Privacy Badger is a browser extension that learns to block invisible trackers
privacybadger.org
privacybadger.org
In general I consider ads to be unethical cognitive burden. The exception is if the site owner keeps the lights on by incorporating non-tracking advertising, it would feel scummy to block off their ads and just take the good content. On the other hand tracking users is an active hostile move and blocking it is the right choice. At least that's my reasoning for choosing Privacy Badger.
You don't even have to go that far. They're attempted fraud. They are by and large lies intended to trick you into giving someone money.
I’m completely desensitized to ads and know people who won’t click on ads at all. I wonder how effective ads are then.
"Need a plumber in $TOWN? Call $TOWN Plumbers at 555-1212."
Others simply advocate for a cause:
"Vote Yes on $TOWN Proposition #4!"
Ads like those above do add cognitive burden, but they can provide utility to a community and are demonstrably neither fraud nor lies.
Nevertheless, I believe that giving the awareness part a free pass, can be a slippery slope. I didn't want to think about plumbing or the Proposition 4 or plastic surgery. So unless I search for either of those two I feel it's an intrusion to force those thoughts on me.
"Creating awareness" would be handing out unsolicited facts with a neutral point of view. Most ads are more in the nature of unsolicited and manipulative advice from someone who does not have your best interest in mind.
I agree.
> The exception is if the site owner keeps the lights on by incorporating non-tracking advertising, it would feel scummy to block off their ads and just take the good content.
I disagree - if content cannot survive without advertisement, then we're better off without it anyway. Non-tracking advertising is less bad than advertising, but it's still intrusive and not-called-for, just like all advertising.
There are many people who simply don't have the financial means to support all the content they like. Does that content not deserve to exist? Should quality internet content really be a class question?
Thought experiment: what about a free website that shows people where their nearest food bank is?
Back to ads, it sounds like living in a corporate dystopian nightmare where your every move is tracked and you're constantly manipulated is somehow the "woke" option in this discussion. Great.
I could easily host a local Facebook-esque site for a hundred friends and family for less than $10 a month. I wouldn't need all their apps and every website they use to participate in a spy network to make it work, either.
Goodbye, niche knowledge sites, I suppose
So radio and TV should have never existed?
> Non-tracking advertising is less bad than advertising, but it's still intrusive and not-called-for, just like all advertising.
So yeah, they are against all forms of ads
There are noncommercial models for broadcast media, and the fact that some countries ended up with the vast wasteland[1] that is commercially-supported broadcast television and radio isn't an inevitability. It was made to happen, by commercial interests. It could well have been different in the US, and still is in numerous other regions.
See Robert W. McChesney's Telecommunications, mass media and democracy : the battle for control of U.S. broadcasting, 1928-35 (1995)
https://www.worldcat.org/title/telecommunications-mass-media...
https://archive.org/details/telecommunicatio00mcch
https://libgen.rs/book/index.php?md5=05E6FC47CE851CB143F1DD4...
________________________________
Notes:
1. FCC Commissioner Newton Minnow, 1961
https://www.latimes.com/business/story/2021-05-06/newton-min...
Google wouldn't exist if it couldn't support itself.
Neither would 99.99% of websites available.
Think of how many sites, are available just because they can cover their costs by putting adds on their site.
Ads are a plague. They waste screen space, they're often virus-laden traps, they look ugly and ruin the look of a good website, they're often scams, etc.
I pay for the the internet service that sends the ads to me, the screen the ads show up on, the computer that requests the ads and the electricity that powers the computer.
I am not paying for all that just to get ads shoved in my face. If they want donations or a subscription, fine. Understandable. But no ads.
This is the exact reason why I use DuckDuckGo Privacy Essentials instead of an ad-blocker. Whenever I mention that I don’t block ads out of principle, I get down-voted a lot :-D
Nothing is scummier than web site owners thinking they are entitled to our attention, to say nothing of selling it to the highest bidder without our consent.
There is zero obligation on our part to pay attention to ads. Zero. There is absolutely no shame in not wanting to be subjected to such noise. They'd very much enjoy it if we paid attention but they aren't entitled to make a single cent off of us without our consent.
Especially when I don’t discover the problem until I’m half way into a multipart form submission that can’t be refreshed, or an e-commerce transaction fails because it rapidly hands off between multiple third-party servers and one of them in the middle of the chain had some critical JavaScript path blocked.
I still do it but it is a pain.
