µBlock dynamic filtering: default deny
github.com
github.com
hits.theguardian.com points to our Omniture implementation, which is the main tracking suite used for macro-level reporting (like when we say we have X unique monthly browsers, or whatever). So if you want to be invisible to that, leave it blocked.
ophan.theguardian.com points to our own analytics tool, Ophan, which does things like tracks whether you "read" the article. It's for journalists to work out if people like their stuff. All the views of the data are aggregated, but if an analyst really wanted to they could go write some SQL to look at the behavior of individual cookies. So if you want to be invisible to that, leave it blocked. A quick Google [0] will turn up lots more about Ophan and how it works.
Our only calls out to Facebook and Twitter are to retrieve share counts for the current URL (besides articles with embedded tweets, for now). These are probably relatively safe to unblock, but if that information doesn't interest you they're equally safe to block.
api.nextgen.guardianapps.co.uk is handling most Guardian stuff that gets ajaxed onto the page, like suggestions for what to read next. It's pretty harmless and required for a bunch of functionality. All the guim stuff is obviously just static assets.
It would be cute if there was some way of us hinting to the plugin which domains were needed to not break the site, though likely impractical in the real world.
Wouldn't this expose you to tracking by Facebook and Twitter? I would think people are more interested in blocking third-party tracking than first-party.
Thanks for the detailed explanation either way!
I had collated this so far to mostly un-break the site -- for viewing at least:
www.theguardian.com guardianapps.co.uk * noop
www.theguardian.com guim.co.uk * noop
www.theguardian.com theguardian.tv * noop
Whenever I un-break myself a site, I add the proper rules in there: https://github.com/gorhill/uBlock/wiki/Dynamic-filtering:-de...There were 16 3rd-party root domains I found were not needed [1]. Probably fonts.googleapis.com would make the site looks better, but it's up to users whether they want to let Google know they have been visiting what article on the Guardian.
[1] adnxs.com criteo.com doubleclick.net fonts.googleapis.com google.com googleadservices.com googlesyndication.com googletagservices.com gstatic.com imrworldwide.com krxd.net mathtag.com moatads.com ophan.co.uk outbrain.com revsci.net scorecardresearch.com
No advertiser or site looking to cash in on ads would abuse that.
The same goes for the SuperCookie; everyone knows the technology exists, but it's only the rotten apples in the industry ruining it for everyone else by actually making use of it. I got asked whether we would support this a few times, but it was always asked by the most shadiest of our customers, and a simple "we want to listen to the visitor's intent" sufficed.
The only real risk I see for online privacy is that this sort of stuff will happen en-masse and there will be a powerful lobby to illegalize this behaviour.
I wonder if a solution would be to tie third party cookies to the parent page. So that by default a Facebook cookie on a Guardian page could only be retrieved when the user is on the Guardian website. You could then have options within ther browser to explicitly allow cross domain cookies if the user wants (and send the actual Facebook domain cookie).
We actually took that approach to be compliant with the EU's cookie law; if a visitor rejected third party cookies, we fell back to first party cookies.
Sounds like RFC 3514, only negated.
That and Ad Muncher for Windows.
The one problem I've found is that certain services that use a bookmark/iframe combo (instapaper, for instance), create problems because you want to whitelist instapaper, but aren't given a chance. For that, I recently found: https://tsibley.net/provoke-the-privacy-badger/
Most of the time there's no way around that breakage except by allowing the script (unless you use surrogates). So if Ghostery breaks the page and another blocker doesn't, usually that means that the other blocker is not blocking that script.
Adblock Plus lists, for example, contain extensive exceptions to allow scripts/ads on certain broken sites. This improves usability greatly and is a big reason some people are happy with ABP and not Ghostery. This isn't done in the most transparent way though, which leads to people unjustly accusing them of accepting money to allow ads when they find out about these exceptions. (This has nothing to do with the non-intrusive ads feature, which is a separate issue)
I don't see any feature to accomplish this with Ghostery. You can block hosts from its pre-built library of hosts, not more, and not at a higher granular level then whole hosts.
uBlock will report all hosts encountered on a page, not just those part of an internal database.
