Live data from Hacker News

AdGuard publishes the first ad blocker built on Manifest V3

adguard.com

321–330 of 371 posts

Re: AdGuard publishes the first ad blocker built on Manifest V3

#321
post #298

Earlier quoted context omitted.

MV3 splits permissions into host permissions and classical permissions (tabs, storage, etc). Putting in your host permission list means that whatever the extension does, it can do it on all possible urls you may visit in the browser. In this sense, it's no different than in MV2. What's different is the classical permissions. Previously you could use the webRequest permission to execute custom JS functions in response…

It's a big difference between letting extension provide some rules and letting extension do whatever it wants with the request.

Only if you've already accepted that a loss in functionality is acceptable.

If you could implement a declarative language as powerful as an imperative one you could solve the halting problem.

So the switch from imperative to declarative is not free to make and Google has thrown the baby out with the bathwater. They just so happen to lose money every second that baby is alive. On the one hand, the decision to implement this specific declarative language is a malicious exertion of market force. On the other hand it's a stunning display of implementation incompetence. The language can't even reimplement the most popular existing extensions.

Re: AdGuard publishes the first ad blocker built on Manifest V3

#322

Are we going to lose ublock origin on chrome when v2 will be disabled?

Probably, or it'll be nerfed to fuck. I'm sure someone will make a fork off Chromium and leave it enabled. Browser builders, this is your cue: if advertising is not your business, offer an ad blocker. Firefox became popular (in my personal experience) because it came with a popup blocker by default.

> Firefox became popular (in my personal experience) because it came with a popup blocker by default.

Yeah. Firefox should ship with uBlock Origin by default too. They're almost doing that on mobile since uBlock Origin is one of few allowed extensions.

Re: AdGuard publishes the first ad blocker built on Manifest V3

#323

Earlier quoted context omitted.

That repo is archived. Is the project dead?

Isn't it pretty much redundant? You just have to enable advanced mode in ublock origin extension settings. The interface is arguably slightly harder to figure out though, but the functionality is there once you've enabled it. the ublock origin repo actually has a video linked how it works: https://youtu.be/2lisQQmWQkY?t=294

I'm so sick of reading this.

uBO covers most of uMatrix (and more).

Some of that uMatrix coverage is a hell of a lot harder/more awkward in uBO.

Basically every uMatrix user always also ran uBO too, for the more DOM/'content blocking' aspects (primarly 'cosmetic filtering' as it calls it iirc).

uMatrix lets me block all third-party, allow only first-party scripts/XHR/iframes by default, and then in two clicks (including opening the extension's popover menu) allow some specific host's scripts or whatever, while still blocking its cookies/frames/XHR/media/et al.

uMatrix is more advanced than uBO 'advanced mode', and just as easy to use; i.e. easier to use than 'dynamic filtering' or whatever people suggest that's buried in the full-page settings and not something I'm going to be doing 'on the fly' while visiting a site.

I still use uMatrix (and uBO!) and remain thankful for it - I just hope it lasts, not obsoleted by browser API changes or whatever. (nuTensor was forked to take on that burden, but itself now archived. Apparently - I read in another HN topic on this recently - because uMatrix actually did receive some maintenance update.)

Re: AdGuard publishes the first ad blocker built on Manifest V3

#324

Earlier quoted context omitted.

Chrome is not to be trusted; this I agree with. Chromium forks on the other hand, like brave or vivaldi, have none of these problems. The former has already committed to not implementing this garbage restriction on blockers. Chromium's engine is solid from a technical standpoint and doesn't have any inherent privacy issues aside from being owned by Google engineers. If it sounds like I'm holding Firefox to a higher s…

You think a crypto company and a closed-source browser have your best interests at heart? You do you.

Brave has an ad blocker built in. Whatever its flaws, it deserves at least some respect for that alone. Built in ad blocking should be a standard feature of every browser.

Re: AdGuard publishes the first ad blocker built on Manifest V3

#325

Earlier quoted context omitted.

MV3 splits permissions into host permissions and classical permissions (tabs, storage, etc). Putting in your host permission list means that whatever the extension does, it can do it on all possible urls you may visit in the browser. In this sense, it's no different than in MV2. What's different is the classical permissions. Previously you could use the webRequest permission to execute custom JS functions in response…

> Basically, Google is full of shit. Not completely full of shit. Declarative rules are a good idea in the general case. Random browser extensions really should not have unrestricted access to the network requests. This is how we get malware. It's just that uBlock Origin is so important and trusted that these limitations should not apply to it. I'd even say ad blockers should be a built in browser feature but the con…

Now that ad blockers have to be built out of declarative syntax that Google controls, the browser maintainers basically _are_ responsible for implementing the ad blockers. And would you look at that they're pushing back on community contributions and dragging their feet because yes, there is a conflict of interest.

