11 ms·
Mozilla working on in-page popup blocker for Firefox
- Vinnl 9y agoFirefox extension: https://addons.mozilla.org/en-US/firefox/addon/in-page-pop-up-reporter/ https://addons.mozilla.org/en-US/firefox/addon/in-page-pop-u... Chrome extension: https://chrome.google.com/webstore/detail/in-page-pop-up-reporter/dkpphegmeomaffjanagefmejpeebfcmh https://chrome.google.com/webstore/detail/in-page-pop-up-rep... (both for reporting such pop-ups - the blocking hasn't been implemented yet.)
- spiderfarmer 9y agoIt's sad that this is needed.
- austincheney 9y agoIs this about actual popups, new windows with their own browser chrome, or about modals? The graphics in the article reflect modals. If Mozilla really wanted to block actual popups could do so directly by directly removing the userland functionality spawns a new browser window.
- endless1234 9y agoActual popups not spawned from user interaction have been blocked for like the past 10 years though
- austincheney 9y agoWhen I worked at Travelocity we would find ways to prove this wrong as necessary to create those hated popunders. Expedia still uses these.
- deleted 9y ago[deleted]
- Vinnl 9y agoModals (i.e. "in-page"). All browsers have been blocking regular pop-ups for ages now (or at least have tried to).
- anfilt 9y agoHow about just make a time machine and stop the Netscape from creating JS. I think it was a mistake adding a client side language to the web standards.
- gsnedders 9y agoThen we'd have the web relying on VBScript. If you stop Microsoft from doing that, well… the market was still changing quickly enough some other browser might've done it and got traction.
- megaman22 9y agoMicrosoft would have eventually yanked VBScript, and we'd be coding in C# for the browser now...
- Cthulhu_ 9y agoYou know, I think that wouldn't even be such a bad idea. It's got types and it's reasonably static, meaning it can be optimized a lot more than JS can - in fact, Dart was created in part because its more Java / C#-like structure could be run in a much more optimized fashion than Javascript could. And it was invented (iirc) by the guy who made V8, so if anyone knows anything about the limitations of JS's run speed, it was him.
- cakes 9y agoSilverlight didn't really thrive though...
- zingmars 9y agoMaybe if we keep going back and fixing it we'll find a solution that works. Worth a try.
- andrewflnr 9y agoCareful. That way lies PHP as client side language. Or Befunge. Don't mess with Time.
- reacweb 9y agoI think we need blacklists. When I access a URL, the browser should check if it is present in the blacklist. If present, compare the reason of the blacklist (for example adblock avoidance system) and check the associated action specified by the user (for example, block the site or ask for a confirmation). Users would be able to choose the blacklist he prefers and to report missing sites.
- dec0dedab0de 9y agoI think there needs to be white lists. Most websites are actively hostile to their users.
- andrewflnr 9y agoA white list would exclude most random personal sites that are the best part of the internet.
- dec0dedab0de 9y agoRight but we're not talking about defaulting to blocking the entire site, just the ability to do questionable things. If they need to do something questionable, then they should explain to the user what and why, and the user can decide if they trust this site.
- andrewflnr 9y agoAh, right. I lost track of the context. A whitelist of "probably won't try to pwn you" would be nice.
- billysielu 9y agoI want them filtered out of Google search results. Sick of going to them by accident.
- realusername 9y ago
- endymi0n 9y agoI‘m really curious how this will play along with GDPR, which will pretty much absolutely need forced modals in order to to legally capture tracking consent. It could also create interesting legal constellations: How do you prove you asked for user consent when your client side code was blocked or modified?
- chopin 9y agoYou don't get consent if it was blocked.
- robin_reala 9y agoYou can’t do anything without affirmative consent, so if your modal was blocked the user can’t give it. You don’t need modals though: you could have an in-process step for the action you want to collect data for, or just anonymise your tracking rather than collecting personally identifiable data.
- mbel 9y agoGDPR doesn't force modals. They are just the easiest and most lazy way to implement GDPR compliance. So perhaps modals becoming unreliable will inspire web developers to explore other options... like not tracking absolutely everything about the user from first millisecond after the page was rendered.
