Google resumes transition to Manifest V3 for Chrome extensions
developer.chrome.com
developer.chrome.com
If it's not Manifest V3 that makes the Internet safe for advertising, it'll be a "browser integrity" token or some other kind of DRM-by-another-name. Google has made it clear with YouTube that the arms race is on, and sooner or later they'll go nuclear.
I am mostly a Firefox user, at least until it stays around.
It’s probably successful in that it’s a well known project within the tech community. And 0.05% of the global browser market is a lot of users and probably a decent business. (Are they profitable?)
But outside of HN type audiences, no one has heard of it.
They won't stop. Ever.
Hmm...
My workplace banned the use of Brave a number of weeks back because Brave started including a VPN with it. They were concerned about people using the VPN to bypass corporate security mechanisms.
If Chrome did the same, I wonder if they'd ban that as well?
Doesn't uBlock currently block youtube ads by blocking requests based on XHR content? This will kill that.
However, going without any Youtube is difficult. There's a lot of interesting content out there. Do you use an alternative way to access it, or go without it entirely?
I started hosting Viewtube app hoping I'll catch up, but while it's quite amazing (surprisingly light and emulates subscriptions behavior for you), I had issues with it... So as for now I remain mostly cut off.
There is a lot of great dev and ops related content (conferences) that I come back for, but not for subscriptions I used to love.
uBlock Origin works best in Firefox: https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b...
So, no: Firefox will NOT save you.
Chrome is built to serve Google's interests, which is exactly as you'd expect.
Use Firefox for a web which better balances the competing interests of corporations and end users.
So no, on our present course, Firefox will not save us. And even if every HN reader used it, that wouldn't even come close to pushing its usage share out of the single digits.
There are countless banks out there. I have bank accounts with several different institutions in two different countries and they all work fine with Firefox + uBO. If yours doesn't, why are you supporting them?
>Also, crank your browser's privacy settings too high, and any website with twitchy Cloudflare settings will give you the sisyphean "I'm not a bot" check box until you give up and go away (or come back with a Chrome that's hungry for cookies).
I haven't seen this. If a website is too much of a PITA to use, I just won't use it, and I suggest you do the same.
Don't use that bank.
> Also, crank your browser's privacy settings too high, and any website with twitchy Cloudflare settings will give you the sisyphean "I'm not a bot" check box
Don't use that website.
It's certainly true that you have no agency or self respect if you embrace a defeatist and submissive outlook.
So don't do that.
https://www.bankofamerica.com/information/supported-browsers...
You're nitpicking, there are lots of corporate sites that only test against Chrome/Safari these days. I'd love it if Firefox would regain popularity, and Chrome would lose its stranglehold, but let's not stick our heads in the sand about the way things are going.
The situation in the example you cited has improved. You're undermining your own position.
Use Firefox and be happy.
Even if it's my bank -- there are other methods of doing business with most banks, after all. And if my bank, for whatever reason, can only be dealt with through their website then I'd change banks in a heartbeat.
Edit: an example is Windows 11 requiring new enough processors for security reasons even though it would run on older PCs.
The question is whether that atmosphere would simply cause people to quit Google services vs. turn off Adblock altogether to continue using them. I would wager that the latter would be far more likely and common for the average person.
That said, I have fond memories of installing Linux on my iPod Mini so I understand the joy of making devices do things they were never intended to do.
Or they just keep making it harder and harder to use alternative browsers that support ad blocking.
The collateral damage from that would probably lead to the mother and father of all class-action lawsuits, literal Acts of Congress, and EU fines that Google would have to get a second job in order to pay if they don't try to break them up outright.
One could argue that Google can "kill" Mozilla easier than it can "kill" uBlock.
but policy decisions aren't like technical ones.... principles are at play at every layer above the strictly-technical discussion
You make a good case to use Firefox.
Still not a case against Firefox; just pointing out there's more to the picture.
Maybe I'm old, but doing the right thing on the internet has always been harder than just going with the flow. Using Linux in 2000 was very hard, using Firefox in 2001 was no walk in the park - but one gotta do what one gotta do, if one has some principles.
