Mozilla reaffirms that Firefox will continue to support current content blockers
ghacks.net
ghacks.net
Considering that uBlock Origin works best and can do the most in Firefox with this continuing support, I’m glad Mozilla is still walking the talk on this one.
We need at least one browser that makes the web usable, and that might as well be Firefox with uBlock Origin.
Edit: Oops. Missed providing the link reference below earlier.
[1]: https://blog.mozilla.org/addons/2019/09/03/mozillas-manifest...
Personally I’m a mobile personal browser person which is safari. I can’t stand to be at a computer after a day of being at the computer.
The only differences that come to my mind are super minor (chrome logging 400er requests to console, Firefox having more advanced grid/flex debugging. I'm kinda interested if I'm missing a super obvious feature that's commonly used.
It's also a psychological bond to a certain extent, having relied on them during stressful times in my career... before that I had only FireBug and that served a similar purpose but didn't teach me quite as well and did never reach the status of "if the Chrome Devtools are open, I can understand what's going on here"-sense of security & confidence.
Overall, it also seems less accessible to me. It may well be that it's much more powerful in some respects, but I've never got my head around it enough to work that out.
I do very much rate its Memory Tree Map view, though. Big advantage over Chrome for rapid debugging of where memory goes.
Sometimes stack traces are missing in the console which Chrome does show.
For example, document.querySelector("input[type=text") (note the missing ]) worked in Firefox but didn’t in Chrome. Or something similar to this.
Presumably, you don't need an ad blocker to test and debug your own code, unless you are testing specifically for ad-blocking browsers. And if you are doing things properly, you should be testing on both browsers anyways, at least as a final step.
The user chooses what website page to visit, but it's the website that chooses want content gets served at any of its URLs. That's how the web works. Hence, when websites choose to include aspects of the page users don't want: "blockers", to block some of the page. Nothing loaded about the term it's just descriptive.
Nor are they "content selectors/choosers", nobody uses their adblocking plugin to find content, only to block parts of content they've found by visiting a website.
Maybe easy version could work exactly the same way as blockers do, except they'd invert the way the rules are evaluted, and of course the rules would need to be custom as well. And then if the rules would fail to find some actual content on the page, then I guess you might not even know about it :).
But isn't "filtering out all of the content" just another way of saying, "not loading any content" - until explicitly requested?
Can I tell uMatrix to only show a certain XPath from the page? If so, I agree it is a content selector, albeit pretty impractical :).
I do install uBlock Origin for all non-technical family members, but uMatrix is so much more capable.
"Blocker" implies a specific set of assumptions about a publisher having some say in how content gets presented. "UserAgent" entails a different worldview, one that the companies making browsers seem increasingly unwilling to defend against competing interests.
No, not at all. The web was specifically designed so that the client chooses which parts of the available content to load, and in what way.
When I first started browsing the web I didn't have a graphical browser at home. My web client made decisions about which parts to display and which parts to not. It was not "blocking" anything, it was rendering the available content according to the capabilities of my system.
> "Nothing loaded about the term it's just descriptive."
It's a loaded term because it implies that websites ought to have control over display, when the web was specifically designed such that they should not.
> "Nor are they "content selectors/choosers", nobody uses their adblocking plugin to find content"
I modify many aspects of webpage display to help me assimilate content. When a website has chosen difficult to read colors, I change them so they're easier to see. I change fonts and font sizes. I modify page layouts, sometimes collapsing many separate pages into one long page, and sometimes I use screen readers and I don't even look at a visual rendering at all. I often remove annoying, obnoxious or intrusive content which also make it harder for me to read a page, many of which are ads.
The web is specifically designed from inception to give this agency to clients. Websites provide units of content and suggestions on how to best display it. That is all.
It was designed with this technical capability. But the social contract was always that you went to a site for it to tell you what to display. And we have many very nice, very non-standard sites because of it.
There is nothing wrong on blocking part of that content, but everybody's state of mind is that by default, any site content is expected to load.
Source that this is just a side effect from other design decisions?
>My web client made decisions about which parts to display and which parts to not
Your browser sucked because it couldn't even support the full standard.
>It's a loaded term because it implies that websites ought to have control over display
They should. Websites describe what should be shown using HTML and CSS.