Unfortunately, Chrome for Android doesn't support extensions [4]. But if you have a rooted device, you can block ads/trackers/etc. across all apps via AdAway [5], which manages a custom HOSTS file for you.
[1] https://www.ghostery.com/en/download
[2] https://github.com/gorhill/uBlock/issues/524
[3] https://github.com/gorhill/uBlock/issues/556
In addition to the extension working on Firefox for Android, Ghostery has it's own browser:
https://play.google.com/store/apps/details?id=com.ghostery.a...
It's pretty new and has some key features that are still in development, but it's getting there.
WRT Firefox, it does not play nicely with Google services, like Gmail. WRT, browsers...I have tried many of them under the sun and all of them have a consistent disadvantage over Google, that is, speed.
I've got many lay users friends who still look for an Ad blocker out of the box, for their mobile devices. I have hope from Ghostery and uBlock makers, fingers crossed.
I know Google is not making things easier[1]. Before every app that used WebView had it. Now Opera is alone with this feature on Android. Implementing it would give you a nice competitive edge and make many users happy. Somehow Opera is able to to do it super elegantly with WebKit code.
[1] https://code.google.com/p/android/issues/detail?id=62378
See:
https://github.com/gorhill/uMatrix/wiki/Changes-from-HTTP-Sw...
https://github.com/gorhill/uMatrix/wiki/Using-%C2%B5Block-wi...
But I can't figure out how to enable deny by default mode?! (Yes I have advanced mode enabled)
Then red the left side of the top five boxes (images and scripts and the like).
If I understand correctly, it's not really a mode, it's just several broad filters. 0.8.5.7 on Firefox doesn't have an 'all' that I can see.
Edit: Would be nice to be able to set those global settings once and not have them pop up on every page. And/or have a visual distinction between global and site specific rules, right now there is no option to globally disable images and then whitelist on a per site basis, right? I can just whitelist a domain which will then load everything?
My initial impression wasthat I could globally blacklist everything I don't want per default and then enable it on a (sub)domain basis.
I'll certainly give this a shot though. My firefox is really slow with ~20ish addons.
Yes you can, it's in the quick guide[1]:
> First column: what is to be dynamically filtered
> Second column: global dynamic filtering rules
> Third column: local dynamic filtering rules
[1] https://github.com/gorhill/uBlock/wiki/Dynamic-filtering:-qu...
This will be my default setup from now on..
PS, I had major issues on two mainstream travel sites with ublock. It made then unusable with ublocksl's default settings.
If you visit test.com, piwki.test.com would work. However, piwik.not-test.com would be blocked.
[1] https://github.com/gorhill/uBlock/issues/564#issuecomment-70...
By default ublock blocks piwik and abp doesn't. That is a major difference.
Edit: why is a factual response down voted?
That's probably the reason it is in EasyPrivacy.
In EasyPrivacy, I see: "||stats.pusher.com^"
When I put "stats.pusher.com" in the browser address bar, I get a page which only says, in plain text:
> Pusher client stats collection service
"stats.pusher.com" is also present in MVPS and hpHosts.
Edit:
The stats.pusher.com issue was brought to EasyPrivacy maintainer: https://forums.lanik.us/viewtopic.php?f=64&t=20744
Reference: https://github.com/gorhill/uBlock/issues/706#issuecomment-73...
Well, you can use what you want. We have no vested interest.
>still not able to block youtube ads, thanks, but no thanks.
But you're wrong, of course. And you've not given enough information for people to accurately help you, if they wanted to do so despite your tone.
On both Chrome and on Opera, with uBlock I don't get YouTube adverts. (Albeit with some more filter tickboxes ticked, which may or may not make a difference.)
If you want to try and get uBlock blocking your YouTube adverts, I'm sure lots of us would be willing assist. More so if you weren't an ass about it.
Edit: I'm using HTML5 instead of Flash, that could be the key difference.
The ads with Flash is only a problem on Safari, due to API limitation on Safari (Chromium/Firefox can block ads with Flash).
As for the filter lists, I think only _EasyList_ is needed for Youtube ads.