Another example is that Mozilla has a LOT to lose if the DOJ wins in the US v. Google antitrust trial just for those deals.
there are things that through symbolism come to signify life-or-death scenario across different contexts (i.e. life or dead of what-exactly?)
these "ad-tech" wars aren't about technology as much as they (really) are about (the future?) of user freedom.
freedom is the key word (symbol) which links this difficult real world contest into the nuclear leagues
Anyone here know more about this?
From the article linked in that quote:
> We determined that some filter rules, such as those with an action of block or allow, are much safer and are less likely to be abused. They also happen to make up the large majority of ad block filter rules. Based on this, I drafted and shared a proposal in the Web Extensions Community Group to define a set of rules that we consider lower risk and allow up to 30,000 of these.
From what I remember of the discourse at the time Manifest v3 was first announced, the most major complaint from developers who were otherwise open to the idea of static filters was that the number of filters allowed was way too small for the modern web.
Google's proposed changes seem to address that, maybe? I don't know how effective they are in practice.
The fundamental problem is that DNR is not an adequate replacement for webRequest. From something I wrote[2] a couple of years ago:
> [R]emoving blocking webRequest won’t stop abusive extensions, but will harm privacy and security extensions. If Manifest V3 is merely a step on the way towards a more "safe" (i.e., limited) extensions experience, what will Manifest V4 look like? If the answer is fewer, less-powerful APIs in service of “safety”, users will ultimately suffer. The universe of possible extensions will be limited to what Google explicitly chooses to allow, and creative developers will find they lack the tools to innovate. Meanwhile, extensions that defend user privacy and safety against various threats on the Web will be stuck in the past, unable to adapt as the threats evolve.
[1] https://github.com/w3c/webextensions/issues/302
[2] https://www.eff.org/deeplinks/2021/12/googles-manifest-v3-st...
If the things continue to develop the way they are now, the new features will be eventually incorporated into DNR (in somewhat different form, but anyways). Basically, the “innovation” should be requested via the W3C group from the browsers and only then (after quite some time) it can be used as a part of DNR.
Is it worse than what we had before? Absolutely, adding anything to DNR is now a many-months process.
Do we get anything in return? We actually do, the changes and improvements that are being made to the extensions platform are significant.
I’d say that the situation changed from “MV3 is bad, DNR is unusable” to “MV3 is good, DNR is useable-but-limited”.
Honest question, what kind of significant improvements do you actually see in MV3? I see a lot of more restriced, more complex APIs but few new features.
Let me name a few examples.
1. chrome.scripting API and the concept of "isolated worlds" is easier to use and understand than what we had before.
2. Dynamic content scripts registration that everyone has waited for so long.
3. userScripts API is also a welcome addition. It does not provide everything and it needs to be improved, but it is already a good step forward. Finally the existence of userscript managers was recognized by Chrome and they're trying to make life easier for them.
Also, the bug fixes. Before the expansion of the extensions platform team there were major bugs that could be open for many years, and now I see them closing one by one. To an outside observer it may look ridiculous that there was such a problem from the start, but that's how underinvestment looks like and I am happy that the situation improves.
Even DNR is not a bad API by itself, the problem that was never addressed is that in MV3 there is no blocking webRequest anymore and DNR cannot fully replace it.
edit: formatting
> the concept of "isolated worlds" is easier to use and understand than what we had before.
Isn't this basically the same concept they already used with ordinary content scripts for years? It's indeed useful, but also something that could have been relatively easily emulated with dynamic execution inside a content script before, I believe.
> 2. Dynamic content scripts registration that everyone has waited for so long.
3. userScripts API is also a welcome addition.
Yes, but those too are just an improvement compared to the previous state of MV3. In MV2 none of those APIs would even be necessary because an extension could easily implement this stuff itself. So it's an "improvement" in the sense that it now only removes 30% of the functionality instead of the 50% it did before.
> Also, the bug fixes.
That's orthogonal to MV3 though. And it again sounds like "we're now slightly less shitty to extension devs than we were before".
> Even DNR is not a bad API by itself, the problem that was never addressed is that in MV3 there is no blocking webRequest anymore and DNR cannot fully replace it.