The source would be Tim Berners-Lee's original 1989 proposal for a hypertext information system. He specifically wrote: "We should work toward a universal linked information system, in which generality and portability are more important than fancy graphics techniques and complex extra facilities."
These sentiments are also reflected in other technical documents such as RFC 1866. The intent is crystal clear.
> "Your browser sucked because it couldn't even support the full standard."
I think this is a common reaction from people who aren't old enough to remember a world before mega-complex browser platforms and non-portable websites came into being. My browser absolutely was standards compliant at the time, and it was expected that websites would be viewable without graphics.
Keep in mind: javascript had not yet been invented.
Again, HTML is specifically designed around portability, generality, and flexibility. This has been degraded by the rush of commercialization and related platform lock-in -- in large part due to things web 2.0. This is not a good thing.
> "They should. Websites describe what should be shown using HTML and CSS. "
I think you should read a bit deeper into the underpinnings of these standards you're referencing.
This would support the opinion that entire web sites should be protable as opposed to just a small subset.
Oops. I guess you meant to say user request selector/filter then if the term "block" is so loaded.
And if a user wants to have a policy of selectively choosing what content they want, but that content is hard to define or whitelist, then using a blacklist mechanism doesn't mean that the policy is to block. It's just the most common, practical method of choosing the content you want.
No one has enough time in the world to block all the infinite amount of useless content. We already do that perpetually by what we personally value the most and what we choose to ignore.
The client can interpret the data from the website however it wants regardless of the intention of the website.
A website, for example, can use tags that a client doesn’t comply with.
The client is and always has been opinionated. It does not and never has had to obey the websites intentions.
"One of the fundamental features of CSS is that style sheets cascade; authors can attach a preferred style sheet, while the reader may have a personal style sheet to adjust for human or technological handicaps."
In reality, the more interesting question would be whether we shouldn't limit our media consumption to begin with, or form a culture that is less dependent on advertising. If browsing with ads becomes mandatory some day, I will probably make the choice to severely cut the amount of Internet I gorge on. It will take some willpower, but every time I switch off the blocker and see what websites really are like I want to gag, so I won't be that difficult.
I personally don't care if click bait tabloids and exploitative re-hosters we're to crumble overnight.
The case of HN is particularly enlightening because the community is very hostile to ads and for the most part has the technical ability to avoid them with a higher degree of sophistication than just installing Ublock. But there is also the majority of the focus and admiration placed on SWEs and companies that are directly and indirectly tied to the ad ecosystem. The energy given off is similar to McDonald's executives yelling at their children if they see them with a processed patty in hand.
There is a ocean of addictive distractions to wade through, but at the same time we know the following things:
- We have to be constantly mindful of the Gell-Mann amnesia effect
- News sources and journalism have always had significant quality problems when they venture beyond just reporting basic news, even in the case of business-oriented publications that as Chomsky has pointed out have a vested interest in delivering quality reporting
- Understand topics requires delving into the academic literature in many cases. In this scenario, the internet becomes the line towards that literature or those long-form articles but most of the users' time has to be spent reading and thinking instead of just browsing
- Identifying skinner boxes and addiction traps is easy. You usually know when you are in one. We have to just be honest about what our goals in life are and how much progress we are making towards them
What this does not solve is the problem of focusing on the wrong things in life or embarking in a career or interests that are ultimately deleterious to your life. But the internet at least makes it far easier to pivot and refocus as long as you let it do so and use it towards a conscious goal. This mindfulness is easier said than done but it's far from an impossibility.
That's why I think the internet would be better off without a lot of the intense duplication that is out there today.
Sort of. Many of the useful (not ad-driven) sites of the 90s are still around. Mine are. So in that sense, yes.
But they are drowned by the flood of ad and SEO-driven junk. Finding the good parts, if you don't already know, is becoming harder. Search engines no longer return most of the useful sites on any given topic.
Today's internet has astoundingly accessible resources on all sorts of things. A motivated person can still sidestep all of the crap with relative ease. Or to put it another way, if they get lost in the shrubs, they weren't gonna make it in any case. Motivated people now have many more tools and platforms at their disposal to gather alongside one another and make things happen. The pre-September internet was more private, yes, but that was actually a massive flaw in an absolute sense. Now you can have a bright middle class Mongolian kid become an electronics expert on his own and the greybeards aren't barred from finding their watering hole either.
