Live data from Hacker News

EBAF – eBPF Based Ad Firewall

github.com

41–50 of 56 posts

Re: EBAF – eBPF Based Ad Firewall

#41

Earlier quoted context omitted.

> getting underneath TLS and DoH (which have both been effectively weaponized at this point). Only to the extent you are running software you don't trust. If you're running a user agent (e.g. a browser), rather than an app, you can easily do full ad-blocking much more effectively. Calling TLS and DoH a weapon because apps you don't trust can use them to maintain integrity of their connections is like calling secure c…

Yeah I'm just going to have to completely disagree at a militant volume. Keeping the contents of connections made on my behalf secure from my own inspection is fucked up and I want harm to befall those that do so. I'm not a little angry about surveillance capitalism, I'm start a war angry about it.

I agree with your frustration, and just fundamentally disagree with your attribution of blame. Security is a feature. Software that works against its user is an awful thing. Security features that help secure software for the benefit of users do not become bad just because they also help secure software that works against the user. The solution there is not running software that works against its user.

Eliminating buffer overruns across the entire industry will also make it harder to e.g. jailbreak game consoles or iOS devices. That doesn't make it bad to eliminate buffer overruns; the problem is with devices requiring jailbreaking in the first place, rather than serving their users.

If you believe that TLS and DoH do more harm than good, you may be in a bubble where e.g. things like pihole are common, rather than being obscure tools used by highly technical users who tolerate and debug breakage.

Re: EBAF – eBPF Based Ad Firewall

#42

Earlier quoted context omitted.

Yeah I'm just going to have to completely disagree at a militant volume. Keeping the contents of connections made on my behalf secure from my own inspection is fucked up and I want harm to befall those that do so. I'm not a little angry about surveillance capitalism, I'm start a war angry about it.

I agree with your frustration, and just fundamentally disagree with your attribution of blame. Security is a feature. Software that works against its user is an awful thing. Security features that help secure software for the benefit of users do not become bad just because they also help secure software that works against the user. The solution there is not running software that works against its user. Eliminating bu…

Maybe we agree and maybe not, I'm unsure.

I don't think there is any justification for shipping software with exploitable security problems on purpose, and it sounds like I maybe gave you the impression I do. I think all software should be as secure as it's feasible to make it.

But I don't think that security should ever operate against the person who bought the device and is sitting in front of it. I don't think anything on my device or anyone's should be able to phone home in a way that is secure from me: and so I am very happy with things like eBPF that make root mean root.

I think that there are certain things you do not do as a professional, as a moral person, as a person who wants to be proud of what you've done. And both TLS and DoH are now routinely used by vendors to do things that users don't know about, don't want, wouldn't consent to if they knew, and I think people should go to jail over it.

I worked in big consumer internet during the period when it was beloved, and during the period where it was starting to get sketchy, and at some point I walked away from millions in unvested stock because a line had been crossed.

Near as I can tell a lot of us with reservations left, and those that remain are those with few if any qualms of any kind.

Re: EBAF – eBPF Based Ad Firewall

#43
post #19

Absolutely no need to do kernel level packet filtering for this. You can use the absurdly easy hostfile approach, or a simple self-hosted DNS server. This looks entirely LLM generated as well. Also... who the hell tries to make changes to a user's sudoers file from their install script? This is an awful project.

Can you share a pre made hosts blocklist that is regularly updated & works on Spotify? The ones I've come across are all dated or still let ads through.

Re: EBAF – eBPF Based Ad Firewall

#44

Earlier quoted context omitted.

I agree with your frustration, and just fundamentally disagree with your attribution of blame. Security is a feature. Software that works against its user is an awful thing. Security features that help secure software for the benefit of users do not become bad just because they also help secure software that works against the user. The solution there is not running software that works against its user. Eliminating bu…

Maybe we agree and maybe not, I'm unsure. I don't think there is any justification for shipping software with exploitable security problems on purpose, and it sounds like I maybe gave you the impression I do. I think all software should be as secure as it's feasible to make it. But I don't think that security should ever operate against the person who bought the device and is sitting in front of it. I don't think any…

> I think all software should be as secure as it's feasible to make it. But I don't think that security should ever operate against the person who bought the device and is sitting in front of it.

I don't think that software, in general, should place the interests of the software author above the interests of the user.¹ I just don't think that's specific to TLS or DoH; it's a general problem of running software that doesn't operate in your best interests. And I feel like laying the blame for that on TLS or DoH, rather than on the software author working against the user's interests, has the net result of making it harder to make software more secure, because it contributes to pushback against those technologies in general.

