Live data from Hacker News

"Begin disabling installed extensions still using Manifest V2 in Chrome stable"

developer.chrome.com

151–160 of 490 posts

Re: "Begin disabling installed extensions still using Manifest V2 in Chrome stable"

#151

For people who want to stick with a Chrome-based browser while still using the full-featured uBlock Origin: Brave will keep supporting uBlock Origin even after Manifest V2's removal from Chromium. https://brave.com/blog/brave-shields-manifest-v3/

Brave browser should probably not be trusted. They violated basic trust by redirecting URLs to their own affiliate links for those URLs. That is pretty bad. https://www.theverge.com/2020/6/8/21283769/brave-browser-aff...

Re: "Begin disabling installed extensions still using Manifest V2 in Chrome stable"

#152
post #111

Earlier quoted context omitted.

That's old news, as noted in my other comment: https://news.ycombinator.com/item?id=41810420 The change here is actually about the stable channel. Also, the title makes it sound like MV2 code has been removed from the source, but that's not the case.

> That's old news, as noted in my other comment: None of your comments have actually provided evidence for this assertion, and the previous update dated June 3rd 2024 says users will start seeing a warning . So when between June 3 and October 9 did Google start actually disabling MV2 extensions, and where was it publicized prior to their October 9 update?

> None of your comments have actually provided evidence for this assertion

It's not an assertion. It's simple reading comprehension. How else can you interpret this?

"Over the last few months, we have continued with the Manifest V2 phase-out. Currently the chrome://extensions page displays a warning banner for all users of Manifest V2 extensions. Additionally, we have started disabling Manifest V2 extensions on pre-stable channels. [paragraph break] We will now [emphasis mine] begin disabling installed extensions still using Manifest V2 in Chrome stable."

> So when between June 3 and October 9 did Google start actually disabling MV2 extensions, and where was it publicized prior to their October 9 update?

I don't know if it was publicized, until now.

After all, when did they publicize that there would be a warning in Chrome stable? But there is a warning in Chrome stable. That started happening some time before this announcement.

Four months is a long gap between announcements.

Re: "Begin disabling installed extensions still using Manifest V2 in Chrome stable"

#153

On Mac OS: https://kagi.com/orion/

I love Kagi, but I wish they focused on their core product first. Search is a hard problem to nail down and there's no shortage of bugs in Kagi right now, their issue tracker is a solid testament to that. When they spread their attention and resources between multiple products, they run the risk of pulling a Mozilla and shooting themselves in the foot multiple times.

Re: "Begin disabling installed extensions still using Manifest V2 in Chrome stable"

#154

Earlier quoted context omitted.

I'm not convinced that this is a good idea, but I don't think that's the reason; don't all your dlls come from the internet?

My comment was sarcasm. The difference here is are you downloading a random dll from a well known source or from http://free-vpn-fast-internet.dwnloadfree.ru/free-chrome-vpn... ? My mom isn't going to know the difference and will click the big green DOWNLOAD NOW button blindly.

But that's not a difference, is it? Can't Windows enforce that DLLs have to be signed just like extensions?

Re: "Begin disabling installed extensions still using Manifest V2 in Chrome stable"

#155
post #152

Earlier quoted context omitted.

> That's old news, as noted in my other comment: None of your comments have actually provided evidence for this assertion, and the previous update dated June 3rd 2024 says users will start seeing a warning . So when between June 3 and October 9 did Google start actually disabling MV2 extensions, and where was it publicized prior to their October 9 update?

> None of your comments have actually provided evidence for this assertion It's not an assertion. It's simple reading comprehension. How else can you interpret this? "Over the last few months, we have continued with the Manifest V2 phase-out. Currently the chrome://extensions page displays a warning banner for all users of Manifest V2 extensions. Additionally, we have started disabling Manifest V2 extensions on pre-s…

> I don't know if it was publicized, until now.

So you literally don't know if it was news before now, but you're insisting on calling it "old news", apparently based solely on Google using past tense in their announcement.

