Live data from Hacker News

The FBI now recommends using an ad blocker when searching the web

standard.co.uk

241–250 of 445 posts

Re: The FBI now recommends using an ad blocker when searching the web

#241
post #24

Earlier quoted context omitted.

Acting like you don't know what a real browser means in this context just so you can be mock offended. Oh you Apple users.

Safari is clearly a real web browser, you can use it to browse the web. It is a weird comment, the more straightforward and honest way of putting it would be “alternative browsers.”

Safari is real. People mean Chrome or Firefox on iOS are not real because they are just skins for Safari.

Re: The FBI now recommends using an ad blocker when searching the web

#242

Pretty late to the game there, FBI. There are examples going back decades of drive by downloads and exploits from ads on popular websites. It's not enough to avoid shady websites. Any website filled with ads is already a shady website.

Any good case studies to back this up? I’m interested to read more into it.

Some older articles:

https://www.pcworld.com/article/435020/hackers-make-driveby-...

https://money.cnn.com/2013/02/22/technology/security/nbc-com...

https://blog.fox-it.com/2014/01/03/malicious-advertisements-...

https://www.cbsnews.com/news/huffpo-readers-hit-with-ransomw...

Re: The FBI now recommends using an ad blocker when searching the web

#243

Earlier quoted context omitted.

uBlock Origin URL filter lists don't work the same as ClearURLs. Privacy Badger is an extension by the EFF. It blocks cookies, that's it. The other one I don't know, but you should stop being condescending when teaching people about things you don't know about. Using uBlock Origin only might be a good option for some cases, but it's not a silver bullet. For reference, ClearURLs can bypass redirects, has etags protect…

Original commenter is right about the feature obsolescence and didn't seem condescending to me. Just more or less critical of the general idea, as one doesn't really need so many extensions for privacy, which most of the list appeared to be tackling. That said, URL filtering isn't necessarily effective at keeping your behavior private either. There's an argument to be made about ClearURLs and URL filtering in general…

   > Original commenter is right about the feature obsolescence and didn't seem condescending to me
Maybe it wasn't, intention and tone are really hard to get through text, that's just how it felt to me when I read it.

   > That said, URL filtering isn't necessarily effective at keeping your behavior private either. There's an argument to be made about ClearURLs and URL filtering in general being counter intuitive, as you might stick out among a sea of other users with marketing params in their URLs.
I'm personally kind of torn on this kind of thing, because fingerprinting is the default in the www since you expose your IP to every server you connect to. I personally believe it's worth to try and reclaim the privacy even if it could expose to even more advanced tracking techniques. Also things like removing google analytics tags and removing the "google.com" of urls in google searches is probably really effective. (you'll notice that Google only adds this redirect mechanism if you have JavaScript disabled, probably because they don't need that if you're running JavaScript anyways).

   > Still wishing for a Tor-like solution to anonymizing all users on a browser configuration level.
One can wish. I'm very pessimistic about Tor and i2p though, the market incentives to block these networks are just too great to ignore for most business. Ultimately though I believe the problem is that privacy is not a computers problem but a human one.

Re: The FBI now recommends using an ad blocker when searching the web

#244

I recommend using an ad-blocker while visiting that site :-/ Lately, I find myself using more and more plugins to make the "modern web" tolerable. To list a few: Channel Blocker (lets me block channels from search results on Youtube); uBlock Origin; Disconnect; F.B Purity; Consent-O-Matic (auto fill cookie consent forms); Kagi Search; PopUpOFF; Facebook Container; Privacy Badger; ClearURLs; Return YouTube Dislike Bas…

> Channel Blocker (lets me block channels from search results on Youtube)... I wish this were possible for the phone app. Every now and then I am recommended a video from one YouTuber in particular that I can't stand. Is there an app for that? I don't think you can block within YouTube, which would be great.

I don't think so (I looked). Best I could find was some articles online claiming you can add "-unwantedChannel '...'" to your YouTube search to exclude individual channels. I didn't even test it because it would be WAY to cumbersome. Maybe that's all Channel Blocker does under the covers -- add a bunch of those switches to my search.

What frustrates me the most is that this is one place where mine and Google's interests actually align! Let me help train them to not show me crap I don't want to see... then I'll use their products (YouTube and Search) more and give them more opportunities to show me ads! (Well, theoretically -- I block as many ads as I can right now).

That was one of the big reasons I looked for an alternative to Google search. IIRC, you used to be able to exclude results from Google search. In order to do so, you HAD TO LOGIN TO GOOGLE (another huge win for Google!). Now I use Kagi -- primarily because they allow me to exclude sites from their search results.

