4 ms·
> Apple is making this move indeed to protect the privacy of its users more. I'd give Apple's claim here as much credence as I give Google's claim that webRequ
by ivl 7y ago
> Apple is making this move indeed to protect the privacy of its users more.
I'd give Apple's claim here as much credence as I give Google's claim that webRequest caused performance problems when extensions used it.
- endorphone 7y agoWhat do you doubt about their claim? Adblockers are an significant privacy vulnerability in the traditional model. Apple has no vested interest in ads. It seems entirely consistent with their privacy focus why they'd do this.
- yellow_postit 7y agoOf course Apple has an interest in ads given their competition with Google, which is an ad company. Harder to make money off of ads is bad for their competitors and in a zero sum view of the world good for Apple.
- ivl 7y agoBecause ads and trackers are as great a threat to privacy. All ads are malicious, while only some extensions that misuse powerful extensions are. I'm aware ads are not Apple's business model, yet I'm incredibly skeptical whenever an API that is open and powerful gets shrunk down to 'protect' users.
- endorphone 7y agoApple has gone to great extents to enable ad and tracker blocking, making it a first-class feature in iOS, and pushing the envelope on the blocking of tracking cookies and other technologies. I use AdGuard on my iPhone and it might be the most effective browsing experience I enjoy. For that matter, on macOS I don't have anything in Safari, and regularly go between Safari, Chrome and Firefox (the latter two with uBlock Origin). Somehow just the native anti-aggravation technology in Safari is more than sufficient to give me a great experience. If it has a list solution like the iOS Safari, then I'll partake of that. Apple should enable classic-style blocking as an admin override kind of thing, but remarkably their list-based regex approach has been remarkable effective.
- 9dl 7y agoAnd how exactly app outside browser \wo api for filtering can filter page content? MitM like "antiviruses" do? Nice
- danShumway 7y agoThe problem is that websites are also currently a significant privacy vulnerability. I'd love an adblock system that allowed me to block trackers with a purely declarative API. I do not trust Apple (or Google) when they say that their API will be as effective as current extensions. Ublock Origin and UMatrix are hands-down the gold standard for blocking right now. I'm very, very cautious about ignoring the advice of the person who made them, and that person is saying that declarative APIs don't offer enough flexibility for the blocking they want to do. Of course extensions are a privacy risk. But I only need to vet two extensions, and without them I need to vet hundreds of websites. If the current extensions do a better job without a declarative API, then I'd rather risk installing them. You have to look at the risk of extensions in the context of the risks of the broader ad ecosystem on the web.
- jakobegger 7y agoI think you underestimate the threat potential of extensions. Yes, ad networks can track you across participating networks. But an ad network can only attack the sites that use it. An extension can access everything. And how do you "vet" an extension? By checking if the author looks like a trustable person on their Github photo?
- danShumway 7y agoThe same way you vet desktop apps. Install as few of them as possible, because the sandboxing is currently quite bad. Do research on the people who are developing them. Read the source code. If you're worried about malicious transfers of power, turn off auto-updating in Firefox. If you're worried about being able to audit the actual installed code, use Firefox Developer Edition and audit and compile your own version to run. In practice, I trust UMatrix and Ublock Origin because I'm familiar with Gorhil's work and comment history around Github and HN. I also extend a similar amount of trust to Decentraleyes for similar reasons. Those are the only big 3 you need to get the biggest impact on your privacy. Arguably, you don't even need Decentraleyes if you only want to trust one person.
- bduerst 7y ago
- fouric 7y agoLocal code execution is also a significant privacy vulnerability. Should Apple take away the ability of their users to install non-app-store programs? Some security vulnerabilities are acceptable in some situations in exchange for user freedom and/or other benefits, such as blocking ads, which are essentially malware for your brain.