a riddle for me how chrome managed to make it both very obvious and very unclear at the same time that this are websites desktop notifications. (As a counter example I used some sites which used desktop notifications on FF/Andriod instead of making a app just because notifications, that I loved)
I'm sorry that your family are... having such a hard time making reasonable choices for themselves. I have literally never seen this anywhere, or heard any coworker ever report their family rampantly adding shitty extensions. I tend to see pretty clear & obvious signals about what extensions are good & ok when I go to consume. Bad extensions seem to be discovered fairly quickly & taken down. I'm trying to imagine how folks even get to the Chrome Web Store in the first place if they have no idea what they are doing. The world to me seems no where near as grimdark as you project.
Alas I think it requires a paid Google Enterprise account, but your family sounds like their need external management of their browsers. That they should, like a school computer, have an administrator & a denylist or perhaps even allowlist of what extensions they can use.
This post spreads so much Fear Uncertainty and Doubt. Trying to justifying ending a good thing because some creative user keeps finding a way to misuse, to not listen to sense, to not make good judgement... I find it unfortunate that such heavy fearmongering, such terror at the world is allowed to sway us so heavily.
Ultimately I want 3rd party sites hosting extensions. Not Google. And I want moderation teams able to surface claims that some extensions are bad. We need more choice, more democracy, more ability to help each other. Sunlight is the best disinfectant. Simply giving in to the bed-wetting terror of, oh no, freedom & denying ourselves user-agency is intellectual suicide for the web.
It doesn't sound like you think your family is at all educateable in any way, you seem to think this is a horrible lost cause & that we must withdraw power & good for the world to protect your vulnerable unfortunate tribe. You're using that as a weapon against the world, against good, against freedom, against capabilities.
This is extremely menacing a position you've made, using your own family's purported victimization a weapon against good.