- zaarn 9y agoNah. We'll get the same thing we got on mobile phones (and still have); force redirect the user to a new page, then redirect back to the home page (not where you came from) or just reloading the entire page when consenting (or not).
- a_humean 9y agoI don't think GDPR is going to be easily dismissed with modals asking for permissions like cookie notifications were. Someone correct me if I'm wrong, but if the user doesn't give consent (whether explicitly, or via a browser blocking a modal) then unless that information was critical to the application function then you have to provide the service anyway without downgrading the functionality. Its all explicit opt-in/implicit opt-out instead of implicit opt-in/explicit opt-out. There are no consequences for the user if they opt-out, and it is extra-territorial in its enforcement meaning it impacts any businesses in any region handling European citizen data. GDPR seems to mean business from a regulatory standpoint.
- zaarn 9y ago>Mozilla wants to make Firefox automatically detect and dismiss the popups. That would be quite amazing, some newspaper outlets have that annoying inpage popup that nags me on disabling adblocker. And if you dismiss it, it shows up every 5 seconds. And that's not even exaggerated. It was legit 5 seconds.
- tannhaeuser 9y agoI hope they're careful with that. Modals could contain legally required waivers such as for upcoming GDPR etc. Edit: what endymi0n said in another subthread
- zaarn 9y agoIf they kill legal waivers then I would say that is up to the website operator to fix, especially when it's being widely deployed by a major browser vendor.
- Cthulhu_ 9y agoI think those legally required waivers shouldn't be displayed as a modal but as a landing page of sorts - a modal implies that underneath, the page itself, including ads and trackers etc are already loaded. A proper cookie warning thing should not be able to set any cookies or whatsoever before the user has agreed to it. Of course, a properly designed website will grant access to its content regardless of the user accepting or rejecting the cookie thing. Second, if a user installs a plugin that automatically hides or rejects cookie warnings / gdpr stuff, that's their own fault then.
- Feniks 9y agoOn a side note my ublock origin went into overdrive on androidpolice. How many trackers does a man need FFS?!
- hotwire 9y agoI just have a bookmarklet to kill all "fixed" position divs. I'm clicking it more and more these days - even those damn fixed navs that take up a stupid percentage of the screen give me the shits. If clicking the bookmarklet doesn't get rid of your stupid modal newsletter sign up or annoying sticky nav, I'm just closing the tab. Here's the bookmarklet btw: javascript:(function()%7B(function () %7Bvar i%2C elements %3D document.querySelectorAll('body *')%3Bfor (i %3D 0%3B i < elements.length%3B i%2B%2B) %7Bif (getComputedStyle(elements%5Bi%5D).position %3D%3D%3D 'fixed') %7Belements%5Bi%5D.parentNode.removeChild(elements%5Bi%5D)%3B%7D%7D%7D)()%7D)()
- deleted 9y ago[deleted]
- yourduskquibble 9y agoYou may also be interested in my filterlist[1] project for uBlock Origin which attempts to do this via CSS style overrides for many, many sites. [1] https://github.com/yourduskquibbles/webannoyances https://github.com/yourduskquibbles/webannoyances
- hotwire 9y agoholy shit dude. if this is as awesome as it looks, i'm actually excited. thank you.
- yourduskquibble 9y agoNo problem, I hope it works out for you! Feel free to spread the word to others as well as provide sites that are causing issues for you so I can add fixes to the list.
- option_greek 9y agoProbably olark and other chat bot crap can be added too. They are mostly used these days for pushy sales people to hook casual browsers.
- sly010 9y agoHopefully it will allow user triggered overlays.
- cddotdotslash 9y agoI'm torn on this. On one hand, yes, these modals are some of the most annoying parts of the web and are really ruining the experience on lots of pages. But on the other hand, why should Mozilla (or any browser) get to start fiddling with the content of web pages? If Comcast announced they were doing this, HN would be up in arms about how they were modifying traffic. I'm aware of the browser vs service provider difference, but the end result is the same. Suppose Google decided that it doesn't like websites with bad color schemes so it's going to have Chrome automatically update some websites to use their material design style? Suppose Microsoft decides that websites with small font aren't friendly enough to people with vision problems so they start upsizing all font below size ten in IE? The point is - the browser should render what it's given. If the user wants to modify that, use a plugin.