It's indeed not a bad API and there are many use cases in which it's clearly the better choice than the blocking version. However, the removal of the blocking variant and the removal of various usecases is Google's entire point here - otherwise, they wouldn't be so cagey with setting the limits of the number of rules. Firefox shows that it's no technical problem at all to implement both APIs at the same time.
It was implicit, now it's explicit and it gives more control and better understanding. It also allows introducing more levels of isolation, like a separate "USER_SCRIPTS" world or "MAIN", before that you had to mess with evals and adding script tags.
> Yes, but those too are just an improvement compared to the previous state of MV3
Yes, that's why I listed these as improvements.
> And it again sounds like "we're now slightly less shitty to extension devs than we were before".
They went from "1 person that tries to make things not crumble" to a large team of developers, it's a big step forward. What signal do we send them if we always say "everything you're doing is bad" even when it's factually not true?
> Firefox shows that it's no technical problem at all to implement both APIs at the same time.
At first we all thought that DNR is there for them to limit content blockers. With time they proved us wrong when they worked hard on improving it and covering more and more use cases.
Now I tend to think that this is an engineering decision that's driven by the other change - the shift from persistent background pages to service workers.
Is there a better solution that could save the blocking webRequest and achieving their goals at the same time? Most likely there is, but how hard would it be to implement it instead or what if it requires an architectural change? Anyways, these are speculations, I am with you here and I don't support blocking webRequest removal.
I am not comfortable making that assumption! We already went through one "lost decade" for Chrome extensions.
Ironically, this might be a market opportunity for MS to get a few users back to chrome's poor cousin Edge, if they allow proper extensions again.
They also give detailed steps on how to configure the DNS settings for a given browser or device.
https://mullvad.net/en/help/dns-over-https-and-dns-over-tls#...
I don't really care anyway. Chrome is not the internet. Just use Firefox.
If some mechanism or capability is no longer possible or is made infeasible for adblockers to control, then ads will simply switch to using that mechanism. It's a pretty obvious outcome. You cannot simply give just an inch with adtech.
- Now any block filter list will have be updated with a plugin update. So no fetching lists from links directly.
- strict blocking ability [1]
- No dynamic filtering [2]
- No Custom lists (own or third party by the user)
- Element Picker [3]
[1] https://github.com/gorhill/uBlock/wiki/Strict-blocking [2] https://github.com/gorhill/uBlock/wiki/Blocking-mode [3] https://github.com/gorhill/uBlock/wiki/Element-picker
https://github.com/w3c/webextensions/issues/151#issuecomment...
Google is an advertising company. Chrome extensions already experienced a lost decade, where nothing much happened until the Manifest V3 "proposal". It's not a good idea to let Google hold the keys to anti-tracking tech.
[1] I stand corrected, DNS lookups are not part of webRequest in MV2 Chrome either. This doesn't change my larger point.
But Chrome never had CNAME filtering before either
That approach doesn't work well given Firefox's established track record of just imitating Chrome, and then getting rid of the prior (and better) way of doing things.
XUL extension developers are well aware of this problem, for example.
We've seen it happen repeatedly with Firefox's UI, too.
Established track record? What?
> and then getting rid of the prior (and better) way of doing things.
Do you mean how they did the complete opposite by keeping Manifest v2 around for much longer than Google wanted to? Then by making their own Manifest v3 that didn't gimp ad blockers like google has been trying to for years?
> XUL extension developers are well aware of this problem, for example.
XUL was super useful... for it's time.
But it became a drag on performance as Firefox became more optimised for multi-core CPUs. And it became a drag for developers trying to support an older standard. Sure the new extension standard became more difficult to get started, but it did push the workers standards forwards which is ultimately what the web needed.
> We've seen it happen repeatedly with Firefox's UI, too.
Firefox's UI goes up and down in quality all the time. Thinking nothing is improving at all is an observational bias.
That said, it's not like there's a large amount of choice in the browser space. Today's Firefox can be worse (in ways that are important to you & I) than yesterday's but still be the best of the options available to us today.
My opinion, and the reason I switched back to FF, is that FF is the "least bad" option we have.