> Protects you against tracking through "free", centralized, content delivery.
Is it not still relevant as long as all sites don't choose to host their own dependencies, as recommended in the article you linked?
This add-on shaped the privacy-positive landscape for browsers upon it's release, but the features have be made obsolete with the latest browser isolation and that most entities have migrated to bundled JavaScript and off of CDNs.
I'd like to keep 500MB or so of data locally and just have it replace the network requests when they're made. I'd be curious how much data that might end up saving after a month or year of browsing.
I'm more interested in techniques for faster page loading.
Why would I allow all websites I visit to store things on your computer? I have about 20~ domains whitelisted (which I've added and maintained over years). The rest will be forced to forget me and not be allowed to create profiles and sell my interests and habits to the highest bidder.
Works great with Firefox Multi-Account Containers: this lets me be stayed logged into an account (eg Google) but only for a subset of services (Google Drive, Gmail) – not Google Search: why would I want Google to keep an history of my queries?
Works great with https://www.i-dont-care-about-cookies.eu (I really don't care about them since they're auto deleted anyway). I wish uBlock, Cookie Auto Delete and I don't care about cookies would be installed by default with Firefox.
private browsing i do as in, i start my pc, firefox starts on its own so i do ctrl+shift+p. then i go about my day using this window and more such windows.
whenever i have to wind down for the day or want to get rid of a session, i just close the windows and i am clean.
i understand people use cookies auto delete like you mentioned but for my use case, i dont even bother. i can sign in, do what i need to do and i dont care about signing out or even being tracked across sessions because sessions are not persistent across logins
In Privacy & Security settings set it to clear all browsing data when Firefox closes, and simply add exceptions for whichever domains you want. This also has the advantage of clearing some things CAD is unable to due to limite of the WebExtension APIs.
2. Exceptions in Firefox preferences don't support regular expressions, so you need to whitelist both https:// and http:// and you can't tune things for subdomains. CAD is much more powerful, with custom rules (*.google.com), white and greylists, etc https://github.com/Cookie-AutoDelete/Cookie-AutoDelete/wiki/...
3. CAD has the option to keep a log of deletions and restore the deleted data/cookies.
4. And CAD supports containers, so you can open tabs of the same URL but only be logged in the one you want (multiple Gmail accounts but remain incognito in Search, Maps, Youtube and other Google properties).
https://blog.mozilla.org/security/2021/02/23/total-cookie-pr...
While there is likely to be overlap between the various advertising/tracker lists and Privacy Badger, regardless of whether you enable learning locally, Privacy Badger can automatically discover new trackers that list-based blockers don’t know about.
Besides automatic tracker blocking, Privacy Badger comes with privacy features like click-to-activate replacements for potentially useful trackers (video players, comments sections like Disqus, etc.), and link cleaning on Facebook and Google.
Privacy Badger is also a political tool. By using Privacy Badger, you support the Electronic Frontier Foundation [1]. Privacy Badger sends the Global Privacy Control [2] signal to opt you out of data sharing and selling, and the Do Not Track [3] signal to tell companies not to track you. If trackers ignore your wishes, Privacy Badger will learn to block them. The idea isn't to block all advertising but rather to promote a better Web.
[1] https://www.eff.org/ [2] https://globalprivacycontrol.org/ [3] https://www.eff.org/issues/do-not-track
Has there been any study as to how closely Privacy Badger converges to list-based blockers like uBlock Origin given enough time? Is that at all a metric you use in development?
There are a few academic studies that note that algorithmic and manual approaches to tracker blocking tend to compliment each other, for example:
https://kevin.borgolte.me/files/pdf/www2020-privacy-extensio...
Do any significant disadvantages of Privacy Badger stand out to you, contrasted with uBlock Origin? The biggest problem I can think of is that uBlock Origin will immediately prevent me from loading content that could be dangerous, while Privacy Badger has to visit dangerous content enough times to learn to block it, which is less good for security.
On the other hand the big advantage to me for Privacy Badger is that it doesn't depend on manually-curated lists. uBlock Origin nicely wraps the block lists but when it comes down to it you are giving control over your browsing experience to the random volunteers building these lists, which, who knows? Though I'm not accusing anyone of anything.
Regarding having to see dangerous content multiple times:
- Privacy Badger gets remote learning at this point from Badger Sett, so most common trackers should be accounted for.