¹ Modulo some reasonable caveats and subtleties like following standards, which place one interest of the user above another interest of the user.

I think TLS and DoH are net wins in the world, due to all the positive benefits they have, despite the fact that they (like many many other technologies) are also sometimes used for anti-user purposes.

And, of course, if you control a device that includes controlling the software running on the device, which includes arbitrarily debugging, intercepting, or modifying it. I'm glad to see people who legitimately control a device using whatever technologies they desire to prevent software from working against their interests. (Though I continue to believe the right solution there is to not run software that runs against your interests in the first place, whenever possible.)

Re: EBAF – eBPF Based Ad Firewall

#45

Earlier quoted context omitted.

Maybe we agree and maybe not, I'm unsure. I don't think there is any justification for shipping software with exploitable security problems on purpose, and it sounds like I maybe gave you the impression I do. I think all software should be as secure as it's feasible to make it. But I don't think that security should ever operate against the person who bought the device and is sitting in front of it. I don't think any…

> I think all software should be as secure as it's feasible to make it. But I don't think that security should ever operate against the person who bought the device and is sitting in front of it. I don't think that software , in general, should place the interests of the software author above the interests of the user.¹ I just don't think that's specific to TLS or DoH; it's a general problem of running software that…

Well fortunately for user choice there are people like me who are going to build and distribute software that is not prescriptive about what certificate authorities users should be compelled to accept as net wins as well as people like you who apparently are willing to navigate a twisty rhetorical maze before arriving back at: status quo, intact.

my intention is to render your net win calculation irrelevant by letting users decide and educating them about the implications of trusting people like you.

Re: EBAF – eBPF Based Ad Firewall

#46
post #37
post #12

Earlier quoted context omitted.

Artists are earning pennies of what subscribers are paying? then let's not pay, that will show them artists

Some people choose to pirate media and then pay the full price to the artists directly.

These people are largely theoretical - I've heard this many times, but I've never seen it.

Regardless, I don't necessarily think piracy is immoral. There's a lot of situations where it's the only viable option. However, we should acknowledge that most people are pirating because they are cheap. Which, to me, isn't a sustainable model for anyone. Pirates want music, too, and if they keep this up then they lose as well.

Re: EBAF – eBPF Based Ad Firewall

#47

Earlier quoted context omitted.

> I think all software should be as secure as it's feasible to make it. But I don't think that security should ever operate against the person who bought the device and is sitting in front of it. I don't think that software , in general, should place the interests of the software author above the interests of the user.¹ I just don't think that's specific to TLS or DoH; it's a general problem of running software that…

Well fortunately for user choice there are people like me who are going to build and distribute software that is not prescriptive about what certificate authorities users should be compelled to accept as net wins as well as people like you who apparently are willing to navigate a twisty rhetorical maze before arriving back at: status quo, intact. my intention is to render your net win calculation irrelevant by lettin…

> not prescriptive about what certificate authorities

This seems like a non-sequitur. DoH does not specify particular certificate authorities; it just uses a secure connection, rather than plaintext DNS.

Is your complaint specifically about certificate pinning in proprietary applications, as opposed to using the system CA store?

> twisty rhetorical maze

That is an excessively reductive description of an argument you disagree with.

Re: EBAF – eBPF Based Ad Firewall

#48
post #30

Earlier quoted context omitted.

no advertiser has the right to tell me how to process their advertising data. hypothetically, once it's in my network, i can do whatever i please with it.

>once it's in my network, i can do whatever i please with it. But that literally applies to any online licensing check flow. And extends to binaries that are on your disk. I can patch that conditional jump, it is on my hard drive.

Correct on all counts.

Capitalism is about everyone doing everything they can to improve their own personal situation. If you let companies do everything they can to improve their situation, while you also do everything you can to improve companies' situations, you're not doing very well at capitalism.

Re: EBAF – eBPF Based Ad Firewall

#49
post #43
post #19

Absolutely no need to do kernel level packet filtering for this. You can use the absurdly easy hostfile approach, or a simple self-hosted DNS server. This looks entirely LLM generated as well. Also... who the hell tries to make changes to a user's sudoers file from their install script? This is an awful project.

Can you share a pre made hosts blocklist that is regularly updated & works on Spotify? The ones I've come across are all dated or still let ads through.

there are two linked at the end of tfa
Post reply on HN