The web in the late 90s was in most ways far more pleasant and useful place than today. Content was a labor of love, not driven by advertising.
I wouldn't hesitate for an instant go back to an internet which bans advertising. It would be far better than what we have today, not just the ads but all the toxic data collection and spyware that those fuel.
There was a link posted to HN today: "Homemade Heat Pump Manifesto". I remember when a web search about any topic would find you a few similar pages, of people diving deeply into topics and DIYing experiments and publishing everything they'd learned simply because they wanted to share hard-won knowledge.
On my projects-to-do-someday list, I would like to try mashing up a search engine to filter out results that contain advertising (load the page, check if anything matches adblock list, if so, discard). Obviously in today's adcancer-filled web, that is going to discard the vast majority of results. But I'd hope that it would eventually surface some interesting results that have been drowned out by spam, assuming they're even still indexed. But it certainly couldn't be any worse than all the false positives that drown the results these days.
The way those ads get put these is massive privacy violations happen to fuel an engine that’s smarter than you with data. Then this engine shows the perfect ad at the perfect time in the perfect moment of weakness to get you to do what the advertiser wants.
If these ads were merely roadside billboards I don’t think I would care as much. These are internet ads connected to an extensive surveillance infrastructure. Manifest v3 indirectly means an increase in surveillance activity and the biggest companies and governments on earth expanding their power. Let’s also not just say that content blockers merely block ads, I use them to block scripts all the time which are there to expressly mine your data to manipulate you in the future. I’m not smart enough to not get manipulated if I give these companies my data.
If I block ads to prevent all that and we have less 6 figure FAANG jobs and convenient services on the internet - oh no! P2P is a thing, community run websites are a thing, alternative funding models are a thing, open source is a thing, lower wages are fine, we’ll be fine.
If you don’t have moral qualms with using your eyelids to block ads then you shouldn’t have with software content blockers either. It just outsources the act of blocking from your eyes into the computer.
Ad blockers on the PC are the same thing.
Not everything needs to be analyzed to death for some sort of symbolism.
IIRC they get $400 million annually. There are 200 million FF users. $2 each wouldn't be bad... But realistically only 1% of the users would donate and $200 is unpalatable.
Maybe another organization picks it up and runs it more efficiently or at a loss for advertising?
Or...?
Wikipedia collected 162m in revenue (no ads!) and spent 112m dollars! I'd be curious to dig into what % of that goes to core wikipedia and what % goes ancillary projects. You'd have to dig very deeply into their finances to figure that out.
Firefox should set apart a large chunk of that 400m/year in an endowment intended for Firefox to continue and to be independent in perpetuity. That could easily be a multiple-billion dollar endowment by now and their spending and growth from that spending should be on revenue from that endowment.
Competing with Google and Microsoft funded competitors ain't cheap. And requires more than developers. People don't play that nice, at least not when there's an advantage to playing dirty. And there is.
[1] https://frankhecker.com/2020/08/15/how-mozilla-makes-money-a...
I'd pay $200/yr for the privacy and control benefits of Firefox over google-controlled Chrome.
That single fact makes me reluctant to pay for Firefox. Unless I'm sure that all the money I donate goes to the right cause and not to a CEO's bank.
$4B is a lot of money, no matter how you look at it.
And no, as bad as the big bad corporation is, nobody has the regulatory capture required to ward off an anti-trust lawsuit in guaranteed perpetuity. Among other things, the law would have already changed to not bother with anti-trust if it did. All it takes to upend the regulatory applecart is a change of the driver. And when that day comes, you want to have plausible deniability.
I'd go even further, as the example of AT&T shows that just breaking up a monopoly is insufficient, as it can reform over time. In addition, (dis)incentives must be created to counter whatever led to the market failure in the first place.
The Sherman Anti-Trust Act forbids attempts to establish a monopoly, regardless of the success or failure of such an attempt. Designing a system in which network effects tend toward monopoly (e.g. "Keep using our platform, because when your friends talk on this platform, it's the only way to hear what they're saying.") is an attempt to establish a monopoly.