Re: The FBI now recommends using an ad blocker when searching the web

#246

Earlier quoted context omitted.

> Channel Blocker (lets me block channels from search results on Youtube)... I wish this were possible for the phone app. Every now and then I am recommended a video from one YouTuber in particular that I can't stand. Is there an app for that? I don't think you can block within YouTube, which would be great.

I don't think so (I looked). Best I could find was some articles online claiming you can add "-unwantedChannel '...'" to your YouTube search to exclude individual channels. I didn't even test it because it would be WAY to cumbersome. Maybe that's all Channel Blocker does under the covers -- add a bunch of those switches to my search. What frustrates me the most is that this is one place where mine and Google's intere…

Doesn't help for searching for new stuff, but you can subscribe to channels using rss feeds. From my experience, it helps avoid getting sucked down the YouTube rabbit hole

Re: The FBI now recommends using an ad blocker when searching the web

#247

Earlier quoted context omitted.

You are correct ads have become popups of late 90s. Yet, very few browsers do, as most of them depend directly or indirectly on ad revenue. AFAIK only Orion browser [1] comes with full 1st party and 3rd party ad and tracker blocking, by default. [1] https://browser.kagi.com

Brave browser is literally built to block ads.

Brave is directly financed by advertisers.

Re: The FBI now recommends using an ad blocker when searching the web

#248

I recommend using an ad-blocker while visiting that site :-/ Lately, I find myself using more and more plugins to make the "modern web" tolerable. To list a few: Channel Blocker (lets me block channels from search results on Youtube); uBlock Origin; Disconnect; F.B Purity; Consent-O-Matic (auto fill cookie consent forms); Kagi Search; PopUpOFF; Facebook Container; Privacy Badger; ClearURLs; Return YouTube Dislike Bas…

Do you use a password manager? Do you visit websites for banks or brokerage firms? If so, how do you ensure that none of these plugins and extensions steal your data?

Heh, you got me. A password manager is the ONE plugin I have installed in my profile that I use to access my banks.

Simply put, I trust the password manager. Recently, however, I have considered uninstalling that plugin and using only the desktop version of the password manager -- and then copy/pasting username/pw from the password manager to websites.

One reason I don't do that, though... is because having the password manager as a browser plugin guarantees (?) that the password it presents to me is for the site I am visiting. If I end up on a webiste with an IDN that was chosen very carefully to look like my bank's domain, my password manager plugin won't present me with a password -- which will trigger my paranoia.

If you can't tell, I wrestle with this decision pretty regularly...

Re: The FBI now recommends using an ad blocker when searching the web

#249
post #62

Earlier quoted context omitted.

While these are all good practices, killing DoH conclusively on your home network is more difficult than you've made it seem, as ultimately all you can really do is use domain blacklists at your firewall. It's no longer as straight forward as just control port 53 traffic, not like you can realistically shut down 443... Blocking DoH is largely whack-a-mole and I think is only going to get worse as this and similar tec…

This is exactly why DoH is a trojan horse. You can't control it as a network administrator, all it takes is a piece of software to simply remove the controls for users to configure their own DoH and bam, end user has little to no control over how their applications perform name resolution. Little pro-tip for anyone who tries to run their own private DoH infrastructure too, Firefox doesn't like RFC1918 addresses for t…

> You can't control it as a network administrator

Yes you can. Do what corporate firewalls do. MITM all TLS connections with your own personal CA. Don't allow any traffic streams that you can't MITM to leave your network.

Re: The FBI now recommends using an ad blocker when searching the web

#250

Earlier quoted context omitted.

But: 1. couldn’t you “just” (yea yea I know) install a cert on all your devices and force all 443 traffic though a proxy (like some corporate networks do)? 2. (Something I’ve been meaning to get around to trying for a while) default-block outgoing connections unless unless the external host was recently resolved for the corresponding internal host via your internal resolver? That seems like it would kill anything tha…

The biggest problem with 1) is that you lose the ability for your browser to perform checks on the certificate. If the certificate fails, the only option is to deny the connection. (Or fake it and return an error page but that can have unintended consequences.) And with 2), that would work, though you'd probably want to whitelist port 53 so that you can resolve names in the first place. Sounds like it should be effec…

Those checks are then performed on the MITM device. Instead of an error page the device could return the same sort of page that your browser would otherwise display for you. The connection has been MITM'd after all.
Post reply on HN