Chrome Users Beware: Manifest V3 Is Deceitful and Threatening (2021)
eff.org
eff.org
> Manifest V3, or Mv3 for short, is outright harmful to privacy efforts. It will restrict the capabilities of web extensions—especially those that are designed to monitor, modify, and compute alongside the conversation your browser has with the websites you visit.
Yes. Exactly! That's the point - it restricts the ability for extensions to monitor, snoop, and steal content from every website you browse.
This isn't the case for extensions and I think it's become clear over the years it can't be fixed with various trust knobs so they're left with fiddling with the capabilities/trying to fix the overly permissive design.
Either it is my device that I own and I can make decisions for or it isn't, and if it doesn't belong to me then who does it belong to?
Hence software publication tied to real-world identity, sandboxing to reduce access to local sensitive data, entitlements to enumerate needs for local capabilities and a review process both to restrict unnecessary entitlements and put additional non-technically-enforceable restrictions on software.
Maybe if GDPR-like regulations were not laxly enforced or non-existent, the platforms would need to do less policing themselves.
I've made browser extensions and I find it difficult to make an informed decision!
I feel like the real solution here is simply to pop up a big scary warning whenever you try to install an extension that says: "Hey, this extension will be able to read and/or modify your internet traffic. It could steal your bank account information. Are you really sure you trust the developer of this thing that much?".
Or, you could make two tiers of extensions, where one tier is the "harmless" tier that can't actually do anything with requests and responses or modify the DOM, and the other is the "advanced" tier that displays the big scary warning above.
But, honestly, that should be about it. There are a few things we need to remember for some context, IMO:
* 99% (made up number) of web users don't install extensions, anyway. This is more true the less savvy the person is. * A web browser isn't going to stop the user from downloading virus.exe or from installing SpyBrowserMaxx.app on their computers, so how much effort is really reasonable to try to prevent users from installing bad extensions? * Hindering good extensions, like uBlockOrigin, actively HARMS the privacy and security of browser users.
Let's not be tricked into giving up our own ability to fight against tracking and spying for the mythical Grandma who installs browser extensions from sketchy side-channels (is that even possible anymore in either Chrome or Firefox?).
Does it though? The webRequest API still exists in MV3, but as read-only. So if you're interested in snooping everything you still can.
> That’s because Manifest V3 doesn’t change the observational APIs available to extensions. (For extension developers, that means Manifest V3 isn’t changing the observational parts of chrome.webRequest.) In other words, Manifest V3 will still allow extensions to observe the same data as before, including what URLs users visit and the contents of pages users visit.[1]
[1] https://www.eff.org/deeplinks/2019/07/googles-plans-chrome-e...
You can still opt into having your data stolen, but now it's no longer a requirement for adblocking.
Manifest V3 doesn't get rid of the permissions that allow an extension to spy on you.
Yes, you can choose not to install extensions that use those permissions (although the current webextension permissions system is chock-full of holes and Manifest V3 still has many of those holes). But you can already make that choice. You can go to Firefox and install Ublock Origin Lite right now today if you want to make that choice: https://addons.mozilla.org/en-US/firefox/addon/ublock-origin...
It's available on both Chrome and Firefox and you can install it and only grant it the blocking permission and nothing else.
Removing the blocking web request API in Manifest V3 does nothing to improve security. It doesn't offer you new choices, it just removes your choice to use a more powerful adblocker if you need one.
Yes, but extensions have to go through review to be in supported channels, and review will absolutely look at over-entitlement of submitted extensions.
Okay, then Google can use that same review process for apps that request access to the blocking API. If you've decided to trust the review process to ferret out unneeded permissions, then copying Firefox's model and having a `blocking` permission should be fine.
Either way, removing blocking webRequests isn't improving anyone's privacy. The same review process is required that would have been required before, and the same kind of spying is possible when that review process fails.
No? OK so it's just another land grab taking more from users and giving it to Google. The enshitification continues, and apparently we should thank Google for the privilege.
The existence of malicious extensions is worth having that ability.
This, but Apple's changes are just as bad and should be used as evidence of how this kind of restriction can go wrong, not how it can go right.
Adblocking capabilities on Safari are unarguably weaker than they are on Chrome and Firefox. People will occasionally get upset at me when I say this, but it's really not debatable, there is a reason why uBlock Origin is not on Safari. There is a reason why the best adblocking apps for Safari run as desktop applications and then communicate with an extension.