At the end of the day, yeah, it seems like it might cause people to switch. I'm also honestly wondering, how long until a real competitor to YouTube surfaces? I realize that this is hard to build (though we do have multiple streaming platforms in existence), but Google has been playing this slowly boiling frog experiment with ads on YouTube. Now you have multiple ads per video, coupled with ads baked within the videos themselves, and sponsored content. If you don't pay for YT premium, it's kind of unusable.
The worse the product gets, the more of an opening is created for the competition. Seems like a matter of when rather than a matter of if? What if Amazon or Apple created a YT alternative that was ad-free, maybe with some paid content to sponsor creators (pay $2 a month to get bonus content from this channel). They could afford to sink money into it and it could be very disruptive, but it's like they don't dare. Maybe they're afraid to associate their name with a product that could fail, kind of like Google Plus.
Technical users have what is probably the lowest tolerance to BS that's humanly possible when it comes to the web viewing experience. The web without an adblocker is really really bad, to the point where I would instantly switch to another browser that continued to allow adblockers. The user experience of that browser wouldn't even matter as long as pages rendered and it worked reasonably well, that is already a million times better than having a ton of ads forced upon you.
I don't know about you but I also can't remember the last time I saw a paid ad and thought "wow, I want that" and then bought it. It just doesn't happen for me. If I end up buying something it's because there was a gap somewhere and a product filled that gap. I'm going to attempt to research the problem (the gap) and find a solution (various products) from a non-biased source before I buy it. This involves organic search results. Basically a paid ad that would have been blocked by an adblocker is going to have a 0% chance of converting me into a buyer.
Also, most non-technical users don't even know what an adblocker is. Unless someone set one up for them they are seeing ads. It seems weird to me they would spend a lot of effort into trying to block adblockers. The audience who uses them likely has a very small chance of ever buying something because of a paid ad and a large chunk of users don't use adblockers.
This whole scenario reminds me of Let's Encrypt in a way. If push comes to shove and major browser vendors like Chrome prevented adblockers something tells me some of the best minds in this space will come together and make a browser that will be technically better in every way possible.
Lol! Truer words have never been spoken.
https://blog.nightly.mozilla.org/2022/09/21/these-weeks-in-f...
the only problem i can imagine is the invisible pressure by the unending desire to become chrome,you know with hiding the search bar by default "because people are used to that from chrome" and other shenanigans, i feel this support might be shortlived because the stupid people managing firefox are paid by google to fuck up firefox in the worst possible way and this just feels another attempt in that regard.
btw, i've been online since 2004, daily so i have used a lot of firefox
I, too, feel that eventually they might just go: "Everyone is doing it and it cost us more effort to keep maintaining it, here you have our own internal blocking, which won't block Google related stuff because they fund us"
All I know is. It's my device. Not Google's and I intend to fight that battle, just like we did with Microsoft.
There are numerous smaller items like this, that just flowed a lot better, particularly if you're heavily browsing images, like tab previews, that have been sacrificed either in the name of performance or to be more like Chrome. Fortunately, SeaMonkey still maintains these classic features, but is unfortunately a memory hog.
My daily browser has also been Firefox since around 2004. SeaMonkey remains a time pocket, when I long for the old days of yore.
I mean, there might be a relation? I went from IE to Netscape (edit: Or NS to IE?), to Firefox to Chrome, then tried every 1-2 years to switch back to Firefox and always returned to Chrome because it was so much faster. It was only 2-5 years ago (can’t remember exactly) when FF switched to fully multiprocess and stopped using their unique extension model, that I could finally start using FF again because the performance was finally on par with Chrome.
Now it only lets you send the page you're currently on, which is annoying.
I send a lot of stuff to my desktop when I'm riding the bus.
Chrome replaced it with a less flexible API that has bounded runtime, preventing the browser from the kind of slowness that caused a certain dissatisfaction, even disharmony here.
You could say that people shouldn't configure so much adblocking that the browser has to evaluate 90,000 regexps for a simple click. Or you could say that the browser shouldn't prevent that case by design. It's not simple. IMO a worst case like this is one of the causes of "invisible pressure".
I wonder if an optimizing regex-compiler could transform the set of regexes into a single finite state machine that’s more efficient than running individual regex recognizers in parallel. The optimal solution feels NP-hard, but I wonder if one could get sufficient improvements with some heuristic optimizations, like extracting common clauses, etc.
Maybe @burntsushi has some insights about this?
