9 ms·
This is exactly what Chrome intends to do and everybody hates Google for it. Defending this when Apple does it is a double standard.
by srbby 7y ago
This is exactly what Chrome intends to do and everybody hates Google for it. Defending this when Apple does it is a double standard.
- throwawayy1001 7y agoGoogle is an Adtech company.
- hoten 7y agoIt's also good for performance. The blocking can happen immediately in the browser/network process, instead of waiting for the extension code to run in its own process and tell the network service what to do.
- pythux 7y agoIn principle yes. But in practice, we are talking about nanoseconds; and I would very much like to see benchmarks/measurements showing anything that can be perceived by users. Also, this blocking cost is still orders of magnitude lower than network latency and blocking requests (even with a slow adblocker) will result in a noticeable performance boost while browsing the web.
- hoten 7y agoIt certainly does not take merely nanoseconds to wait for JS to run in another process.
- loeg 7y agoThis comparison is only apples to apples if exact same content can be filtered. If you lose some filtering due to the added restrictions on blockers, the page may load more resources (in particular, javascript), easily negating any CPU performance benefit.
- loeg 7y agoFrom OP's argument, it seems likely they'd support Chrome doing the same thing. A double standard requires the same person or population to hold logically contradictory viewpoints. That isn't what is happening here.
- why-oh-why 7y agoThere’s no double standard. Everyone hates Safari for this too… all the 500 users of it. Of course you’ll hear a lot more noise from the users of the browser with the larger share by a wide margin.
- jzl 7y agoExactly. The whole point of this HN post is that people are annoyed and upset about Safari doing this. Ultimately this and Chrome's potential upcoming changes have driven me back to using Firefox almost exclusively.
- tssva 7y agoMozilla's statement regarding Manifest V3 hints that Mozilla is likely to follow the same path at a later date. They face the same security and privacy issues surrounding plugins that have driven Apple and Google to make the changes they have.
- p4t44 7y ago> We have no immediate plans to remove blocking webRequest and are working with add-on developers to gain a better understanding of how they use the APIs in question to help determine how to best support them. I don't take from that they will apply it in the future, just they don't want to rule anything out. source: https://www.ghacks.net/2019/09/03/mozilla-wont-follow-google-in-limiting-apis-in-coming-extensions-manifest-v3/ https://www.ghacks.net/2019/09/03/mozilla-wont-follow-google...
- Account123481-x 7y agobah a demon of stupidity needs to exercised here.
- adwi 7y agoEstimates for Safari marketshare range from 15.15 - 24.9% across all platforms [0] [0] https://en.m.wikipedia.org/wiki/Usage_share_of_web_browsers https://en.m.wikipedia.org/wiki/Usage_share_of_web_browsers
- sweeneyrod 7y agoMaybe, but Apple has less of an incentive to deliberately misimplement it since they don't earn huge amounts of revenue from ads.
- wlesieutre 7y agoWhen Apple says "We're designing this API in a way that allows you to block ads without having full visibility to monitor everything that any user does every web page they visit" it's totally believable because it's in line with the last 10+ years of their product direction. Yeah, it makes ad blockers less powerful. It also makes them less of an enormous security risk in that all of your web traffic is redirected through them, and a compromised extension could do whatever it wanted with that. People are more skeptical of Google's motives because nearly all of their money comes from selling ads and for all we know they're more concerned about their very very very large piles of cash than they are about browser extension security. That's not a motivation that Apple would have for their Content Blocker limitations.
- michaelmrose 7y agoAdblockers don't redirect all traffic though them. If you think about it for a moment you will see how absurd that idea is. This would incur one of the most massive bandwidth bills on the internet for negligible financial gain. Current ublock origin. Your adblocker frequently updates lists of patterns to block via any of many user configurable lists. When you load a site ON YOUR COMPUTER it consults all those lists including custom ones you create yourself for annoying elements on particular sites before loading content. It NEVER sends said content to the adblocker or leaks your information. Ublock origin provides both the adblocking engine and the lists and can innovate on the former and iterate on the latter as fast as you please. New chrome restrictions. Google provides an adblocking engine substantially inferior to ublock. Extensions are able to provide only a list much smaller than current lists and can only update that list when the extension itself is updated. They cannot innovate on the adblocking engine as they are stuck with the crummy one an ad company provides. This basically ensures that ad providers win the arms race with adblockers. Safari Shares the same inherent flaw with chrome that Apple will be providing the adblocking engine with the possible benefit that apple isn't directly making money off ads and has less incentive to directly break adblocking.