And they aren't afraid to diverge from Chrome in important ways. For example, letting you disable 3p cookies already.
[0] https://github.com/brave/adblock-rust [1] https://twitter.com/brave/status/1574822799700541446
In typical internet mob fashion Apple doing this is considered doubleplusgood, Google doing it is them being evil and trying to kill the Internet.
It wasn't actually considered good that Apple killed the safariextz format. There were a ton of complaints among Safari users.
But of course Safari for Mac has a small marketshare, given its nonexistence on Windows (since Safari for Windows was discontinued in 2012), so it can't kill the Internet. On the other hand, plenty of people think that Apple's browser engine restrictions on iOS are killing the Internet.
Apple and Google have drastically different profit incentives.
https://www.wired.com/story/apple-is-an-ad-company-now/
https://www.searchenginejournal.com/apple-ad-network-gives-m...
https://seekingalpha.com/article/4578462-apples-new-strategy...
There isn't though. Safari is one of the most complained about pieces of software on here. Actually I wouldn't be surprised if it was the most complained about.
Second, Google is hostile towards users. Apple isn’t. This means they would use the same mechanism for different purposes.
Apple has neither Chrome's market share nor Google's advertising network. Context matters.
The context is that an entity that does not give a crap about making ad blocking hard (Apple) believes that this is the best design for content blocking extensions. They have no ulterior motive, it's just obviously the right technical design.
"Alphabet pays Apple 36% of Safari search revenue, Sundar Pichai confirms" https://www.cnbc.com/2023/11/14/google-pays-apple-36percent-...
> it's just obviously the right technical design.
Setting aside the question of motives, Safari engineers designed their content blocking system (1) without any actual experience in developing ad blocking extensions and (2) without consulting the developers who do have such experience.
Moreover, ad blocking extension developers are practically unanimous in saying that Safari content blockers are inferior and not obviously the right technical design.
I have yet to find an ad blocker that manages to block anywhere close to as many ads as ublock origin. AdGuard is certainly better than nothing at all, but I still see an awful lot of ads while using it.
An advertising company investing in a new API that will make it earn less – that's the point.
Outlawing dynamic code (use of eval for example) is a huge locking down of the system, one I have some sympathy for but also think deeply narrows the type of extensions that can be built, in a chilling way.
I use this all the time just to improve websites I visit, change colors or adjust workflows to make them less jank. My work jira is reskinned with violet monkey.
They're called userscripts. Making folks have to enter a dev mode to use them feels abominable.
Also seems like this narrowly targets just userscripting cases, while ignoring any other use cases where we might want to have dynamic behavior. It still doesn't allow me to write an extension that lets me ship up code & run it. I get this is by design, to improve security, but it feels so much less like my user agent when I'm outlawed from running whole categories of code in the browser.
My best hope is that many of the dynamic code practices are enforced chiefly by the web store. And that we can sideload whatever we want.
Do you control your browser? Manifest V2 you can write a plugin to modify the page in pretty much any way. This is used by adblockers but philisophically important because this is no longer possible in V3 in the name of security. Instead chrome mitigated the adblock concern in-particular.
But manifest v2 isn't actually disappearing, it's a chrome web store policy. You can still manually install the crx.
It is actually disappearing. Re-read the announcement. Google Chrome will be disabling MV2 extensions. It's not just a Web Store policy.
My read was that they’ll disable existing installs (which may be manually re-enable-able by the user), and they definitely won’t let users install them from the Chrome webstore. But it isn’t clear whether these can be sideloaded. My guess is that it will depend on how the rollout goes, and what the antitrust landscape looks like.
> What would be the point of saying “you can’t install from the Chrome webstore” if they’re permanently disabling them and not allowing sideloading?
It's a gradual rollout:
"We will begin disabling Manifest V2 extensions in pre-stable versions of Chrome (Dev, Canary, and Beta) as early as June 2024, in Chrome 127 and later. Users impacted by the rollout will see Manifest V2 extensions automatically disabled in their browser and will no longer be able to install Manifest V2 extensions from the Chrome Web Store. Also in June 2024, Manifest V2 extensions will lose their Featured badge in the Chrome Web Store if they currently have one.