However, when you're talking about thousands of regexes, that's going to be a very large automaton. Probably impractically large. It's not NP-hard. It's "just" impractical.
Using heuristics to whittle down the set of possible regexes to match---likely using literals extracted from each regex---is exactly what you want to do for a problem like this. If all you have are literals, an Aho-Corasick automaton is feasible to build for 90,000 entries. Aho-Corasick, in my experience, doesn't really start to break down until you eclipse 1,000,000 entries.
Last time I ran benchmarks of all well-known content blockers using Ghostery's benchmark tool[1], all of them could process a network request under 20µs on average.
Some do have performance concerns, but it has nothing to do with network filtering, it has to do with other stuff they do beyond network filtering (for example see [2]) and declarativeNetRequest does not help there, so they will still suffer these performance issues under MV3.
---
[1] https://github.com/ghostery/adblocker/tree/master/packages/a...
[2] https://www.extremetech.com/computing/182428-ironic-iframes-...
Since they aren't taking away the onBeforeRequest() functionality, I don't see a good reason why greasemonkey can't be ported over.
- [ ] ENH,SEC,UBY: Browser UI: indicate that a domain does not have DNSSEC record signatures
- [ ] ENH,SEC,UBT: Browser UI: indicate whether DNS is over classic UDP or DoH, DoT, DoQ (DNS-over-QUIC)
- [ ] ENH,SEC,UBY: browser: indicate that a page is modified by extensions; show a "tamper bit"
- [ ] ENH,SEC: Devtools?: indicate whether there are (matching) HTTP SRI Subresource Integrity signatures for any or some of the page assets
- [ ] ENH,SEC,UBY: a "DNS Domain(s) Information" modal_tab/panel like the Certificate Information panel
Adding blockers to the hosts table still works with Chrome... hope they don't muck with that...
https://github.com/StevenBlack/hosts
But if they do... there are always DNS solutions you can add to your Router.
I use Firefox, but even things like Windows spams ads at you if you let it. So many things have Google trackers built in too...
So while still useful, that's not really a replacement for browser extensions.
https://github.com/uBlockOrigin/uBlock-issues/issues/338#iss...
It’s really worth a read to better understand the pros and cons of this new API.
This works, its just hidden. Says unsupported but works fine in Nightly even so far.
https://support.mozilla.org/en-US/kb/compact-mode-workaround...
Edge is still faster but its good that the default Windows browser is finally good.
I know it's cool to not like Google and whatever, but I would hope that we can at least discuss facts on this website and not just sling FUD around.
Can you provide any detailed technical information that proves that Google intentionally crippled this new API for nefarious purposes?
Just to be clear, I am a long term Firefox user and probably will continue to use it. I just want to see some real proof for these claims.
The idea of an unprivileged content blocker sounds attractive to me, and considering how much effort Google puts into security on Chrome I don't think it's far fetched that this change is for security purposes.
Chrome was the first browser (afaik) to support running extensions with limited privileges, and I'm sure people were originally upset by this, but today it's clear that this was the right choice and massively increased browser security for the majority of users.
This is not a technical decision by google, it is business strategy.
No company publically publishes strategy meeting notes, so asking for them is not a reasonable argument. Of course they are not public and anyone who was present at the meetings is under heavy NDAs.
uBlock Origin just needs to migrate to this new API. Despite the noise from people who just hate on big tech the only true difference as far as I know is that the browser will enforce a limit on the number of rules that can be added. This number exists to try and prevent bad performance from too many rules existing.
> The second is that it ensures that poorly optimized web extensions can't slow down the performance of loading sites.
This is true for any code that is running on the browser. Luckily, uBlock Origin and the webRequest API allows me to block arbitrary Javascript and assets so that poorly written websites can't slow down the performance of loading sites.
There is an inferior port of uBlock to MV3: https://github.com/gorhill/uBlock/commit/a559f5f2715c58fea4d...
Are you paid by Google?
The goal is to increase increase the level of privacy of the entire ecosystem. While ublock origin may be trustworthy there are many extensions that are not. It would be better to find a more privacy preserving replacement compared to having to trust extensions to be good actors.
>This is true for any code that is running on the browser.
Typically the code doesn't blocking the page from loading though. And again if this change results in faster loading speeds for users ecosystem wide this change is a win.