Safari has a ton of other great privacy features, but adblocking is not one of them. So when we talk about how Manifest V3 is going to harm adblockers, we have good reason to make that claim -- we can look at Safari and see how it played out when Safari did the same thing.
> That's the point - it restricts the ability for extensions to monitor, snoop, and steal content from every website you browse.
Most of the changes in Manifest V3 are actually pretty good, especially changes around the permission models. Active click is great, the optional permissions improvements are good.
I understand why people are phrasing this as "Manifest V3" because you need a name for it, but I hope it's not lost in this conversation that Firefox is also moving forward with its own implementation of Manifest V3 and it has the vast majority of the privacy improvements and almost none of the downsides.
Getting rid of blocking request handlers doesn't really improve privacy. Active tab permissions and optional runtime permissions improve privacy. When people talk about Manifest V3 being bad, what they usually mean is the extra restrictions Google has imposed on top of the privacy stuff; restrictions that do very little if anything to improve privacy (seriously, it is still trivial to spy on users using Chrome's Manifest V3 across all sites) but that cripple adblockers.
It's possible to get the privacy improvements without the downsides.
This is the only supported model for web extensions under Safari. There are no pure JavaScript distributions, they must be in an app.
Adguard was (I haven't checked in a while, maybe it still is) one of the more popular Safari content blockers for Mac, and it shipped with an Electron app -- and one that had to actually be running with a tray icon and everything at the same time as the browser.
This is not a model that any other browser maker should be trying to copy. I feel like if we're looking at browser adblockers and they're setting up system trays and system-level proxies just so they can do basic stuff like HTML rewriting, then that's not something the browser maker should be proud of. Congrats, people can't spy on your browser's web-traffic anymore, instead they have to MITM their entire computer.
It's possible to make something so restrictive that the end result is that people are actually less secure, because they're forced to compromise security at much lower levels in order to get that basic functionality back. Safari's current extension ecosystem is a great example of that.
Well, we know Apple's answer to that...
Tangentially, I remember how utterly disgusted I was when I first started seeing people on Reddit chastising others for rooting their Android phones. They'd keep saying that it's a "security risk" for me to have root... on MY device. I can feel my blood pressure rising just from typing that...
Your average user doesn't try to copy movies, which is why DRM is accepted in Netflix.
Again, same market pressure, a useful actually used feature will never be removed because people will not buy the device.
Most people don't care about replaceable batteries, headphone jacks or rooting.
In fact not allowing rooting is net benefit for the vast majority because it prevents spyware being installed on the device by a controlling partner, ...
My position is freedom. To create locked-down devices. Or open ones. And freedom for consumers to buy which kind they want. You are taking a position that you know what's best for consumers. That's quite presumptuous.
For most consumers a locked device is in their interest because it protects them from malware and data loss.
The reality is that people in the developed world need to carry smart phones. It's expected in order to be a functioning member of society. My kid's school has an app that does messaging and notifications, my kid's after-school group has a different app that does likewise, etc. A few weeks ago, I was expected to "sign" a waiver for an activity by clicking a link in an email... while I was AT THE PLACE IN QUESTION. Since I didn't happen to bring a laptop to this activity, I pulled out my smart phone to do it.
So, when my phone breaks, I have no choice but to buy another one. It doesn't have to be a new model, of course. But, if they all collectively move toward removing features that I'd prefer to have (like removable batteries) or start adding things that I DON'T want, I'm still going to buy it because I more-or-less have to.
So, it's not that people don't care or actually prefer the way things are going. It's that they feel like they have no choice.
Again, I understand that they/we LITERALLY have a choice. We're not going to die if we don't buy a smart phone. But, it's not as simple as "they bought the thing, so they must approve of all of it."
You are not forced by the evil companies, you are forced by market pressure from the majority of consumers.
Not even Apple was able to resist consumer pressure, they famously yielded and made a big screen phone.
It can be both.
If Apple decided to do something moderately annoying to their phones without considering any user/customer feedback, it wouldn't drastically affect sales.
There's a limit, of course. If they're too hostile, too quickly, then people will buy Android phones instead. But, if it's just a little bit worse for the end user, customers will keep buying iPhones.
Why? Because of vendor lock-in. Why do you think companies have been trying to lock us in to their product ecosystems since the dawn of market economics? It's certainly not to make it EASIER for their customers to "vote with their wallets."
