Live data from Hacker News

Chrome users beware: Manifest v3 is deceitful and threatening

eff.org

321–330 of 396 posts

Re: Chrome users beware: Manifest v3 is deceitful and threatening

#321
post #301

Earlier quoted context omitted.

They get paid to set the default search engine to Google.

That's actually incorrect: Vivaldi generates revenue from partner deals with search engines. Every time you search using one of the pre-installed search engines, you’re helping us grow, one search at a time. Currently, we work with DuckDuckGo, Ecosia, Startpage, Yahoo!, Bing, and Yandex. The only exception is Google – we don’t make money when you search with Google. However, we know that some of you use this search e…

They also accept private donations: https://vivaldi.com/contribute/

Not affiliated in any way, just thought if someone wanted to, they might donate.

Re: Chrome users beware: Manifest v3 is deceitful and threatening

#322
post #292

Earlier quoted context omitted.

There is no decision left to make once this change goes through. You can talk about improved security all you want, but the fact remains that uBlock Origin will be permanently crippled. This by far negates any security or privacy gain that Manifest v3 could possibly make. Switch to Firefox.

This is in fact one of the best arguments pro to do the change: * Chrome destroys ad blocking * Advanced users now suffer the same internet as everyone else * Advanced users will find a solution, and that solution can't be chrome anymore * This starts an exodus of advanced users . * Advanced users configure the browsers for everybody else, hence everybody else also joins the exodus The end result is less of a monopol…

Unfortunately, Mozilla does not have a track record of listening to their user base too and afaik they never had any monopoly. They just pushed their Track/Ad-Features out of desperation(?), which leads to the root of the problem: commodification of common goods like privacy and its resulting degradation.

Re: Chrome users beware: Manifest v3 is deceitful and threatening

#323

It's hard to take EFF seriously when they write so hyperbolically. What's clearly also the case is that Chrome extensions are one of the great modern security and privacy challenges --- to the point where multiple tech company security teams have people whose job it is just to screen them. Another detail that EFF doesn't want to share is that ad blockers are some of the worst offenders --- they demand maximal access…

The EFF doesn't need to give "the other side" because the other side is mostly obvious to the target audience (which isn't random people, Google itself is a huge part of the target audience). Note that Google doesn't give the other side either. Also, nothing in politics works like that, if you want to get people to join your cause you don't end everything you say with "But keep in mind that $foo".

So long as they're only interested in preaching to the choir, that's true. If they want to reach other people who are as zealous, they could stand to give a better full of the landscape.

Re: Chrome users beware: Manifest v3 is deceitful and threatening

#324

Earlier quoted context omitted.

The article does not mention changes over the last two years because there haven't been any to mention. The new WebRequest API still does not support blocking requests (and still does support _recording_ requests), and the replacement for that functionality is still very limited.

> WebRequest API still does not support blocking requests (and still does support _recording_ requests) The whole point is that there would be no reason to allow any ad blocking extension access to the WebRequest API anymore. The replacement, declarativeNetRequest, does not require the user to give any permissions, so the days of granting ad blocking extensions full access to every page are gone. If you think Google…

> The replacement, declarativeNetRequest, does not require the user to give any permissions, so the days of granting ad blocking extensions full access to every page are gone.

Great, but I want to give my add blocker access to every web page. That's kind of it's purpose.

Sure it could be abused, but not if you used one of the community recommended blockers.

> If you think Google is doing this for their own gain, I guess you can simply ask if declarativeNetRequest will be able to block all Google ads, or if you really need a turing complete language for that.

I am not sure if it will be able to block all google ads. Pretty sure it wont be able to remove their ads from search results, since you wont be able to remove/hide parts of the site. Also it wont be able to remove annoying pop up adds (sure it might remove the content of the ad, but popup will remain - well depending how its implemented.)

Also it is only limited to 30k max urls in a blocker. Nowdays my blocker has 80k+ urls. So i guess I would have to pick an choose (If i continued to use chrome).

Re: Chrome users beware: Manifest v3 is deceitful and threatening

#325

It's hard to take EFF seriously when they write so hyperbolically. What's clearly also the case is that Chrome extensions are one of the great modern security and privacy challenges --- to the point where multiple tech company security teams have people whose job it is just to screen them. Another detail that EFF doesn't want to share is that ad blockers are some of the worst offenders --- they demand maximal access…

Every time someone mentions this I have to think about the messed up ecosystem of Safari Webextensions. Safari only allows extensions installed via the apple store, but every single adblocker there is a scam. I'm not kidding you, I audited most of them. Chances are it's either a three years outdated list of adblock plus that doesn't catch anything or it's an extension that replaces all google analytics identifiers wi…

Time to share the testing protocol details, I think. Unless you want people to just believe that [4,5], two of 3 most recommended ad blockers for Apple devices, don’t work or don’t remain up to date.

Re: Chrome users beware: Manifest v3 is deceitful and threatening

#326

Earlier quoted context omitted.

I've been using Firefox for as long as I've been on the internet, but I got really tired of using it just because "It's not chromium". Mozilla been doing really stupid and frustrating decisions that made me feel like I'm in an abusive relationship. I've been eyeballing Vivaldi for a long time, and Firefox breaking compact mode finally broke the camel's back for me earlier this year. When I switched to Vivaldi I felt…

> Mozilla took my fundamental addons that separated Firefox from other browsers, they took my RSS reader, they took my cool Torrenting and Email clients that were a part of the browser itself. It was never the point of Firefox to offer them. Firefox originally started to be the slim alternative to the fat Mozilla suite. > The TreeStyleTab requires you to go through obscure and hidden config files that often break wit…

> It was never the point of Firefox to offer them. Firefox originally started to be the slim alternative to the fat Mozilla suite.

