I'm now routing my traffic through a PiHole via a VPN to cut down the worst ads and will probably never install another extension.
I'm now routing my traffic through a PiHole via a VPN to cut down the worst ads and will probably never install another extension.
Be aware that if you use these "passive" blocking methods, there are some sites like YouTube where you will see ads, because in these cases it's necessary to actually manipulate page content to hide them. What you can do is use a traditional adblocker but enable it only for these few sites where the declarative approach is not enough, take a look at [3] for more details.
[1] https://github.com/uBlockOrigin/uBOL-home
[2] https://github.com/StevenBlack/hosts
[3] https://seirdy.one/posts/2022/06/04/layered-content-blocking...
For TGS I use the last known good version, as an "unpacked" extension.
I think this approach of taking ownership of the code (i.e. running the extension "manually") is the best option, aside from two critical factors: skill and effort.
(Not very much of either is needed, if you know basic JavaScript, but it's a significant "mental hurdle".)
(I've never heard of them; this is a fundamental problem with using centralized "privacy preserving" services.)
https://en.wikipedia.org/wiki/Watering_hole_attack
I think ublock origin is a bit better, in that it is open source. Does it support reproducible builds though?
https://github.com/orgs/nextdns/repositories?type=all
https://github.com/AdguardTeam/AdGuardSDNSFilter
If you don't trust their DNS servers for whatever reason, you can simply add these entries to your hosts file to replicate their functionality locally.
If you want to have all the data under you control, there's this: https://github.com/AdguardTeam/AdGuardHome
Regarding open source, AdGuard DNS actually is: https://github.com/AdguardTeam/AdGuardDNS
In the case of AdGuard DNS being open source does not change the fact that it is a centralized service and using such a service is a matter of trust.
Besides, I don't know what a paying-customer relationship has to do with trust. I could just as easily be betrayed by someone I'm paying. For example, GrubHub drivers have a chronic problem of "losing" my drinks, despite being promised a tip and wages. I have to go chase refunds every day for these "mistakes". I'm a paying customer, yet I can't trust them to get my order right.
They have more variations like social media block and instructions for using it at https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/
Sure, Google wants to architect things so that ad blockers as we know them now aren't really feasible. But I think that we can conceded that Google has a good point in saying these world-read-write-anything extensions are not good for us.
The biggest issues with extensions are things like silent updates (perhaps after the developer sold their extension to a bad actor) and extensions that depend on online resources. An extension that you've verified does what it claims to and nothing else, can read/write everything, doesn't update automatically, and never sends data to random servers isn't a problem at all.
Conceivably, this could mostly be accomplished without the extension being able to see all content. Such as manipulation by regexp.
It's like a pipeline in Bash. You could work with an end-user to build some patterns to match, then pass them to "grep" or "perl" for processing, and neither the user nor shell need to be privy to a file's contents.
Apple doesn't trust you to write your own JavaScript engine, for instance. You have to use Apple's.
On the Play Store side, the ability to download executable code has proven to be an issue, as you mention.
> Known as Joker, this family of malicious apps has been attacking Android users since late 2016 and more recently has become one of the most common Android threats.
One of the keys to Joker’s success is its roundabout way of attack. The apps are knockoffs of legitimate apps and, when downloaded from Play or a different market, contain no malicious code other than a “dropper.” After a delay of hours or even days, the dropper, which is heavily obfuscated and contains just a few lines of code, downloads a malicious component and drops it into the app.
https://arstechnica.com/information-technology/2020/09/joker...
If you have an established extension and push an update, odds are there will be no human review of the code changes. That is how most malicious extensions happen.
Sure, Mozilla historically had less malicious extensions than Chrome. But that's for the same reason that Linux has less viruses than Windows: hackers will target the 90% of users and not waste time on the rest.
I say all this as a staunch Firefox user and maintainer of a handful of extensions.
Open question about that for me though, is after the initial review is done, do they audit the updates? Something tells me that may not be the case.
[0]: https://support.mozilla.org/en-US/kb/recommended-extensions-...
Mozilla mostly doesn't review source code either, except for a small number of select, popular extensions.
Any Mozilla extension that has the recommended extension badge has been through a an extended review process.
As usual, Google avoids hiring human beings in any user support role.