For example, I'd be willing to bet good money that Microsoft didn't start putting ads and shit into Windows 10 or whatever because it really thought that Windows users would just LOVE that. I also bet they didn't decide to re-enable settings during updates that users disabled because the majority of Windows users wanted to have to periodically reapply settings changes that they made...
> Not even Apple was able to resist consumer pressure, they famously yielded and made a big screen phone.
I don't know the internals of what goes on at Apple, but both the small size and the "no-stylus" convictions seemed to be due to Steve Jobs. And I'll note that both, the bigger size phones and the iPad stylus came out at least a couple years after he died. So, it's not obvious to me that Apple would have yielded on those with Jobs at the helm.
When all devices are the same, you have no choice.
That'll mean I'll either drop Google search and directly search SO/reddit and have quicklinks for manpages and other documentation (maybe with GPT help to parse that), or I'll drop chrome at work (i really, really can't work without an ad blocker.).
We wrote the following call to action a couple of years ago in https://www.eff.org/deeplinks/2021/12/googles-manifest-v3-st...
> Google needs to cancel moving to service workers, restore blocking webRequest, and halt Manifest V2 deprecation until all regressions in functionality are addressed.
To their credit, Google did halt MV2 deprecation. They fixed bugs, filled in functionality gaps (examples: userScripts API, the Offscreen API cludge), and made a number of improvements to DNR, their limited-by-design replacement for the powerful and flexible webRequest API. Google also relaxed their initial, entirely unreasonable service worker lifetime requirements.
So where are we now with service workers and DNR?
The requirement to base extensions on service workers adds complexity and headaches to developers, but because of various policy changes and workarounds, it is no longer the issue it was two years ago. Google put in a lot of effort to make service workers kind of work for extensions. I think the end result is it's now harder to make a browser extension, but service workers are no longer a deal breaker.
However, blocking webRequest is still mostly gone, unavailable outside of a specific proxy authentication use case, and DNR is still not an acceptable replacement.
There are still outstanding functionality gaps such as https://github.com/w3c/webextensions/issues/302, which is interesting in that much of the tracking that privacy extensions are no longer able to properly handle is by Google!
But more importantly, DNR is fundamentally not an adequate replacement for webRequest.
As we wrote in https://www.eff.org/deeplinks/2021/12/googles-manifest-v3-st...
> [R]emoving blocking webRequest won’t stop abusive extensions, but will harm privacy and security extensions. If Manifest V3 is merely a step on the way towards a more "safe" (i.e., limited) extensions experience, what will Manifest V4 look like? If the answer is fewer, less-powerful APIs in service of “safety”, users will ultimately suffer. The universe of possible extensions will be limited to what Google explicitly chooses to allow, and creative developers will find they lack the tools to innovate. Meanwhile, extensions that defend user privacy and safety against various threats on the Web will be stuck in the past, unable to adapt as the threats evolve.
The gist is that we now all depend on Google to keep evolving the API to keep up with advertisers and trackers. Google is a massive advertising company. Chrome extensions already had one "lost decade", where nothing much happened until the Manifest V3 proposal.
It's just not a good idea to let Google hold the keys to anti-tracking tech.
EFF had a slew of articles about the evils of MV3 2019 - 2021. Since then, nothing. Has subsequent development proven them wrong - or right? I don't really follow this space closely other than as a user of chrome extensions (in Vivaldi).
They wouldn't be possible to build in Chrome.
Firefox won when it was significantly better than IE in ways that lots of people actually cared about (it had tabs). Then Chrome won when it was significantly than Firefox in ways lots of people cared about (it was fast and if a tab crashed the whole browser didn’t crash with it).
For a long time, no browser has been significantly better than Chrome in ways lots of people care about. I don’t know if Manifest v3 is as bad as everyone says, but if it is, that might open up a big enough point of difference.
Firefox shill here. I believe Chrome won because 1) Firefox had long been struggling with RAM consumption and stability 2) Chrome's onboarding was closer to effortless 3) It was relentlessly marketed/placed to saturation.
Chrome had it's own RAM issues but #3 outweighed that. Any lock-in Chrome now has is due to A) #3, B) a better sync process that's integrated with Gmail and C) better corporate deployment (Gmail+Chrome).
I've had my corp customers on Chrome over Firefox by about 4 to 1. I'm not happy about that but I have to prioritize their experience.
However, Firefox has drastically improved in stability (as has Chrome). Chrome is getting less friendly. Where syncing isn't used, I see paths to swap users over the next year or so.