>There is an inferior port of uBlock to MV3
The downsides seem to be from wanting to be permissionless and not from not being able to replicate the functionally with manifest v3.
>Are you paid by Google?
No, I have never been paid by Google.
By running arbitrary code on your computer you are inherently trusting the author of the code to be a good actor.
> Typically the code doesn't blocking the page from loading though.
Tens of megabytes of bloat block pages from loading all the time.
> And again if this change results in faster loading speeds for users ecosystem wide this change is a win.
uBlock speeds up loading because it blocks useless bloat such as advertisements. MV3 restricts the ability to block content, ergo it will slow down loading speeds.
It's not actually designed for privacy or whatever, it's simply a way to gimp adblockers so that Google (one of the largest online advertisement companies) can get more money from their advertisement business. You must be really naive if you don't understand this simple concept.
While you may be running arbitrary code, there is only so much it can do from within the sandbox it is in. Because we can't stop 100% of bad actors that shouldn't mean we should give up on security.
>Tens of megabytes of bloat block pages from loading all the time.
That is a separate issue from web extensions. Just because X is slow, it doesn't mean we should not speed up Y.
>MV3 restricts the ability to block content
No, it does not. You just need to use a different API / give it permission to do so.
>It's not actually designed for privacy or whatever
That is one of the reasons Google provided, so yes it is.
>it's simply a way to gimp adblockers
Then why did Google work with adblock extension developers to improve the API by adding things like dynamic rules? The reason is that this is for improving privacy / performance as opposed to trying to kill off extensions.
>You must be really naive if you don't understand this simple concept.
If Google wanted to get rid of ad blockers they would make them against the rules in their extension store. You have to realize that Chrome is software that is used by billions of people and not just you. Google has a responsibility to protect people's privacy and there are engineers who want to be able to move metrics like the number of malicious extensions removed each month or p99 page load speed.
You fail to understand the grand strategy. Outright banning ad blockers would be quite radical and may push people away from using Chromium. Simply progressively gimping ad blockers increases Google's revenue from advertisements while keeping all those users.
I do not use Chrome. I use Mozilla Firefox, since it supports a better webRequest API so that uBlock can block ads despite things like CNAME cloaking.
The goal is not to gimp ad blockers and Google is open to working with adblock extension developers so that they can continuing functioning with the new API.
>I do not use Chrome. I use Mozilla Firefox, since it supports a better webRequest API so that uBlock can block ads despite things like CNAME cloaking.
Chrome supports / is planning to support forwarding the domain of the CNAME record. This means that CNAME cloaking would no longer be a thing.
UBlock Origin is not the only extension that uses the webRequest API that people use. If that were the case they would not have removed it. Again ad / tracking blocking can still be done with the new API.
You are not required to install every extension in the world. Only install the ones you trust.
> Again ad / tracking blocking can still be done with the new API.
As the authors of ad blockers disagree with you, what evidence do you have to support your position?
Despite that there exist people who install malicious extensions for one reason or another.
>what evidence do you have to support your position?
Go and read the documentation. There is enough capabilities to implement one.
If there was a way for technical users to unlock the more risky settings, it would placate the conspiracy theorists. That doesn't appear to be the case, so the argument that Google is doing this to restrict and minimise ad blocking remain entirely valid.
>At this point I consider being permission-less the limiting
factor: if broad "read/modify data" permission is to be used,
than there is not much point for an MV3 version over MV2, just
use the MV2 version if you want to benefit all the features
which can't be implemented without broad "read/modify data"
permission.That is an unjustifiably absolute statement.
In security you need to look at threat models, not just declaring something better or worse.
There are multiple parties you may (or may not) trust. For instance, the browser developer, the website developer and the extension developer. Different people legitimately have different threat models.
You seem to trust the browser developer (an advertising company driven by ad profits above all else) the most. In that scenario, your statement makes sense.
I trust the ad-blocker extension developer more than the other parties, so of course I want it to have full acess to block evil behavior.
It's fine to be absolute due to the contents of requests no longer being able to be accessed by extensions. There being less data that can be slurped up is a win.
>For instance, the browser developer
If you are Google you already trust yourself.
>Different people legitimately have different threat models.
The context of this change is to protect people's privacy from malicious extension developers.
