Live data from Hacker News

Chrome users beware: Manifest v3 is deceitful and threatening

eff.org

261–270 of 396 posts

Re: Chrome users beware: Manifest v3 is deceitful and threatening

#261

Earlier quoted context omitted.

Chrome has just been getting worse and worse over time, but if you can recall, Firefox was also a slug when it was at a peak of market dominance and before that MSIE... The problem is that orgs and companies stop caring once they gain the primary market share. They also start dictating standards to everyone and ignoring user feedback. It's symptomatic of our current software development driven economy. I recall when…

Mozilla never seemed to get out of that "the user is an idiot, best ignored" mindset even as their market share falls lower than a vendor-specific mobile browser. It's mind-boggling how just about everyone except the people calling the shots in that org can point out the problem.

How do you mean? I use both browsers and, while I certainly wasn't happy with the changes that accompanied their move to WebExtensions back around version 57, I don't find FF these days to be any worse overall than Chrome. Not trying to be argumentative, just not clear on your meaning.

Re: Chrome users beware: Manifest v3 is deceitful and threatening

#262
post #226

stop using spyware like chrome* or brave*. * https://spyware.neocities.org/articles/chrome.html * https://spyware.neocities.org/articles/brave.html

.. or firefox*

* https://spyware.neocities.org/articles/firefox.html

Off the three, brave seems the least worse one in terms of telemetry and the best in terms of respecting it's users' wishes. All are considered spyware by that site.

Re: Chrome users beware: Manifest v3 is deceitful and threatening

#264
post #105
post #19

Earlier quoted context omitted.

I'm just not smart enough to figure that out. That first answer references steps that don't exist on any Chromebook I've ever seen. So I assume I have to enroll the machine in a group policy externally? I have no idea. Never been able to figure it out. I usually just end up installing an extension (oh, the irony) that blocks the extensions domain. :/

> That first answer references steps that don't exist on any Chromebook I've ever seen. That's because Group Policies are a Windows-only thing.

So there isn't a way to disable extension installation on anything other than windows?

Re: Chrome users beware: Manifest v3 is deceitful and threatening

#265

While a good message that does have actual merit if you know what's happening already, I don't see how this is a legitimate consideration of MV3. The entire argument regarding security doesn't mention any of the reasons Chrome developers cite its security improvement, instead it brings up that Firefox "does good enough already" and that malicious extensions can still get past the review process. the review process is…

Yeah, for an article that claims in the title to be adressing Chrome users, it does a very poor job of actually telling these users what this "Manifest v3" thing is and why exactly it's a "raw deal" for them. Provided they even know what a "raw deal" is - for me it's a rarely-used US-specific expression, and I am only aware of it because of an R.E.M. song (https://genius.com/Rem-monty-got-a-raw-deal-lyrics).

Re: Chrome users beware: Manifest v3 is deceitful and threatening

#266
post #188

Earlier quoted context omitted.

I'm not arguing that V3 is better -- I think that's a complicated question, and I was trying to describe some of the tradeoffs. What I am arguing is that V3 does, contra my parent, support request blocking.

It does not allow request blocking as that has been understood in the context of extensions until now It is not a question that V3 breaks the gold standard privacy protecting extension.

I quibble with this. Request blocking "as that has been understood", is preventing the request from leaving the browser. That's still demonstrably doable with mv3. What's changed is the mechanism. You can argue about the value of changing the mechanism, about the burden placed on plugin developers, or the efficacy of various APIs, but the functionality is inarguably still there.

Re: Chrome users beware: Manifest v3 is deceitful and threatening

#267

Earlier quoted context omitted.

Brave said they will keep the v2 capability in their Chromium fork "as long as it's possible" (paraphrasing, I can't find the exact tweet to quote).

Does Brave have their own extension repository yet, or are they still leaving that all up to Google? I don't see much value in Brave supporting a feature dropped from Chrome if it only has Chrome extensions and they all drop support for it anyway.

this kind of thing is why we need firefox, not chromium fork X.

Re: Chrome users beware: Manifest v3 is deceitful and threatening

#268

It's hard to take EFF seriously when they write so hyperbolically. What's clearly also the case is that Chrome extensions are one of the great modern security and privacy challenges --- to the point where multiple tech company security teams have people whose job it is just to screen them. Another detail that EFF doesn't want to share is that ad blockers are some of the worst offenders --- they demand maximal access…

That seems like an unnecessarily uncharitable reading of what they're saying.

We are constantly handing over power to big tech in the name of security, and they inevitably end up using that power against us.

Yes there are shady actors out there, but that doesn't mean we have to give the tech monopolies a monopoly over what are the capabilities of the internet and who can be trusted.

Re: Chrome users beware: Manifest v3 is deceitful and threatening

#269

It's hard to take EFF seriously when they write so hyperbolically. What's clearly also the case is that Chrome extensions are one of the great modern security and privacy challenges --- to the point where multiple tech company security teams have people whose job it is just to screen them. Another detail that EFF doesn't want to share is that ad blockers are some of the worst offenders --- they demand maximal access…

The EFF doesn't need to give "the other side" because the other side is mostly obvious to the target audience (which isn't random people, Google itself is a huge part of the target audience). Note that Google doesn't give the other side either. Also, nothing in politics works like that, if you want to get people to join your cause you don't end everything you say with "But keep in mind that $foo".

Re: Chrome users beware: Manifest v3 is deceitful and threatening

#270
I can see why Chromium-based browsers such as Vivaldi (non-opensource) are increasingly baking in features of popular extensions into the browser (ad-blocker, dark mode).

First, there's the risk of Chrome Web Store simply not being available to non-Chrome flavours. Next, the extensions APIs and ecosystem could head in any direction Google wants.

I use about 6 extensions, 3 of them self-compiled and sideloaded (JSON Viewer, Dark Reader, Violentmonkey).

I wish services like Pushbullet would open-source their browser extension. Isn't all the secret sauce on the server-side anyway?

Post reply on HN