Firefox is now totally competitive on speed/stability. But it’s not a significantly better browsing experience, which is what it would need to be in order to overcome inertia and get people to switch.
PS: My memory is that Firefox’s RAM issues were pretty awful when Chrome launched (if you had many tabs open it was only a matter of time until the browser crashed). Chrome was a significant improvement in that regard (and Google’s reputation was very good at the time, which probably helped).
4) Chrome was faster, more responsive, and more stable than Firefox since its inception. Firefox reached parity *9* years later, with Firefox Quantum.
Human societies are deliberately designed to disincentivize volunteering or doing anything without getting profiting. These cultures promote the idea that people are only worth what's in their bank account.
So why should people start paying money for things when it's the fault of the developers for choosing to give away their time and work?
I write that as someone who has FOSS projects. If you want to be paid, don't write code or deliver support until you get the paycheck.
So, is exploitation and lying and theft part of our nature? Capitalism only rewards sociopathic behavior. It cannot be prosocial.
https://gs.statcounter.com/browser-market-share
Chrome continues to have a massive lead over any other browser. The only exception is if we look exclusively at the US mobile market, where Safari has a narrow lead; though I'm sure that's because it's enforced by Apple rather than chosen by users. Worldwide across all devices, Chrome and Chromium based browsers have sat comfortably around 80% market share for the better half of the last decade and there's no sign of that changing.
Chrome is not repeating that mistake, most new web APIs come from them.
If they actually focused on bettering their web services they wouldn't need to hold reign over web browsers.
This actually shows that they know themselves their products could not stand up in a real free market.
They’re way to conflicted and financially motivated to do the wrong thing for the user
They keep talking about privacy and security threats. Google is the threat here
Google blog ( https://developer.chrome.com/blog/resuming-the-transition-to... )
"As always, migrating to a new platform is a large undertaking, but we're very hopeful..."
EFF blog ( https://www.eff.org/deeplinks/2021/12/chrome-users-beware-ma... ) - sourced from AdGuard blog ( https://adguard.com/en/blog/manifestv3-timeline.html )
"Nearly all browser extensions as you know them today will be affected in some way..."
But yes, my opinion about MV3 did improve with time. Briefly: it is not ideal, DNR is not a full replacement for the blocking webRequest, but their work for the last several years made me hope that they can compensate for what we're losing by other platform improvements.
edit: grammar
There's a better question: what if instead of investing huge amount of times into DNR they put it somewhere else? For instance, into providing better tools for extensions to persist their state so that we didn't have to rewrite the extensions from scratch to make them work with the new service workers model? I think it would've been much much much better. Unfortunately, that's how hindsight works.
Yeah, at first I thought of using offscreen documents as a replacement, but it appears that:
1. They're not persistent too.
2. They have a different purpose, they're supposed to be used as a temporary crutch that gives access to DOM features for the time until it's brought to service workers.
> persistent service workers
You're right to write it in cursive, there're ways to prolong the lifetime of a service worker, but they're not persistent anyways. All in all, the only reliable way to live with service worker is to rewrite extensions in a way that allows them to very quickly initialize after the service worker is brought back to life. For some extensions it's easy, for some it's quite a complicated task.
edit: formatting
Looking at Adguard recent publication https://adguard.com/en/blog/afds-2023-recap.html it seems more in line than the one from 2021. But still they end with :
>Despite the fact that the Chrome devs spend considerable resources on fixing the MV3, and the dynamic is definitely positive, there are still many questions left.
Edit: for a technical listing of what is not possible with v3 : https://github.com/uBlockOrigin/uBOL-home/wiki/Frequently-as...
A few years ago some new web apps only supported Chrome, like they only supported IE a few years before, but today I haven't had to use Chrome for months.
I might just have been lucky but I don't know. Does anyone else?
Also it integrates better with Google services.
You speaking anecdotally or do you have data?
Rendering/JS performance seems reasonable nowadays, but the UI has weird skips and freezes fairly often.
Maybe one of the extensions I typically use in both works differently in Firefox.
On Windows and macOS Firefox is a bit more competitive, but important benchmarks such as JetStream and Speedometer still have Firefox easily beat (note the inverted score axes).
That doesn't mean Firefox is slow per se, it just means Chromium (and WebKit) are faster.
On Android I use Firefox for its addon support, but the UI is notably more glitchy and buggy than Chrome's.