>You seem to trust the browser developer
That is beside the point I'm trying to make.
>I trust the ad-blocker extension developer more than the other parties, so of course I want it to have full acess to block evil behavior.
But do you trust that every web extension that will exist will not abuse that full access? I sure don't. This change isn't because of trustworthy / high quality extensions, but because of malicious and slow extensions. By changing the API exposed Google wants to reduce the number of extensions in that second category without breaking the extensions in the first.
I sure don't.
But that is not in my threat model because I have zero intention of ever installing every web extension that will exist.
In my threat model the evil parties are the advertising/spyware industry (which includes google) so I want powerful browser extensions to help with that problem.
There would be no faster way to nuke the entire product. Which is a good thing.
The reality is that this time, they are taking a good decision, on its own, not because they have to for some reason, and this should be recognized as-is. They took enough bad decisions we can attack, no need to belittle them for this one.
With your point of view, there's no way to tell the truth.
Firefox already has more APIs than Chrome to support content blocking. E.g. DNS uncloaking and reliably blocking content loading on startup is impossible for extensions in Chrome.
Mozilla literally did this back in the version 37 and only Firefox forks remain to support the full set of extension features. I guess we're all amnesiacs or the pot is just being boiled slowly enough to not notice.
The internal APIs also had to go. What else would you do?
Fission (process-per-origin) came later and would have broken many, many more.
So people would have still been pissed off at Mozilla (the difference between levels of breakage would have been lost), and Mozilla would still be on the hook for supporting a barely supportable API. Without the resources that would require.
No. Firefox is adding Manifest 3 support, and people naturally have questions about whether they'll follow Chrome's lead in killing the blocking API.
That metaphor is based on a myth¹:
> While some 19th-century experiments suggested that the underlying premise is true if the heating is sufficiently gradual, according to modern biologists the premise is false: a frog that is gradually heated will jump out. Furthermore, a frog placed into already boiling water will die immediately, not jump out. Changing location is a natural thermoregulation strategy for frogs and other ectotherms, and is necessary for survival in the wild.
And the incorrect usage of the metaphor may give people, such as superkuh, an incorrect model of the world where frogs do not jump out of water that is gradually made more and more uncomfortable.
I like when others make my model of the world more accurate by notifying me of errors.
My least favourite Hacker News trope is when someone assumes ill-intent instead of understanding a comment for what it says.
I did not make a comment on the OP’s larger point, nor do I think their use of the metaphor invalidates their comment.
Dropping XUL wasn't some 'hahah, own the power users' thing, it was a move to allow the Firefox architecture to modernize, with XUL this wasn't possible. I have plenty of criticisms of Mozilla, but simplifying things to the point of removing all important context is not the way to do it imo.
See what I mean?
A /r/firefoxcss mod has a wonderful collection of code snippets that they maintain, which you can browse here: https://mrotherguy.github.io/firefox-csshacks/ and they created a userChrome.js loader here: https://github.com/MrOtherGuy/fx-autoconfig
My favorite customization repository is https://github.com/aminomancer/uc.css.js - which really tests the limits of what is and isn't possible with userChrome.css and .js. My favorite feature is the implementation vertical tabs, without the use of extensions.
Some legacy extensions are maintained and can be found here: https://github.com/xiaoxiaoflood/firefox-scripts/tree/master... (although you will need to use xiaoxiaoflood's userChrome.js loader AFAIK).
Honorable mention goes to the Firefox CSS Store, which can be found here: https://trickypr.github.io/FirefoxCSS-Store.github.io/
Moving to WebExtensions was the logical choice for Firefox, technical/security reasons aside, as they are not alienating extension developers that target Chromium-based browsers.
Yes, they alienated their own extension developers. Yes, they could've handled the transition better, and worked harder towards supporting some of the many APIs/functionalities that extension developers needed (or still need) for their extensions to work in the WebExtensions ecosystem. I myself was quite mad for a very long time at how they handled the switch, but I think overall it's been a success - my own personal feelings aside.
Having no way to properly save/manage sessions feels like I'm one crash away from losing my (way too many) tabs, although luckily that hasn't happened to me for a long time.
And no, I don't want to be told that I should be closing tabs. I have 64Gb RAM and I can search tabs by typing "%" into the url bar. Why should I ever have to close a tab if I don't want to?