Live data from Hacker News

uBlock Origin CNAME uncloaking now supports filtering by IP address

github.com

101–110 of 133 posts

Re: uBlock Origin CNAME uncloaking now supports filtering by IP address

#101
post #43
post #17

Earlier quoted context omitted.

News payers used to all serve their own ads including in house sales and design. Frankly with how key advertising is I don't understand why anyone would out source it.

cost and effectiveness. selling ad space was always a lot of work. algorithms do it cheaper and in general better. next step is just to run a GoogleAds lib/proxy...

Until the algorith associates you with an ad for something negative to your audience. Scams for example are common for algorithms to allow while a human can validate some legitimentch

Re: uBlock Origin CNAME uncloaking now supports filtering by IP address

#102
post #12

Earlier quoted context omitted.

I moved many years ago to this combo, and never saw a single reason to switch away. Same for android phone, the only usable mobile web experience I've seen. Those few sites over a decade that had some display issues had issues also under chrome. Plus I personally consider ads a cancer of modern society. White and not so white lies, manipulation... nothing respectable regardless (or because ) of tremendous money circu…

I really wish I could agree but sadly this has not been my experience with Firefox, and I have so many issues I've started to switch away recently. Wasting way too much time fighting with websites that turn out to work perfectly fine on Chrome, and the captchas I get on Firefox are becoming genuinely impossible for me to solve. I'm with you on the ads though, and glad it's working out for someone at least!

I have very few issues with Firefox. The two that I suspect are:

1) Google-owned sites seem to just chew CPU on Firefox. In particular I'm thinking of GMail and Youtube, both of which I'm a heavy user of, and also Maps. But no non-google sites seem to have this problem.

2) I'm constantly getting websites saying "This is your first time using this device, are you sure you're you?", and I haven't tried whether it's better on Chrome, but it's pretty crazy because I've literally never used your stupid site with any other device, and I used it with THIS device just last month you idiots. I'm just blind guessing that this is some kind of problem as a result of Firefox privacy choices, like maybe the site doesn't know how to use cookies in a way that doesn't trigger anti-tracking. For example banks.

But Firefox can keep thousands of tabs open at once (thousands. plural. not kidding, not exaggerating.), it has working uBO, and the frequency of "just because we wanted to" UX changes is much lower. It's just a better choice all around.

Re: uBlock Origin CNAME uncloaking now supports filtering by IP address

#103
post #63
post #6

Earlier quoted context omitted.

This is such an intrusion of privacy. I wish I could just disable cookies entirely but the usability of many webpages just goes down. I should not be punished for not wanting 3rd party trackers.

I run all the time with first-party cookies disabled. Most of the web works. Anything that does not, and I care about, gets blessed. The only content I allow by default, even in low-security browser profiles, and even from first-party domains, are HTML, CSS, and images. I consider the occasional broken page to be a successful test of my configuration. If I care, I adjust permissions.

What do you use to enforce this? Is it something that's going to break with Manifest V3?

Re: uBlock Origin CNAME uncloaking now supports filtering by IP address

#104
post #100

Earlier quoted context omitted.

There's no reason why a declarative manifest v3 API couldn't offer this. If I'm reading the commit details correctly, it could work even better by being better integrated into the request flow to block the request on the actual IP address used before anything is sent to the servers. Of course, this all relies on browser vendor (Google) wanting to add this API. Doing this imperatively with "live code" allows for innov…

It could. Google won't do that for chrome. Had they not taken away onBeforeRequest with manifest V3, plugins could implement it themselves. Which is the thing you're suggesting...before the request goes.

The commit message details the caveat of using onBeforeRequest, and how it's not perfect because it's called at the wrong time in the request lifecycle with incomplete info.

Re: uBlock Origin CNAME uncloaking now supports filtering by IP address

#105
post #100

Earlier quoted context omitted.

It could. Google won't do that for chrome. Had they not taken away onBeforeRequest with manifest V3, plugins could implement it themselves. Which is the thing you're suggesting...before the request goes.

The commit message details the caveat of using onBeforeRequest, and how it's not perfect because it's called at the wrong time in the request lifecycle with incomplete info.

This commit is using onBeforeRequest:

>The change allows early availability of ip address so that `ipaddress=` option can be matched at onBeforeRequest time.

It is using some other functionality, on Firefox only, to get that early availability. But I'm saying Chrome is a non-starter since onBeforeRequest is hobbled there. So the "early availability of ip address" doesn't help. You need both.

Re: uBlock Origin CNAME uncloaking now supports filtering by IP address

#106
post #76
post #48

This a good example of why manifest v3 sucks. By definition, it can't do anything like this...no live code hueristics are possible. It's a war of escalation with advertisers. Google is the arms dealer to both sides. They won't give you what you would need to win.

>This a good example of why manifest v3 sucks. By definition, it can't do anything like this... Technically manifest v3 has nothing to do with APIs that the browser makes available to extensions. On firefox manifest v3 is supported with blocking web request[1], which is the filtering api prior to "manifest v3". Therefore the statement that it certain functionality "by definition" is false. [1] https://blog.mozilla.or…

> Therefore the statement that it certain functionality "by definition" is false.

Here's the design document. The hobbling is noted there as part of the spec. "API Changes WebRequest: Restrict the blocking capabilities of the webRequest API."

https://docs.google.com/document/d/1nPu6Wy4LWR66EFLeYInl3Nzz...

That firefox chose to skip that portion of the design and still call it 'v3' doesn't change history. A true-to-spec implementation kills live heuristics.

Re: uBlock Origin CNAME uncloaking now supports filtering by IP address

#107

Earlier quoted context omitted.

This time it affects their bottom line in a profound way so wishful thinking is probably not going to work unfortunately.

> affects their bottom line in a profound way Something around 8% of total digital ad spend.

Source?

Re: uBlock Origin CNAME uncloaking now supports filtering by IP address

#109

Earlier quoted context omitted.

What are the implications?

It more or less boiled down to "we would be labeled an advertiser and not a destination for information on the internet". Like being an advertiser stopped people from using Google search or something

Or newspapers, both before and after it. They've always been vast advertising platforms, but don't have anywhere near the same stigma that online advertisers have acquired (for extremely good reasons imo - they're as invasive as possible, while printed media has rather tight limits)

They could have become the dominant advertisers online too, and then no doubt they'd be just as nasty. But they lost that war multiple times, first to doubleclick-likes and then to social media.

Re: uBlock Origin CNAME uncloaking now supports filtering by IP address

#110
post #79
post #15

Earlier quoted context omitted.

That's part of it. Normally when you visit contentsite.com which serves ads from adsite.com. Adblocker rules can just block adsite.com and the ads won't be shown. CNAME cloaking would have the main site have a subdomain like adsite.contentsite.com point to adsite.com, now the adblockers have the impossible task of blocking millions of subdomains that seemingly belong to legit sites, this also allows the legit sites t…

i hope that this results in sites that host malicious ads and use wildcard session-cookies get hacked to all hell by their ads.

I would hope that this results in websites hosting malicious ads which harm users, which then results in a big lawsuit against these websites with a huge payout for the harmed users. After all, if the malware ad is being effectively hosted by the site, then the site should be legally responsible.
Post reply on HN