- wlesieutre 7y agoI don't mean that it sends the actual web traffic through some uBlock server, I mean that the uBlock browser extension sees all of the requests to load a webpage and decides what to do. It can decide to block them or not. It could also decide to scoop up all of your personal information and do bad things with it. If someone were able to compromise the developer account and get a malicious version distributed through the Chrome browser gallery, that would be a huge problem. The kind of thing that has been making headlines with compromised npm modules recently. Google has reviews in place to prevent malicious extensions from being distributed, but they can't be perfect. We've seen that repeatedly with both Chrome extensions and Android apps. Every extension with permissions set for "This can read and change site data on all sites" has a huge target on it, and the fewer things using that level of access the better. Ad blocking extensions are an obvious place to look for improvement because they're so popular. I hope that Google can put a blocking system together that will be able to perform as well as existing solutions without adding any huge security risks, but I also agree that it's problematic that their incentives are to do the exact opposite.
- pilif 7y agoAFAIK, Safari supports longer lists than Chrome to the point that you can produce an usable ad-blocker for Safari but not for Chrome because you will hit the limit too quickly.
- mirashii 7y agoIt's easy to verify that this is completely not the case. Safari allows 50,000 rules [1]. Chrome allows 150,000 [2]. [1] https://help.getadblock.com/support/solutions/articles/6000099239-what-is-safari-content-blocking- https://help.getadblock.com/support/solutions/articles/60000... [2] https://blog.chromium.org/2019/06/web-request-and-declarative-net-request.html https://blog.chromium.org/2019/06/web-request-and-declarativ...
- lorenzhs 7y agoSafari allows 50k per list, Chrome is planning to move from 30k per extension (!= list) to 150k global max per your links. That's quite a difference. On iOS, some blocks use multiple lists -- AdGuard has six and 1Blocker X has seven, for example. An ad blocker that would be limited to 30k rules, as originally suggested by the Chromium folks, would be severely neutered. And even with the 150k max, I currently have ~240k rules in uBlock Origin. That's way above Chrome's planned max. But easy enough to implement with Safari's model, even if it requires using at least five lists.
- swsieber 7y agoNo, it's not. Chrome says its for privacy but still allows plugins to snoop on all network traffic (just not midy the requests). So it doesn't improve privacy. That's why everybody is hating on google - it's a reduction in functionality without an increase of privacy even though that's "why" they did it.
- wlesieutre 7y agoMy understanding is that Manifest v3 pushes ad blockers from chrome.webRequest to chrome.declarativeNetRequest, and they do not have the ability to see what requests are made with declarativeNetRequest. They can define rules to block or modify requests, and the browser executes them without letting the extension see any specific requests. Is that not correct? The complaints from blocker developers have been that Google isn't allowing enough rules (Google has agreed to increase that), and that their existing blocking lists are defined in a way that needs more logic than declarativeNetRequest's matching system. https://twitter.com/gorhill/status/1134127701583904770 https://twitter.com/gorhill/status/1134127701583904770
- swsieber 7y agoThe two complaints are valid. The point I was making is that chrome.webRequest is still around (as I understand it - if I'm wrong, please correct, because that's my whole point!), it's just for observation only now. Plugins can still request that permission... which means plugins can capture just as much data as before this change. That doesn't seem like a good trade off, given the two complaints you listed.
- wlesieutre 7y agowebRequest is still around for now, but Manifest v2 as a whole will be deprecated sooner or later and I think webRequest goes away with it. I don't know if Google has specified dates for this, but for historical context here's the timeline from Manifest v1: https://developer.chrome.com/extensions/manifestVersion#manifest-v1-support-schedule https://developer.chrome.com/extensions/manifestVersion#mani... Deprecated in March 2012, stopped accepting updates to Manifest v1 extensions in March 2013, and existing extensions stopped working in January 2014. EDIT: Google's blog post talks a lot about removing the "blocking version of webRequest", so perhaps the monitoring one still exists? But their goal would be to make these into separate permissions - the very popular blocking extensions can work blindly, while monitoring extensions can still function? It's not very explicit about it, but that's how I'm reading it https://blog.chromium.org/2018/10/trustworthy-chrome-extensions-by-default.html https://blog.chromium.org/2018/10/trustworthy-chrome-extensi...
- mfer 7y agoIt's not exactly a double standard because... Like many things in technology, there are few write ups explaining this, including the pros and cons, in simple terms that most people can understand. So, people are not well informed. When they are not well informed they will tend to make decisions based on other things, like their business model. We know that Google makes money displaying ads and has generally soaked up information on people to use for their benefit. Apple has been advocating privacy and makes money selling hardware and services. If there was an "explain it to me like I'm 5" write up on how the changes to Safari and proposed changes to Chrome would work I could imagine it would help people see something other than the business model. This isn't a double standard. It's people making judgements on something other than the technology.
- blaisio 7y agoChrome was going to allow only a very small list - that's what people were complaining about. The idea of having a built-in way to specify blocks is fine, it's more efficient anyway.
