13 ms·
One of the stated goal of MV3 by Google[1] was to avoid extensions with broad permissions: > our new declarativeNetRequest API is designed to be a privacy-pres
by gorhill 4y ago
One of the stated goal of MV3 by Google[1] was to avoid extensions with broad permissions:
> our new declarativeNetRequest API is designed to be a privacy-preserving method for extensions to block network requests without needing access to sensitive data
This MV3-based AdGuard extension still requires a broad permission to "read or modify host data" on all sites[2]:
"host_permissions": [
"<all_urls>"
],
So what you have now is the same required permission to "read or modify host data" as with MV2, but with a network filtering engine capabilities gated by Google (an advertising company).
We can't innovate anymore the filtering capabilities of our content blocker engines as we have been constantly doing over the years.
For a recent example, there has been discussions lately with filter list maintainers of whether uBO should support AdGuard's proposed capability of being able to support pattern-matching for `domain=` filtering option[3] (uBO supports AdGuard lists).
That sort of proposition is not possible to entertain with MV3 since only Google get to decide how the filtering engine will evolve, if at all. All content blocking issues will have to be resolved with the Google-controlled filtering engine, and left unaddressed if the solution can't be shoehorned in the declarativeNetRequest API.
* * *
[1] https://blog.chromium.org/2020/12/manifest-v3-now-available-on-m88-beta.html https://blog.chromium.org/2020/12/manifest-v3-now-available-...
[2] https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/manifest.json/host_permissions https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web...
[3] https://github.com/AdguardTeam/CoreLibs/issues/1550 https://github.com/AdguardTeam/CoreLibs/issues/1550
* * *
Edit: removed stray `[` character.
- ameshkov 4y agoAll true, and we (content blockers devs) were saying this all for years, since MV3 was first announced. MV3 brings very little (if any) privacy and security enhancements, this is for the future MV4 when extensions will be dumbed down to sets of declarative rules. We'll now need to rely on Chrome team for implementing what we need. But they do it painfully slow or not do at all. Also, where will we get the new ideas if every browser follows that path? Take Safari for example, every little improvement that we requested [1] was inspired by what we already did in other browsers long ago. Anyways, a working content blocker on MV3 is possible. I even think a casual user won't feel much difference. But there is a big difference under the hood and to feel the consequences we have to wait a few years. [1]: https://bugs.webkit.org/ https://bugs.webkit.org/ (search for those reported by @adguard.com). Just a very small part of what we requested was implemented, content blocking is not a priority I guess, and it won't be a priority for Chrome.
- avhception 4y agoI just wanted to say that you (content blocker devs) have been heard, maybe not by the majority of browser users but at least people like me are championing Firefox over webkit-based browsers precisely because to do otherwise would be to loose control of the web to FAANG, especially Google. I've been telling everyone who would listen about how Google leverages Chrom(e/ium) against user interests and have deployed Firefox to every friend & family user whose machines I support.
- Tijdreiziger 4y agoI also recommend people I know to use Firefox, but a lot of people either don't understand the problem or just don't care. A lot of people even conflate Google Chrome, Google Search and other Google services (understandable, as Chrome's home page is a big Google logo with a search box), so they think that they cannot use Google anymore if they install Firefox. The stats [1] speak for themselves: only 3.3% of users use Firefox. Even Edge has more users. [1] https://gs.statcounter.com/ https://gs.statcounter.com/
- novax81 4y agoIt's harder to get people to switch browsers nowadays. When Chrome first came out as a breath of fresh air (IE was IE, Firefox was better but a bit "heavy", Opera was... Opera), normal users would just nod and agree if you recommended a switch, and even as a power user, I only had to migrate a handful of extensions and behaviors over. At this point, browsers (particularly Chrome and Safari on their respective platforms) have ingrained themselves into their users daily routine. Things like bookmarks and some habits transfer pretty quickly, but casual users won't care enough about this (until they're impacted more).
- cycomanic 4y agoI think the stats are showing that we really need debundling of the browser from the OS. I'd wadger that those stats pretty closely align with the percentage of android and IOS users, or in other words the stats are completely dominated by mobile browsers, where hardly anyone changes browsers. I can't understand why we have not seen strong regulatory/antitrust action on this front considering the precedent with MS.
- e3bc54b2 4y agoFor context, gorhill is the veteran author of original uBlock, and current uBlock Origin. He knows what he's talking about as author, maintainer and one of the community leader/voice of probably the single best and only conflict-of-interest-free ad-blocker currently in existence. His past post[0] was reposted and generated quite a discussion on HN [1]. For further details on why uBO is conflict free, this is the README.md on github repo[2] says: --- Free. Open source. For users by users. No donations sought. --- 0: https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-best-on-Firefox https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b... 1: https://news.ycombinator.com/item?id=32542968 https://news.ycombinator.com/item?id=32542968 2: https://github.com/gorhill/uBlock https://github.com/gorhill/uBlock
- dylan604 4y agothank you gorhill for making the internet a useable space.
- naikrovek 4y agohear, hear.