- neves 9y agoBecause Mozilla defends its users, while everybody else defends their revenues. That's why Firefox is the best browser.
- Cthulhu_ 9y agoYou say that but it was Mozilla / Firefox that force-remote-installed an addon without user's permissions for a commercial party.
- CaptSpify 9y agoMozilla is the best that I've seen at defending their users, but unfortunately that bar isn't very high. You are correct that this was an extremely shitty move on their part, but I don't see many alternatives.
- dec0dedab0de 9y agoWeb browsers should always try to act in the best interest of the user, not just render what is given.
- 9y ago
- yAnonymous 9y agoShitty sites like Reddit hide the scrollbar until you manually click the button that makes the popup disappear, so automatically hiding the popups is going to break them. I like it.
- nashashmi 9y agoIt is sad that one of the most powerful CSS features ha been abused to the point where it is now going to be blocked in finicky ways. Modal boxes are quite useful in apps. And they are great for notifications. But they are annoying when they block everything and prevent you from doing anything further. (I'm looking at you WaPo). I used the clearly extension to bypass things like this. And if that did not work I would go into Dev tools and delete things. I guess a machine learning approach might be a good approach. But would it learn from all of the benign use cases when people are only reporting negative stuff?
- amelius 9y agoI hope that Firefox will fix the "permissions" problem for web-apps. I.e., allow web-apps to request permissions, and allow users to grant those permissions. In a way that is not intrusive. Then, I can see this work, and actually be useful.
- drb91 9y agoThis is totally the dream. Tangentially related, I wish I had fine grained control over whether or not websites can access (or block) pasting, keybindings, etc. I think currently you’d have to write an extension or userscript to monkey patch the functionality in javascript land before the site executes.
- wang_li 9y agoWe could push for a signing regime. Every page has a certificate applied for every individual developer who worked on the page, and for every publisher whose content is on the page. Then the browser provides a simple button that will blacklist the developers and publishers from ever getting content onto the user's screen again. Users can opt in to a sharing service which consolidates the blocked certificates across multiple users. When a threshold is crossed for a particular certificate, that certificate can be propagated broadly to all the participants in the sharing service and said developers and publishers can lose the ability to put anything onto a user's across wide ranges of users. I think when people start having things to lose, they might start acting more responsibly and respectfully.
- IshKebab 9y agoHow is this possible? Real popups windows were mostly blocked by only allowing them in user event handlers (sketchy sites like bittorrent trackers can still create popup windows because you have to click on the site at some point). But an in-page popup window can be created in loads of different ways. I can't see a general heuristic you could apply to detect them.
- Cthulhu_ 9y agoThat's why (if you read the article) there's a browser add-on now which allows you to report pop-ups, so that the creator can use that input as a blacklist. Popular sites' popups should be easily blocked that way. Crowdsourcing the patterns, so to speak.
- franga2000 9y agoThe most annoying ones for me are the ones that trigger when your cursor leaves the tab. TheHackerNews.com (unrelated to HN) does this constantly. Would it be too drastic to just disallow mousemove events? I see no good use for them outside of needless analytics and bugging users when they try to leave your site.
- solarkraft 9y agoNot too drastic. If websites continue to display their malicious incompetence this will happen.
- LukeShu 9y agoEspecially if a button isn't pressed. Allow mousemove between mousedown and mouseup.
- degenerate 9y agoI like this solution, smart.
- cpeterso 9y agoBut what about web games that want to track your mouse cursor? Maybe the browser could restrict mousemove events to handlers on page elements that the user has clicked on? But then web developers would probably add an event handler on the page itself and receive all mousemove events again.