If a website uses enough JS for that to matter, it's a problem on all browsers
Do I prefer the modern "let's ship a JS renderer with every webpage" approach? No, definitely not. Unfortunately, quite a few web applications and websites u visit disagree with me.
There's also a perceptable difference in terms of browser responsiveness outside the page itself. Firefox seems to take longer to process UI input in my experience, for reasons I don't entirely get. There's a slight but visible delay before the page starts rendering that Chrome doesn't have, and that small delay adds up when you're working in web UIs fir a significant part of the day.
And I haven't found the Google services integration to be all that deep or interesting to matter. In fact, I'd found the opposite to be true: it's gotten in the way. Having the browser log into your Google Account directly has led to some confusing behavior, especially when signing into a second account via some webapp, which sometimes changes how the browser is signed in.
Regardless, I think we all would be better off with a bit less integration of Google services in our lives.
One website on desktop, which I only use chrome (actually edge but I consider them to be the same thing) for because the developers don't take bug reports seriously unless it's Chromium based
I don't speak well the language of the country I currently live in and Chrome really helps. I haven't really found a comparable feature or add-on in other browsers.
I'd switch to Firefox in a heartbeat if it offered a decent version of this.
Includes offline translation. I very rarely need this, so I can’t speak about the quality, though.
Thus it is fair to state they are preventing adblockers.
No it's not fair to say that. The same way it's not fair to say Apple is preventing adblocking in Safari even if the current state of adblocking there RIGHT NOW is exactly how manifest v3 Chrome will be(using declarativeNetRequest)
If there is a checkpoint at an event which seems to be turning away cars it doesn't matter if other cars are also getting through: the way we use the relevant phrasing allows us to say that "they are turning away cars" as that is a bit ambiguous as to why or how many.
If ad-blockers really will be less effective under v3 remains to be seen. But do you think it is an unreasonable perspective, given the technical limitation?
Not saying this to defend MV3. The ad blocking situation for Safari isn’t dire, though.
I use Firefox for everything... except work.
At work we have Google Suite, Google Meet, etm and these do not work as well, as consistently, or with the same features in Firefox.
A specific example, if you have a 1080p webcam you can use this in Firefox and https://webcamtests.com/ will reveal that I have a 1920x1080 FHD webcam @ 50fps ... all good, but Google Meet will only allow 1080p webcams in Chrome.
That's a rich feature example, but even things like Docs behaves subtly differently and a little more rich and fluidly in Chrome.
What this means is that I segment my life by browser, Firefox is my personal life, and I treat Chrome as my work sandbox.
Btw, in 2020 Google was caught red handed shipping broken code to firefox to make it look like broken/slow. Everytime that happens, just open support tickets with your IT dept. That is the only wining move. Otherwise you are just a fool being pushed around :(
(Sure, if you've specifically bought an external webcam so you can have high-quality video chats, that's another story. But I don't think all that many people do that.)
Outside of the webcam issue, I've never had any problems using any of the GSuite webapss with Firefox.
The problem is browser extensions and the ability for bad actors to use malicious code to harm users. This is a real threat - how do you protect users from their own actions?
Putting aside the cynicism about Google's "true" motives and assuming the best intentions on their part... this still seems like an overly broad limitation without a good workaround.
Personally, I use as few extensions as possible, and I'm very particular about which ones. I'm sure most readers here are as well. So, for me (us?), this is a problem, especially if we also maintain extensions. But - what about my mom? She doesn't even know how to remove extensions, never mind review them for potential problems. We should not sacrifice the many (and encourage the bad actors) to ensure that the few have the access they want.
Why not put in settings that allow the user to allow extensions outside the bounds of MV3? Why not put a warning on the extension page that it "could be risky", or even hide those extensions entirely from the users who don't know to adjust their settings?
There's plenty of security/privacy issues that remain after MV3. It's somewhat telling that onBeforeRequest()'s synchronous blocking was the first thing MV3 went after.
It's a false dichotomy. We don't need to sacrifice anybody. Require more consent or an advanced toggle to turn on the allegedly dangerous behavior.
Unless we intend to regress to the mean, people must be educated on how to use powerful tools responsibly, and we must build powerful tools with effective safeguards.
For a while it meant that userscripts didn't have any way to run. So Google introduced a new API for user scripting. But those extensions only run in "developer" mode. I'm guessing that means when devtools are open?