Not OP, and unlike him still use Firefox but:

I lost a lot of functionality/workflow that I depended on. It worked one day until Mozilla deliberately made it not work.

It pisses me even more because it made that decision to be more like Chrome. If I wanted to Chrome I would just use Chrome.

If you don't see why people like me are upset when thing like this happen, we will just have to agree to disagree.

Re: Chrome users beware: Manifest v3 is deceitful and threatening

#327
post #26

The security argument seems pretty simple. The end goal is that legit extensions that people regularly install should not need to ask for dangerous permissions, because a) it teaches the users that it's normal and b) since the extensions can become compromised later and abuse the permissions. Adblockers are probably the most common kind of extension, and are currently granted effectively unlimited access to read and…

> If adblockers (and other classes of legit and common extensions) can be migrated to a safe API

Sure, but Manifest v3, doesn't have such API. It has a very limited API, that can't do a lot of things uBlockOrigin does.

I am not even taking about way too small limit for filtering (30k urls, my current are at 80k+)

I mean in manifest v3 you can't hide various banners or fullpage overlays and similar. That to me is one of the more important parts of what uBlockOrigin does for me.

So at best I will get half of the functionality (that is if google raises the limit)

> EFF are smart people. They know what the actual security benefit is

yes. Chrome with manifest v3 + uBlockOrign (assuming we even get it for v3), is less secure than chrome with manifest v2 + uBlockOrign

EDIT: Almost forgot. You also cannot block, adds on google search, any more.

Re: Chrome users beware: Manifest v3 is deceitful and threatening

#328

Because of this, sometime in 2022 I will shut down Sitetruth, my fifteen year old ad blocking and site evaluation system. That offers add-ons for Chrome and Firefox, and puts a tag with company background info on each search result. Some search ads are removed, and some are de-emphasized. Some time next year, Google will probably force that add-on out of Chrome, as they tighten their grip over what browsers are allow…

I was working on a project about 15 years ago that could tie a website to a business address. The underlying assumption is that many/most legitimate businesses that sell products have registered trademarks. The main purpose of a mark is to enable traceability back to a legitimate, non-ephemeral source for a product. If the reader disagrees that reputable products would have associated trademarks, then stop reading he…

Forgot to mention the key feature. Users can search for entities/products using trademark names and registration classes, i.e., by searching the appropriate name containing the entity/product name and/or classification. Currently, a page of search results from a "state of the art web search engine" can leave one guessing about the sites represented by the domain names listed in the URLs. The searcher trusts that the search engine "knows what she is looking for" and has performed a disambiguation for her, automatically.

Whereas under the new system, the domain names unambiguously indicate trademark-protected names of companies or products, including their trademark classifications. This tells the searcher exactly what type of entity/goods the site purports to describe/offer and the source of those goods. No need for the search engine to second guess what the searcher is looking for.

For example, a name might be formed as something like productX.companyY.classZ. A user could search for URLs with subdomain "productX" and TLD matching "classZ", or a search for domain matching "companyY" and TLD matching "classZ", or perhaps a more broad search for domain under "classZ".

Re: Chrome users beware: Manifest v3 is deceitful and threatening

#329

It's hard to take EFF seriously when they write so hyperbolically. What's clearly also the case is that Chrome extensions are one of the great modern security and privacy challenges --- to the point where multiple tech company security teams have people whose job it is just to screen them. Another detail that EFF doesn't want to share is that ad blockers are some of the worst offenders --- they demand maximal access…

I think this comment doesn't portrait the situation with abusive tracking honestly and I fail to see how this could get so many upvotes. No, adblockers are certainly not the worst privacy offenders. Sure, there are bad plugins, but that isn't an issue exclusive to blockers and the problem with infromation extraction is mostly relegated to malicious scripts on the websites themselves, as the article points out.

The worst privacy offenders are ad trackers and I don't think it has to be explained that Google has an interest in putting constraints on them. How much that influences Manifest v3 is everybodies guess of course.

But your framing is dishonest as Manifest v3 does take away user choice. A choice that allows you to install bad addons with all the implications. But turning that around and saying the EFF tries to take away choice is just false in this context.

I also fail to see hyperbole, I think this is the usual relativization that puts users in a worse spot than before.

> EFF doesn't want to give you the other side of this story, because they're not an honest interlocutor

And who would that honest interlocutor be in your opinion?

The best and most user oriented ad blockers will be affected by this and this is the actual security issue here. No other scenario comes even close.

Re: Chrome users beware: Manifest v3 is deceitful and threatening

#330
post #180

Earlier quoted context omitted.

I've been using Firefox for as long as I've been on the internet, but I got really tired of using it just because "It's not chromium". Mozilla been doing really stupid and frustrating decisions that made me feel like I'm in an abusive relationship. I've been eyeballing Vivaldi for a long time, and Firefox breaking compact mode finally broke the camel's back for me earlier this year. When I switched to Vivaldi I felt…

TreeStyleTabs works out of the box without any sort of hacking around. I really don’t get this mentality. Firefox’s containers have no corresponding feature in chrome, they haven’t copied it and it is a huge win from a privacy PoV.

I had to modify userChrome.css twice to make it work over time, because obviously, you don't want the old tab bar there at the same time as TST. But also it was very unstable for me because every time I needed the left bar for something other than tabs it would crash or hang or get stuck. The rest of the browser would keep working fine, but the tab bar would not receive clicks or something like that. I had to restart Firefox every time that happened.

As for privacy containers - you can easily switch profiles in Vivaldi. It's not integrated to the same degree where you'd get tabs from many profiles in one window, but it works for me. If you like Firefox Containers you should also know that, ironically, unlike Chrome Firefox doesn't have proper site isolation. [0]

[0] https://madaidans-insecurities.github.io/firefox-chromium.ht...

Post reply on HN