- Cthulhu_ 9y agoFor me it's the ones that go SUBSCRIBE TO OUR NEWSLETTER when I open the tab for the first time - dude, I haven't even read your content, why are you giving me this.
- wybiral 9y agoDetecting popups like this automatically seems like it will be more of a cat & mouse game with developers trying to find ways around it and then a bunch of legitimate use cases being blocked out. And Firefox still hasn't fixed their issues with native popups: http://fan-pages.herokuapp.com http://fan-pages.herokuapp.com (WARNING: if you use FF it may crash your browser)
- shawndellysse 9y agoIt would have been helpful to give a warning that simply going to that site would crash my browser.
- wybiral 9y agoSorry, I didn't think it was that effective anymore. Updated. btw Chrome seems to have some kind of protection against that dialog DoS. From what I've been told Firefox actually downloads the content in the background before you ever approve the dialogs (which is probably great if someone isn't popping an infinite number of them).
- solarkraft 9y agoI have had this extension installed for about a day and already reported numerous in page pop ups. Not only does it feel good to help a blocking effort, it's also a good vent for the anger caused by these things. There will be a few fairly simple ways to block these - probably some libraries or pieces of code reused by almost all websites employing these UX-crimes. As mentioned before, maybe the solution is to just block mousemove events.
- culot 9y agoMaybe some webmaster education to teach people that popping up a dialog begging for Facebook follows or email addresses is generally considered a hardcore dick move? Seriously, who decides to employ those dialogs? A newsletter signup is best embedded in the page itself, as is any social follow ads. To shove them in my face is always rude, and usually means not only am I not going to sign up for your newsletter, but I'm to close out of your page altogether. You lose, go home [and fix your jerky web design].
- gboudrias 9y agoIt's not like most people had education specifically for this. The truth of the matter is most of us are winging it big time. Hence the wild west improvisation.
- bhauer 9y ago> a dialog begging for Facebook follows Or that monstrous dialog Facebook has on its pages asking its visitors to join Facebook. Annoying on desktop, supremely annoying on mobile. Just another reason I usually don't bother clicking on Facebook links.
- zitterbewegung 9y agoI bet it gets enough leads and or sales so that even though it annoys a bunch of users that it is worth it. If it had no conversions they would have stopped doing it by now. Arguing that etiquette should be observed when you have a lead / sales generation flow doesn't work.
- JoshTriplett 9y ago> Arguing that etiquette should be observed when you have a lead / sales generation flow doesn't work. Depends on which customers you want.
- oblio 9y ago> Maybe some webmaster education to teach people that popping up a dialog begging for Facebook follows or email addresses is generally considered a hardcore dick move? That doesn't work. Before Bayesian filtering and Gmail, 90% of my mail was spam. The people who did it knew that it was wrong, they just didn't care. $$$ > almost anything.
- JohnTHaller 9y agoThis will be great coupled with Firefox's ability to turn off "get spam right in your browser" (aka site notification) prompts.
- option_greek 9y agoWorst offenders are iZooto guys peddling their crappy web notifications fixed position dialog all over the Indian news sites. Solves no purpose other than steal good amount of space on the screen. Waiting for either their junk product to die or Mozilla to release this blocker soon.
- dullgiulio 9y agoMakes me think of what you often hear that browsers are the new operating systems. They definitely are, even in the worst vices: here we go, we also need the antivirus now. I think it is about time we rethink the whole web to the foundations. In the meantime we can install Lynx.
- AndrewStephens 9y agoFloat-overs and ridiculous full-width bars are some of the most annoying "innovations" that have appeared in recent years. But I don't see why browsers have to do anything - the publishers clearly like the way their pages work and consider it worthwhile. Blocking things like this is different from blocking third-party advertising in my mind. I should be able to stop my browser from contacting a third-party site. If the author of a page wants to see a float-over then so be it. I can choose to close the tab and not come back.
- atesti 9y agoI wish the browser could present a huge screen (2000px high or bigger) to the webpage and render it. After that I would love to scroll this viewport without the page even knowing about it. This would resolve all problems with position fixed and also block the page from showing real modals once scrolling starts.