uBlock Origin via declarative blocks is almost as powerful as the original. While I would trust gorhill with almost unfettered control over my browser, I don't trust EVERY extension owner (no do I trust uBlock Origin in perpetuity).
uBlock Origin via declarative blocks is almost as powerful as the original. While I would trust gorhill with almost unfettered control over my browser, I don't trust EVERY extension owner (no do I trust uBlock Origin in perpetuity).
A funny argument to make because the thing that would make such a measure ridiculous as you rightly point out, is exactly what already makes the Manifest changes ridiculous in the first instance. They were making a rhetorical point and you elaborated on their point for them as if doing so expressed a disagreement.
Are you trying to say that Mozilla/Firefox is engaging in the same data harvesting, usage, and dissemination that Google is?
If you don't like what a browser is doing, then move to another one? You're acting like you have spent a tonne of money on buying Chrome. Even if that was the case, it's not a clear case of an anti-user behaviour. There is a good reason to deprecate the webRequest API, and we'll see more browsers move towards that in the future (Safari has had declarative blocking for many years now, I believe).
>preventing modifications (and thus also repairs) is anti-competitive
There is nothing stopping someone from forking a manifest v2 version and maintaining it. I'd argue this can't be compared to any company actually doing anti-competitive things (e.g. tractor company, printers, ice cream machine companies, etc.)
An adblocker, by its nature, needs to access *. But Return YouTube Dislike could statically specify that it will only run on youtube.com, and that's fine.
But the option to enable access to * is essential.
Well that's what is in contention. Does everything claiming to be an adblocker really need access to *? Is Adblocker5++ (totally not malware) entitled to as much access as uBlock Origin? You can declare upfront all the URLs you don't want accessed (which on top of security gives a substantial performance boost), and who's to say someone won't figure out a better way of working within these constraints?
"Please stop looking at all network requests, especially when you don't need to."
doesn't result in action... while:
"You can no longer look at all network requests" requires extension makers to update to the new paradigm.
It's not "please stop looking at network requests", it's "ask the user for informed consent to look at network requests". Make it a big scary red warning if you want to. Definitely don't auto-grant it to existing extensions.
There are many options that don't involve removing functionality. It's like when Google removed SMS and clipboard permissions because they used to be too broad. People were pissed, a bunch of apps were killed, Google's walled garden got reinforced...
Scare prompt fatigue is real. If you're constantly blasting users with "XXX wants to do Y" which sounds scary, you're training them to just accept without thinking.
You fix an insecure implementation by replacing it with a secure implementation, not removing the feature completely.