I agree a lot with your premise. It sure seems like Google is targeting everyone with these changes, but that better real affordances & escape hatches need to be builtin to not maim the lives of power users. It took a long long time to come up with a userscript solution, and it seems like an awful doesnt-work-for-me workaround (I use userscripts not to dev but to modify everyday experiences). Chrome just hasn't been taking their obligation to user agency seriously; they can't just start treating everyone as needing huge protective walls all at once.
No, it's a flag you turn on on the extensions settings screen (chrome://extensions/).
I didn't notice that in the announcement of the new API, but that actually seems pretty reasonable for userscripts? It also seems to match what the GP was asking for:
> Why not put in settings that allow the user to allow extensions outside the bounds of MV3
It's ofc not about protecting the user, however.
Google needs to be very specific on this: what precise user-privacy-threatening functionality can an extension have in Firefox's implementation of MV3, that is not also possible in Chrome's? Because if there is actually none, then we have our answer right there.
I don't see how forcing the many to have sub-standard ad-blocking software isn't a sacrifice of its own. Ads and tracking demonstrably harm user privacy.
We have two harms: rogue extensions siphoning off user data, and shitty ad networks eroding user privacy. I don't think we need to choose to solve only one or the other.
And it's not like MV3 really protects users from rogue extensions. It's pretty obvious it's a plan by Google to reduce the effectiveness of ad blockers; the alleged privacy improvements are an unproven excuse.
You fucking educate them.
I’m sick and tired of big tech treating people like children. Sure, in the short term perhaps consider putting fences and whatnot, but come on, general purpose computers are mainstream since at least 1995, we ought to have learned what they are by now.
A very popular extension, Hoverzoom, does the same things I need to do so its author will need the same solution, or severely limit its functionality. ...and I doubt the author will be able to support a proxy service with the volume it would get.
And the secondary effects of it also nerfing adblockers is completely unrelated. It's about user privacy.
V3 only makes it obvious both to users and to the site being requested that there is a man in the middle.
- The browser
- The search engine
- The Ad network
- The device operating system
- Email communications
Plus more money than god to buy dominance where they don't own it. When is it too much control over the primary means of gathering and distributing information in the modern world.
It feels like their current power position even dwarfs MS's at the start of the browser wars.
Nobody gives a rat's ass about the customer anymore because the customer has nowhere else to go.
And now I have one less thing to worry about - my adblocker extension getting compromised through a supply chain attack.
The ambient permissions that uBlock Origin requires on all sites is too risky.
I see it as good hygiene to remove wide ambient permissions.
The Lite version is worse than the original in every way.
I used the lite version while using chromium for a little while and it worked ok for me.
The issue I had with it wasn't that it didn't effectively block ads, it's that you can't block arbitrary elements with the zapper (afaik). I use the element zapper to block non-ad related things sometimes.
For me, I'm torn on whether the extra security is worth this limitation or not, and so far I have went back to using the normal ublock, and I have went back to using firefox because chromium crashed fairly often when using the wayland renderer.
There is some way you can grant ublock lite more permissions on specific sites, I'm not sure what this does, and I don't think it brings back the element zapper, but it would be cool if it did.
But any Chrome users here? Any Chrome users reading this comment? You knew, or should have known, that Google is a snake. You willfully chose to use a browser developed by an advertising company. You've known Firefox was an alternative but you willfully chose not to use it because you placed mild convenience ("Ooooh but chrome is milliseconds faster") before your freedom. You get what you fucking deserve.
I think this should push people towards DNS level blocking (I use nextdns, personally)
"What are we doing differently in Firefox? WebRequest
One of the most controversial changes of Chrome’s MV3 approach is the removal of blocking WebRequest, which provides a level of power and flexibility that is critical to enabling advanced privacy and content blocking features. Unfortunately, that power has also been used to harm users in a variety of ways. Chrome’s solution in MV3 was to define a more narrowly scoped API (declarativeNetRequest) as a replacement. However, this will limit the capabilities of certain types of privacy extensions without adequate replacement.
Mozilla will maintain support for blocking WebRequest in MV3. To maximize compatibility with other browsers, we will also ship support for declarativeNetRequest. We will continue to work with content blockers and other key consumers of this API to identify current and future alternatives where appropriate. Content blocking is one of the most important use cases for extensions, and we are committed to ensuring that Firefox users have access to the best privacy tools available."
https://blog.mozilla.org/addons/2022/05/18/manifest-v3-in-fi...
