7 ms·
What are you saying is the privacy advantage exactly? Regular adblockers also block requests before they happen - there's no "phoning home."
by brianpgordon 7y ago
What are you saying is the privacy advantage exactly? Regular adblockers also block requests before they happen - there's no "phoning home."
- ianlevesque 7y agoBrowser extensions are becoming a notable security vulnerability, with many high profile extensions falling into the hands of (or being sold to!) bad actors. The arbitrary code execution method of ad blocking (e.g. uBlock) is very flexible but it means that without ongoing comprehensive code review using one puts you at risk if the extension ever changes hands or has a backdoor added. Apple's method avoids this issue by never letting the extension see the page contents, it only provides match lists of what to block that the browser then enforces. Even if the extension became malicious it has no access to private data on the webpages it is ad blocking on.
- bryanculver 7y agoWhat I think they're saying is that with Adblockers, they can phone home which ads they block, URLs they see, etc. Content blockers impose rules at the outset and the rule generator won't see what the URLs/content actually is. The way I would think of it would be like "let me see what you're seeing and I'll let you know what to let through" vs "here are a list of things you shouldn't let through but I don't need to know about what the hit rate actually is". Although I could be misunderstanding the implementation.
- cptskippy 7y agoIn the later scenarios, what assurance does the Ablocker have that their requests are respected? I could easily see a scenario where an Adblocker says "Hey Chrome block all requests to ads.google.com" and Chrome saying "Sure thing buddy" then completely ignoring that request.
- zie 7y agoSHHH!!! That's for Chrome 100 ;P I agree it's totally possible they would do that, but one could figure it out pretty easily with a touch of detective work.
- cptskippy 7y agoAnd then what? Google will say that it's protecting critical functions from breaking and to piss off. Suddenly Google is a monopoly in the ad space because they have the predominant browser and let through only their ads.
- zie 7y agothey arguably are effectively a monopoly now. Them doing things like this isn't remotely new. They just got caught tracking everyone's smart TV usage. Nothing will happen to them until: 1) the Government decides to intervene. 2) Users give up and start using different services. I'm pushing for #2, but then I switched off like a decade ago, when I saw the writing on the wall.
- ummonk 7y agoWere they tracking smart tv usage or were smart tv manufacturers using google apis to store their tracking data?
- zie 7y agoBoth it seems: "The most prevalent tracker, Google's doubleclick.net, showed up in 975 of the top 1,000 Roku channels, with Google analytics trackers showing up in 360, the researchers found." - https://arstechnica.com/tech-policy/2019/09/studies-google-netflix-and-others-are-watching-how-you-watch-your-tv/ https://arstechnica.com/tech-policy/2019/09/studies-google-n...
- deleted 7y ago[deleted]
- ryandrake 7y agoAdblocker apps/extensions don't require that assurance. The user requires this assurance, and if the browser ignores the user's wishes, the browser is the application that should be held accountable by users.
- cptskippy 7y agoHow is the user to know if it's the AdBlocker or the Browser though? It's a he-said-she-said kind of situation with the AdBlocker and the Browser potentially pointing the finger at each other. This setup gives the Browser/Maker plausible deniability when they act badly.
- saagarjha 7y agoBrowsers and extensions aren't black boxes; it's easy to inspect them for this kind of behavior.
- Angostura 7y agoThe same assurance you have that the browser wouldn’t simply inject its own ads into all pages.
- TylerE 7y agoThere's really nothing at all preventing Chrome from doing that today if they wished... they can manipulate the page before and after the Adblocker sees it.
- skizm 7y agoWhile true with some, I believe uBO is a list implemented client-side, right? Other ad-blockers can and do phone home and let through ads that have paid, but uBO just has the EasyList filter installed locally and blocks those URLs. That was my impression at least, I never personally went through the source code.
- squeaky-clean 7y ago> That was my impression at least, I never personally went through the source code. That's the rub though. There's nothing but trust preventing them from including some spyware in the next automatic update. Actually not even trust, whoever has account access to publish for uBlock could have their account hacked and someone malicious could inject spyware into a version of the extension.
- deleted 7y ago[deleted]
- fouric 7y agoTrust is everywhere in computer security. You trust Google to not deliver a backdoored version of Chrome to your machine when you download a binary instead of building from source. You trust them to not break the law and leak your personal data to third parties or discriminate against you based on the content of your emails. I trust Raymond Hill more than I trust Google.
- pilif 7y agoThis isn't as much about what existing extensions do today but all about what potential extension could be doing tomorrow. If an extension doesn't get full access to all the pages you are reading, it can't do bad things with that access when the extension's owner inevitably changes (see the fight between uBlock and uBlock Origin for example) and spyware features are added.
- jtbayly 7y agoEven if it is, it doesn’t matter. The problem Apple faces is how to prevent the other bad actors from abusing their API. The answer they’ve settled on is remove those capabilities from the API. Another answer would be to leave the capabilities but somehow only grant access to them to “trusted” parties. I’m sure that would have gone over really well, too. /s
- toasterlovin 7y agoBrowser extensions are executable JS. That is a huge vector for security and privacy issues (you should be extremely selective about which browser extensions you install). This new method is basically a list of regexs that Safari itself runs against the contents of the page. No 3rd party code is executed, so it's not possible for an extension to, for instance, report back on your browsing habits or steal your login credentials.
- brianpgordon 7y agoHang on a second, since when are we this paranoid about installing software? I'm capable of deciding whether I trust a browser extension with the privileges I'm giving it, just the same as I'm capable of trusting any of the daemons running as root which could just as easily steal my personal data. Sure, if all else were equal I guess I would trust Apple slightly more than an open-source extension developer, but all else is not equal - Apple is taking away the flexibility of arbitrary code and dictating that if you want to block ads in the browser then you have to use their regex-based declarative adblock API. I'm surprised to see such a warm reception on HN to a classic Apple "we're taking this away for your own good" kind of move that has historically not been very popular with enthusiasts.
- dpkonofa 7y agoThis is a really long-standing battle between user accessibility and user freedom. Any time a software system or platform or OS allows for people to do whatever they want without restriction, you end up with thousands of compromised systems out there. The alternative, in the past, has been to lock everything down unless users go into some kind of "Advanced" mode or "Developer" mode but then users just get tricked into turning that mode on anyways or more advanced users hand wave those restrictions away for less savvy users without explaining any of the implications. This is the same pattern that happened with IE where users would install all kinds of toolbars accidentally and then get tons of data stolen or when the first iPhone was jailbroken and everyone wanted all the cool jailbreak features. People would jailbreak the phones of their parents, siblings, relatives, friends, etc. without really every explaining what was happening and what the potential pitfalls of that are. Now, unfortunately, we're at the same impasse with browser extensions. They're super convenient for most people and are widely used but there's another vector of attack for people that aren't as savvy and don't understand the consequences. Especially when it comes to browsing history, payment data, and passwords, it's so easy to compromise a system now when you can hide it in something like a browser extensions. The real answer is to do a better job educating people about what everything is but no one wants to do that. More skilled users just want to bitch about what gets taken away from them personally without acknowledging the giant elephant that is ignorance. There is so much advanced technology out there now that people don't even understand the consequences of the most mundane actions. In my opinion, Apple's trying to do something about that even if it comes at the expense of a few power users losing some conveniences. If their past history is any indicator, they will bring back or improve up on this functionality so that power users get it back somehow but, in the meantime, the bigger and more pressing issue is what takes precedence.