- Privacy Badger isn't so much a security tool as a privacy tool. Yes, blocking trackers is good for security, but it's not the primary objective. The primary objective is to stop non-consensual pervasive tracking. In this light, having to see tracking a few times before deciding to block it is a reasonable approach.
[0]: https://www.eff.org/deeplinks/2020/10/privacy-badger-changin...
All extensions that modify page state are fingerprintable. Privacy Badger's local learning creates the possibility of additional fingerprinting. As discussed in the blog post you linked to, we decided that we can deliver most of the benefits of automatic learning without local learning. We further believe that local learning can offer benefits that outweigh the risk of additional fingerprinting, which is why we kept the ability to re-enable this feature at the user's discretion. Does this answer your question?
Nice. I thought the local learning (which was kinda the main appeal of PB) was dead after reading that post. Glad that isn't the case.
So, for example, does it stop loading fonts? Or CDN-hosted assets?
Didn't realize endcards were a thing on youtube until a year ago because of it, and many sites break in subtle to unsubtle ways.
Youtube's endcards are not blocked by default in uBO, and I can't find a list in the set of stock lists which blocks them.
that said, i recently saw "localcdn" addon for firefox which i've started to use. don't know if it has made any improvement but why the hell not
Personally I will wait to try LocalCDN until it becomes recommended by Mozilla and installable on mobile Firefox, but it has peaked my interest. Thank you for sharing it 2Gkashmiri.
[0]: https://addons.mozilla.org/en-US/firefox/addon/localcdn-fork...
[1]: https://addons.mozilla.org/en-US/firefox/addon/decentraleyes...
For reasons you might want to use Privacy Badger, see the following links:
- https://privacybadger.org/#How-is-Privacy-Badger-different-f...
- https://privacybadger.org/#Is-Privacy-Badger-compatible-with...
In October 2020, following security disclosures by the Google Security Team, Privacy Badger changed its default behavior. While it would previously learn to block new trackers heuristically after installed, it now defaults to blocking only trackers it already knows from automated testing before release. While it can still be configured to learn heuristically, it is no longer the default option because it can be exploited by third-parties to fingerprint the user based on trackers it blocks.
So it seems that it no longer actually "learns to block", not by default.
It does learn, just not on your PC:
By default, Privacy Badger receives periodic learning updates from Badger Sett, our Badger training project. This “remote learning” automatically discovers trackers present on thousands of the most popular sites on the Web. Privacy Badger no longer learns from your browsing by default, as “local learning” may make you more identifiable to websites. You may want to opt back in to local learning if you regularly browse less popular websites. To do so, visit your Badger’s options page and mark the checkbox for learning to block new trackers from your browsing.
With local learning disabled, is there any need for using the Privacy Badger add-on specifically? Would it be possible to distribute the tracker lists which are generated by Badger Sett in a format compatible with uBlock Origin?
edit: Found that Badger Sett generates a json blob: https://github.com/EFForg/badger-sett/blob/master/results.js...
I am not that familiar with uBlock Origin's filtering syntax, but from a quick look, it seems like the json could be translated at least to the 'dynamic filtering' rules (accessible only when you enable "I am an advanced user"). Perhaps I'll open an issue.
- https://privacybadger.org/#Is-Privacy-Badger-compatible-with...
- https://github.com/EFForg/privacybadger/discussions/2786#dis...
> In the coming months, we will work on expanding the reach of Badger Sett beyond U.S.-centric websites to capture more trackers in our pre-trained lists.
From the URL it looks like that was written in 2020, but it's in the text the extension links to today. Does the reach of Badger Sett by now extend to the websites visited by users outside the US, or should such users turn on local learning to be protected?
I'm a happy user of Privacy Badger and didn't realise the behaviour had changed until today, when I clicked curiously on my badger icon! I've turned local learning back on and I'm looking forward to the feature below:
> In the longer term, we will be looking into privacy-preserving community learning. Community learning would allow users to share the trackers their Badgers learn about locally to improve the tracker list for all Privacy Badger users.
Also Firefox now builds in functionality similar to HTTPS everywhere:
https://support.mozilla.org/en-US/kb/https-only-prefs
Code needs to be reviewed to be safe, so minimize the code in your browser to reduce both fingerprintability and possible exploits.
- https://privacybadger.org/#How-is-Privacy-Badger-different-f...
- https://privacybadger.org/#Is-Privacy-Badger-compatible-with...
By the way, I like both uBlock Origin and AdGuard!