- Abishek_Muthian 4y agouBlock Origin is the only browser extension I use on Firefox, Even after loosing trust on browser extensions in general after witnessing a recommended Firefox add-on indulge in malicious activity[1] and reading numerous stories of how browser extension publishers with large number of users are routinely approached to integrate malware. The reason why I cannot do away with uBlock Origin is because its not just an Ad-blocker as its philosophy states, I need it to make websites usable by blocking elements like auto pop-up news video player, Blocking side bars to resize the websites to preferred width (When playing videos), Disable tracking and often just to load the websites faster. [1] https://web.archive.org/web/20210924045611/https://github.com/ken107/read-aloud/issues/232 https://web.archive.org/web/20210924045611/https://github.co...
- RunSet 4y ago
- BeefWellington 4y agoIt feels like this was always going to be how this played out. Google being the world's largest ad company has a vested interest in ensuring ads are still displayed to users and once a sizeable enough amount of the Chrome userbase started adblocking it directly threatened their revenue growth. The only option here it seems is to switch browsers.
- staticassertion 4y agoBut these changes don't ensure that ads are displayed to users. This won't impact Google's ad revenue at all. At most it will negatively impact their revenue because the less powerful API will let the sketchier advertisers try to bypass the filters.
- BeefWellington 4y agoGoogle is the sketchier advertiser you're speaking of.
- ComodoHacker 4y agoTo be fair, general ad blocker will always require broad permissions, no matter what API it uses. There's no sense in ad blocker that works only on N sites.
- userbinator 4y agoI hope filtering proxies like Proxomitron become popular again. They'll work on all browsers, and as long as locked-down corporate environments with their own needs for filtering content and the requirement to go through a proxy exist, it's not something they can easily kill off (despite trying their hardest to do so with all the "security" propaganda.) Stop being at the whims of the Google-controlled browser monopoly --- by filtering content before it gets there.
- hackernudes 4y agoProxy and ssl doesn't work for filtering (basically the same as dns). Maybe some sort of "remote browser" remote desktop or browser-in-browser type thing will work.
- Dwedit 4y agoYou can still install a certificate, and that will let you "man-in-the-middle" attack yourself with proxy server programs.
- pkulak 4y agoMan, I used Privoxy back in the day and it was amazing. Now, however, you need to set up custom certs so that you can MITM yourself, plus those things can only look at the initial HTML without running any JS. I don't know how less effective that would make filtering, but it can't help. I'd love to be proven wrong though! Right now I run DNS-based filtering because, no, it's not perfect, but I really like having network-wide blocking.
- userbinator 4y agoYou can do filtering on the JS itself, which of course includes injecting your own JS into the page too.
- zzo38computer 4y agoStill, that you will need to MITM yourself is rather inefficient; it would be better for the proxy setting to include a "non-tunneling" option that you can set, instead. Not being able to look at scripts is another issue, although at least for some purposes you may be able to inject scripts which change the JavaScript objects in order to disable or change some features.
- nightpool 4y agoHas Google said that they would reject CLs to the declarativeNetRequest API if filter list maintainers propose a new feature? Have any filter list maintainers tried to propose those CLs? Obviously it would require a new set of skills and talent to maintain the C++ code that now powers Chromium's ad-blocking capabilities, but Chromium is still an open project with guidelines for contribution, no?
- loeg 4y ago> Chromium is still an open project with guidelines for contribution Hah. The default is to reject changes from the community. I would not pin my hopes on Chromium accepting any adblocking community changes.
- freediver 4y agoIf you care about running uBlock Origin on macOS, happy to report that Orion browser by Kagi (WebKit based) supports it and will keep supporting Manifest v2.
- baggachipz 4y agoOrion also has a damn good ad-blocker already running by default.
- minitech 4y ago(In case anyone else didn’t realize or found it ambiguous, Kagi is their company.)
- staticassertion 4y agoPresumably that permission does not mean the same thing in v3. That is, the site can still read/modify data but, of course, only through the specific declarative APIs that delegate the work to the browser.
- somehnacct3757 4y agoMV3 splits permissions into host permissions and classical permissions (tabs, storage, etc). Putting <all_urls> in your host permission list means that whatever the extension does, it can do it on all possible urls you may visit in the browser. In this sense, it's no different than in MV2. What's different is the classical permissions. Previously you could use the webRequest permission to execute custom JS functions in response to network activity. In MV3 you must now write a declarative rule instead using the declarativeNetRequest permission. By moving from an imperitive model to a declarative one, Google now has exacting control over what ad blockers can and can't do. Gorhill's argument is that the stated reasons for MV3 do not align with the implementation. The example he gives is that Google claims the new API is more private. However you still need <all_urls> so the extension is as un-private as its MV2 equivalent. The only difference is that now Google controls what blocking you're allowed to declare and how much of it you're allowed to do. There's a similar community discovery where MV3 implementation is provably counter to Google's claims of performance enhancement - MV3 extensions need to rehydrate state every 5 minutes as Chrome shuts down their service worker and for highly active extensions such as ad blockers this is actually less performant than the MV2 implementation with a long-lived background. Basically, Google is full of shit.
- hoffs 4y agoIt's a big difference between letting extension provide some rules and letting extension do whatever it wants with the request.
- somehnacct3757 4y agoOnly if you've already accepted that a loss in functionality is acceptable. If you could implement a declarative language as powerful as an imperative one you could solve the halting problem. So the switch from imperative to declarative is not free to make and Google has thrown the baby out with the bathwater. They just so happen to lose money every second that baby is alive. On the one hand, the decision to implement this specific declarative language is a malicious exertion of market force. On the other hand it's a stunning display of implementation incompetence. The language can't even reimplement the most popular existing extensions.