Re: "Begin disabling installed extensions still using Manifest V2 in Chrome stable"

#156
I am tied to Microsoft Edge for sync between desktop and phone, and Microsoft Edge on iOS has AdBlock built in. But looking at this it seems inevitable that Edge will retain V2.

As to switching to Firefox? I'd love to, but Firefox on iOS refuses to put in an AdBlocker. Yea, you can use Firefox Focus but that one doesn't sync.

I don't understand Mozilla's stance on this.

Re: "Begin disabling installed extensions still using Manifest V2 in Chrome stable"

#157
post #100

What does this mean for browsers derived from chrome, like Arc? I heard they plan on continuing to support Manifest v2, but will ublock continue to be maintained for chrome?

https://resources.arc.net/hc/en-us/articles/25540117353623-W...

Re: "Begin disabling installed extensions still using Manifest V2 in Chrome stable"

#158

Earlier quoted context omitted.

> Anyone jumping up and down about MV3 while using Mac or iOS are hypocrites, since MV3 is essentially doing the same thing Safari did years ago, iOS I'll give you, but macOS can in fact run ex. Firefox. > finally matching the security and the privacy in that regard. "Matching" inferior security+privacy is not a good thing. The only way this is an improvement if you think the blockers are malicious; otherwise a usefu…

> The only way this is an improvement if you think the blockers are malicious Extensions and in turn MV2 blockers can easily be malicious. https://usa.kaspersky.com/blog/dangerous-chrome-extensions-8... Look at how many in Kaspersky’s list are advertised as ad blockers. The majority of users aren’t tech savvy like HN.

> Look at how many in Kaspersky’s list are advertised as ad blockers

By my count 5, 6 if we include "Autoskip for Youtube", out of 34. That might be an argument for dropping extensions, but I don't think it's an argument for breaking ad blockers.

Re: "Begin disabling installed extensions still using Manifest V2 in Chrome stable"

#159

Earlier quoted context omitted.

> Anyone jumping up and down about MV3 while using Mac or iOS are hypocrites, since MV3 is essentially doing the same thing Safari did years ago, iOS I'll give you, but macOS can in fact run ex. Firefox. > finally matching the security and the privacy in that regard. "Matching" inferior security+privacy is not a good thing. The only way this is an improvement if you think the blockers are malicious; otherwise a usefu…

One of the most common API malware extensions use is what MV3 blocks, and adblock extension is one of the common malware vectors: https://helpcenter.getadblock.com/hc/en-us/articles/97384768... https://www.wired.com/story/fake-chrome-extensions-malware/ This has been never ending.

Okay, if you absolutely must then make that specific API require extra audit approval from the extension store, but breaking it outright is throwing out the baby with the bathwater; in a world where the FBI outright recommends an adblocker because ads are such a strong malware vector ( https://techcrunch.com/2022/12/22/fbi-ad-blocker/ ), it's irresponsible to undermine uBo.

Re: "Begin disabling installed extensions still using Manifest V2 in Chrome stable"

#160
post #45
post #37

Earlier quoted context omitted.

A lot of other ad blockers use static lists for years. The fact that they work tells that ad industry does not see the blockers as a problem that needs to be dealt with. It can also be that so far the increased cost of development of ads that are immune to simple static lists is not worth it.

Right. Advertisers didn't bother with all these tactics because normal chrome users could download a plugin without any major hurdles to thwart it. Why drive people that wouldn't otherwise use an ad blocker to do so? That's going away now. Now mostly everyone is vulnerable with the only recourse being pretty technical stuff, not just downloading a very popular plugin. So advertisers will now be free to get more aggre…

onBeforeRequest was removed because it is a massive spyware and malware vector.

> I do get that this sounds like conspiracy theory.

> … was not a coincidence.

Could it be that it was coincidence? Do you have a solution for reducing extension malware without removing onBeforeRequest?

Post reply on HN