I wish Mozilla would stand up for their vision of the Web instead of being Google's controlled opposition.
Honestly, the reason most ad-blocking works is because publishers haven't bothered with banning it. And that's because power is concentrated with Big Tech that makes a lot of profit already.
E.g., by blocking ads on YouTube, people are now surprised that there's no alternative left, and now Google can milk those users, too.
I’m asking because it seems to be a flimsy defence, even if it’s currently working well.
Isn't the ultimate answer in this arms race a web proxy?
I'm wondering about a two-part architecture. One part in the browser that can inspect the rendered page, and another part between the browser and the outside world, that can block individual elements. Basically re-implement the Web Request API as a web proxy.
For locked-down environments where you can't run a local proxy, the proxy could be an external service.
It makes me hate the work laptop where I can't use it, and any adblocker is just an inferior experience.
Here's my current annoyances:
– on Android, scrolling and performance is very poor on certain websites, on a high end phone; this including Mastodon, and my report was dismissed;
– on Android, the UI has issues detecting between light and dark modes at the system level; it has other obvious bugs, too, that are reported but remain unfixed;
– poor integration with the OS for player controls; both Android and desktop (macOS);
- unreliable HDR support; in macOS it works, but I sometimes get flicker, and it might get disabled if the viewport is small;
- poor battery life on macOS; this used to be true for Chromium as well, ans Safari is king obviously, but lately Chromium has an edge over Firefox;
– incompatibility with certain online apps, like MS Teams; in fairness they worked hard to fix Meetup at least;
– poor PWA support, no SSB; on both desktop and Android. I prefer PWAs to Electron variants: better sandboxing, use of browser extensions, often better memory use; see: https://howfuguismybrowser.dev/
– no customizable keyboard shortcuts and poor accessibility preventing OS-level solutions; in macOS I can set shortcuts for Chrome, for various Tab actions, like Pin Tab or Close Others. And Brave/Vivaldi have customization built into their settings;
— poor extensions security: for LanguageTool or Google Translate I'd like the "Click to Enable" option or the ability to disable by default or enable per-hostname;
– unusable profiles – in Chrome different profiles have different history and extensions, so for security purposes they are above Firefox's containers; I actually don't get the point of Containers at all, being useful only for logging into multiple AWS accounts, otherwise they have no privacy or security benefits;
---
Firefox does have certain advantages. They aren't enough to keep me using it, though. But in the interest of fairness:
+ History sync actually works;
+ DNS-Over-HTTPS works with fallback to system;
+ Tree-style-tabs;
+ Better bookmark management;
+ Reader view (Android & desktop);
+ Ctrl+Tab;
+ Non-admin upgrades;
+ uBlock Origin;
+ Total Cookie Protection;
+ Android: multiple search engines;
+ Android: Open in app;
+ Android: Dark reader / uBlock Origin / other extensions;
FF has those kinds of profiles too, if you want to you can start it once using the ProfileManager from the command line, (un-)check the box asking if you want to always default to the last profile used or instead always start FF in the ProfileManager UI from now on, so you can choose on each startup. These profiles are completely separated as well, have their own histories, bookmarks, cookie jars, extensions etc.
FF's Containers on the other hand are a less heavy-handed approach, by staying in the same profile, having the same bookmarks, extensions and history but fully separating the cookie jars, enabling you to have (just as an example) Facebook in its own little world, everything else outside that container and/or in their own specific containers, unable to cross-contaminate (to track you) with third-party cookies and the like.
Basically, profiles and containers are entirely different levels of sandboxing.
You don't need a Facebook container, at least since “Total Cookie Protection”. Which itself it's just a better way to “disable 3rd party cookies”, that doesn't break websites, although Firefox's isolation goes beyond just cookies.
https://blog.mozilla.org/en/products/firefox/firefox-rolls-o...
And Firefox isn't the only one that does it, although it may be the best. But Safari, Brave Browser and even Chrome have deployed similar protections. See for instance: https://brave.com/privacy-updates/7-ephemeral-storage/
> You don't need a Facebook container, at least since “Total Cookie Protection”.
It's theater because it does nothing in addition to what Firefox already does without use of containers.
But keep installing that add-on if it makes you feel good.
It's just not a good idea to let Google hold the keys to anti-tracking tech.
And I say this as someone who still uses quite a few Google services. I've managed to get myself off GMail, but it's been a lot harder to ditch the office apps, and Photos.