We will gradually roll out this change, gathering user feedback and collecting data to make sure Chrome users understand the change and what actions they can take to find alternative, up-to-date extensions."
MV2 extensions will remain in the Chrome Web Store for some time. The rollout starts in the pre-release Chrome channels and eventually moves to the stable channel. So Chrome canary users will start seeing MV2 disabled even while Chrome stable users can continue to install and use MV2 extensions. Even the stable release will be a gradual rollout.
Let me ask you the reverse question: What would be the point of toggling off MV2 extensions if users could just immediately open the Extensions window and toggle them right back on? That would be a pointless, silly waste of time and effort. Google is not that dumb.
The point would be to get people off MV2 by default, but giving themselves more cover on the antitrust front by technically still allowing people to use these extensions.
Given the ways in which the story has changed about this rollout, my default is to assume that nothing that is projected is set in stone. This is certainly the case for things that have been left unsaid, like the possibility of sideloading.
There's no antitrust front on the MV2 to MV3 transition. You're imagining something that doesn't exist.
> Given the ways in which the story has changed about this rollout, my default is to assume that nothing that is projected is set in stone.
That's fine, and Google itself said in the announcement that they're doing a slow rollout in order to collect data and see the effects, but it has nothing to do with antitrust. The MV2 deprecation was delayed because Chrome extension developers complained that MV3 still had serious shortcomings that prevented them from migrating their extensions from MV2, so Google paused to address many of those issues.
My understanding is that there is a widespread perception that the transition is largely being executed to neuter adblockers since Google makes so much money on ads. Given how aggressive the federal antitrust authorities have been in pursuing novel claims, I could easily see them going after Google if they prevent users from accessing MV2 extensions at all.
Like I said, you're imagining something that doesn't exist.
There are several points worth noting:
1) Mobile Chrome doesn't even have extension support. This transition affects only desktop.
2) Chrome is not the default web browser on either Windows or Mac.
3) Chrome's Declarative Net Request API is very similar to Safari's content blocker API.
4) Given what Adguard says about MV3 on their blog and indeed in HN comments on this thread, such an imagined antitrust case would seem very hard to win. https://adguard.com/en/blog/chrome-manifest-v3-where-we-stan...
5) I suspect that the majority of desktop Chrome users don't even have ad blocking extensions installed in the first place.
The more I think about this, the closer I come to the conclusion that an antitrust case here is wildly implausible.
My point is that this is Lina Khan's specialty. Everyone knows it, and Google is undoubtedly calibrating many of their business decisions to make sure that they don't attract scrutiny. This would be especially true where the product involved has over 60% market share globally.
So what? I've already explained in detail why there's no case here. I would hope that Khan isn't dumb enough to start a futile, unwinnable fight.
Google has plenty of antitrust problems, for example, paying Apple $billions per year to be the default search engine on iOS. But the desktop Chrome extension API is not one of those problems.
> Google is undoubtedly calibrating many of their business decisions to make sure that they don't attract scrutiny.
The word "undoubtedly" is incorrect. I'm explicitly doubting you. Not to mention that if Google was actually worried, they wouldn't be doing this extension transition in the first place.
The schedule was pushed back. That's the only change. Could the schedule be pushed back again? Perhaps. But speculations about various other unspecified changes are entirely imagined and not based on the evidence.
> If you have an inside scoop on how this is unfolding inside Google, or have worked there in the past, then you'd be in a better position to know.
I'm a professional browser extension developer and have been watching this closely for quite some time, for obvious reasons.
Only time will tell what Google will do; look forward to seeing your opinions as this continues to unfold.
Disabling them is not good though and removing from web store is a death sentence for commercial apps.
You are wrong. Disabling them means that they won't work, end of story. Dead. Gone.
Browser makers like Brave build the adblocker directly into the browser, so they don't have to care what extensions are and are not allowed to do on Chromium.
Ublock Origin has been the best for almost a decade running and is most powerful when running on Firefox.
Raymond "Gorhill" Hill is the BDFL of Ublock Origin and has never accepted any money from ad companies and has never added/removed any feature that weakens the adblocking.