- otterley 7y agoNot "everybody" hates Google for it. People who don't understand the security implications inherent in allowing browser extensions that have nearly-unrestricted access to the user's behavior -- even if well-intended -- may hate the Chrome team for it. But there are those of us who understand why the Chrome team made the decision it did, and are sympathetic. And we're happy that the Chrome team and Apple are of the same mind about this.
- dmix 7y agoSounds like Google hasn't communicated these technical changes nor their intentions very clearly at all. Just judging how there's multiple people saying different things in this thread for both.
- bduerst 7y agoIt's clickbait fodder. Construing the manifest privacy changes as Google is blocking ad blockers is better clickbait than saying Apple safari is doing the same thing. It's similar to when the internet blew up about Google's project dragonfly, which was cancelled, while Apple quietly did the same thing by sharing iCloud user data with the Chinese government.
- LaGrange 7y ago> Not "everybody" hates Google for it. People who don't understand the security implications inherent in allowing browser extensions that have nearly-unrestricted access to the user's behavior -- even if well-intended -- may hate the Chrome team for it. ...this is a fantastic argument for disallowing installation of custom browsers. I do hope y'all like IE and/or Safari.
- autoexec 7y ago> People who don't understand the security implications inherent in allowing browser extensions that have nearly-unrestricted access to the user's behavior You can say the exact same thing about any code we run on our devices. We accept that risk or we wouldn't run any software at all. Google isn't worried about our privacy. They take our privacy. They are worried about their profits because that's all any corporation cares about.
- trophycase 7y agoGoogle makes almost all of their money through ads...
- tptacek 7y agoThe situation with Chrome is actually even more misconstrued than that, since ad-blocking performance isn't the only, or even the most important, issue Chromium is dealing with in Manifest v3. Chrome extension security has become one of the biggest time sucks in corpsec/IT security, and that team had been planning for years to address it. But people have a rooting interest in uBO, so none of that gets out.
- icebraining 7y agoIt might not be the most important issue in the whole Manifest v3, but it's the only issue mentioned for deprecating the particular API that uBO uses to block requests.
- loeg 7y agoGoogle are between a rock and hard place, for sure! As someone who isn't a corpsec/IT practitioner, though, breaking uBO is literally the most important impact of Chrome's Manifest v3 for me. I wouldn't mind if Google incorporated uBO as a first-party component in Chromium while applying the restricted policy to all other extensions! Most purported adblockers are crap, if not malware. Pick the best one and restrict the rest. Unfortunately, I doubt an advertising company is going to incorporate uBO in the browser they provide for free. I totally buy that breaking uBO isn't Google's goal for Manifest v3! It just happens as a beneficial side effect.
- tptacek 7y agoThe actual right fix here is for Google to give a blanket exemption to uBO and to nothing else. That's what security people want them to do. Because the underappreciated problem here is that while uBO is fine, ad blockers in general are security tire fires.
- loeg 7y agoTotally agree that's the right engineering fix! I just don't see it happening for dollar and cent reasons: > The moral dilemma here seems to be that Google is unwilling to privilege a good-citizen adblocker like uBO over other extensions; they're an ad company and any explicit step towards promoting an adblocker probably is hard to explain at shareholder meetings https://news.ycombinator.com/item?id=21032698 https://news.ycombinator.com/item?id=21032698
- TheRealDunkirk 7y ago"Exactly." "Everybody." "Hates." Bonus: "You are an ethic-less hypocrite." Look no further for why our society is having such trouble coming to any sort of agreement on issues that matter. I read the GitHub post yesterday, immediately bought 1Blocker, and moved on! (And it's been great!)
- ulucs 7y agoWhy are you happy for having to pay for an inferior product? If you believe 1Blocker is superior or extensions shouldn't use the now disallowed API, why didn't you use it before? Or if you don't care about this at all, why are you even commenting about this thing which people express their feelings about? Your apathy doesn't make their arguments invalid.
- TheRealDunkirk 7y agoAnd you've illustrated another problem with online discussions, particularly since the ubiquity of social media. You assumed that my call to moderation in this debate is because of apathy, and presumed to read my mind. I'm hardly apathetic, or happy about it. 1Blocker doesn't work at all on Youtube, so I'm using Firefox for that now, where I can still use uBlock Origin. I'm disappointed, to be sure, but no amount of whinging, no matter how vociferous, is going to change this, so I'm pragmatic about it.
- Dylan16807 7y ago> You assumed that my call to moderation in this debate is because of Did you read the same comment I did? They're baffled and they asked you about several different possibilities to figure you out. That's the opposite of assuming. "Your apathy" was conditional, based on the previous question. > I'm disappointed, to be sure, but no amount of whinging, no matter how vociferous, is going to change this, so I'm pragmatic about it. Losing money and being disappointed doesn't sound 'great' to me!