They left alone other imperative-but-dangerous aspects of extensions, such as the ability for any extension to watch what you type into password or credit card fields on any website. Actually that sort of extension is even easier to write in MV3 and Google will still need JS-reviewing wizards to give a guarantee an extension isn't snooping your passwords.

I don't think there's a consistent position from Google if the claim is they want to improve security via declarative syntax. I think Google is full of shit.

Re: AdGuard publishes the first ad blocker built on Manifest V3

#326

Earlier quoted context omitted.

> Basically, Google is full of shit. Not completely full of shit. Declarative rules are a good idea in the general case. Random browser extensions really should not have unrestricted access to the network requests. This is how we get malware. It's just that uBlock Origin is so important and trusted that these limitations should not apply to it. I'd even say ad blockers should be a built in browser feature but the con…

Now that ad blockers have to be built out of declarative syntax that Google controls, the browser maintainers basically _are_ responsible for implementing the ad blockers. And would you look at that they're pushing back on community contributions and dragging their feet because yes, there is a conflict of interest. They left alone other imperative-but-dangerous aspects of extensions, such as the ability for any exten…

I agree with you. I just think this declarative API could have been a good move were it not for the conflict of interest. Makes me wish gorhill made his owh browser instead of browser extensions.

Re: AdGuard publishes the first ad blocker built on Manifest V3

#327

Are we going to lose ublock origin on chrome when v2 will be disabled?

Probably, or it'll be nerfed to fuck. I'm sure someone will make a fork off Chromium and leave it enabled. Browser builders, this is your cue: if advertising is not your business, offer an ad blocker. Firefox became popular (in my personal experience) because it came with a popup blocker by default.

That's exactly what Brave is doing. Chromium fork with a built-in native adblocker that doesn't depend on MV2 at all, and plans to continue supporting MV2 even when it is removed from Chromium entirely.

Re: AdGuard publishes the first ad blocker built on Manifest V3

#328

Earlier quoted context omitted.

I use Chrome because it's faster, safer, more stable. I don't believe V3 in any way is a serious issue for the internet in any meaningful sense either.

Did you read the entry on HN recently, where it is discussed, that Chromium-based browsers allow websites to set your clipboard content, without user action being involved at all? ( https://news.ycombinator.com/item?id=32614037 ) Just one example of how it is not safer, that I thought I should mention, on the background of such a blanket statement as "Chrome is safer" : )

It's not only for Chrome.

Re: AdGuard publishes the first ad blocker built on Manifest V3

#329

Earlier quoted context omitted.

Not recommending Chrome is the way to go. There was a time where developers only tested against IE, built features on top of IE, and there didn't seem any way to defeat the garbage associated with IE. But people recommended Firefox anyway for most browsing since it was a better experience on the open web. Eventually it up ended the dominance by giving a better browsing experience except when forced to use IE through…

This. While I appreciate the work AdBlock does, supporting MV3 is ludicrous. If no ad block extension supported it, it would be dead on arrival - with Chrome too (if Google tried to force it). Just let it be, fire up your Firefox and browse freely.

> While I appreciate the work AdBlock does, supporting MV3 is ludicrous. If no ad block extension supported it, it would be dead on arrival

Only to people like us. The amount of tech-savvy people I see not using an ad blocker is surprising. As a user of an ad blocker, I definitely feel like I’m in a small minority in the real world.

Re: AdGuard publishes the first ad blocker built on Manifest V3

#330
post #220

Earlier quoted context omitted.

I hope filtering proxies like Proxomitron become popular again. They'll work on all browsers, and as long as locked-down corporate environments with their own needs for filtering content and the requirement to go through a proxy exist, it's not something they can easily kill off (despite trying their hardest to do so with all the "security" propaganda.) Stop being at the whims of the Google-controlled browser monopol…

Man, I used Privoxy back in the day and it was amazing. Now, however, you need to set up custom certs so that you can MITM yourself, plus those things can only look at the initial HTML without running any JS. I don't know how less effective that would make filtering, but it can't help. I'd love to be proven wrong though! Right now I run DNS-based filtering because, no, it's not perfect, but I really like having netwo…

You can do filtering on the JS itself, which of course includes injecting your own JS into the page too.
Post reply on HN