29 ms·
> removed it yourself for absolutely no reason I clearly stated the reason: to avoid having to require broad "read/modify data on all websites" permission. I p
by gorhill 4y ago
> removed it yourself for absolutely no reason
I clearly stated the reason: to avoid having to require broad "read/modify data on all websites" permission. I purposefully decided to create a permission-less version of uBO for people who would rather not grant broad "read/modify data on all websites".
> You're taking a single reason that they gave, two years ago
The current documentation regarding the purpose of declarativeNetRequest API deprecating the blocking webRequest API[1]:
> Using this declarative approach dramatically reduces the need for persistent host permissions.
My goal is to create a permission-less version of uBO and this is what I did. I am sure this could appeal to some people out there, as many over time have echoed that broad permissions to "read/modify data on all websites" is scary -- it's a recurring comment for those who support Chromium's deprecation of the blocking webRequest API in favor of the declarativeNetRequest API.
So this is a content blocker for those people. For those who can't live without cosmetic filtering and all the other goodies, there are other options out there.
I don't understand what you perceive this negatively.
* * *
[1] https://developer.chrome.com/docs/extensions/mv3/intro/mv3-overview/#network-request-modification https://developer.chrome.com/docs/extensions/mv3/intro/mv3-o...
- deleted 4y ago[deleted]
- concinds 4y agoI initially punished a comment disagreeing with you, but after thinking about it more, I agree. Google's clearly signalled that they don't want Adblockers to use "read/write data on all websites"; just like Apple did, Chrome's whole idea with Manifest v3 was to make that go away. Frankly, with the genuinely malicious extensions people keep installing, probably for the best. Furthermore having uBlock Origin "continue to behave as normal" will confuse users and make them think uBO is still blocking everything users expect it to (i.e. tracking), which can surely endanger some users.
- nightpool 4y agoGoogle's clearly signalled that they don't want Adblockers to use "read/write data on all websites" Where have they "clearly signaled this"? Gorhil even disproves this in his own comment: he links to an ad blocker in the Chrome webstore that uses MV3 and has been approved, even though it uses the "Read/write data on all websites" permission.
- concinds 4y agoI got it from this comment: (https://news.ycombinator.com/item?id=32755925); https://news.ycombinator.com/item?id=32755925); and Chromium's official blog that hints at that: https://blog.chromium.org/2020/12/manifest-v3-now-available-on-m88-beta.html https://blog.chromium.org/2020/12/manifest-v3-now-available-... > To give users greater visibility and control over how extensions use and share their data, we’re moving to an extensions model that makes more permissions optional and allows users to withhold sensitive permissions at install time. Long-term, extension developers should expect users to opt in or out of permissions at any time. > For extensions that currently require passive access to web activity, we’re introducing and continuing to iterate on new functionality that allows developers to deliver these use cases while preserving user privacy. For example, our new declarativeNetRequest API is designed to be a privacy-preserving method for extensions to block network requests without needing access to sensitive data. > The declarativeNetRequest API is an example of how Chrome is working to enable extensions, including ad blockers, to continue delivering their core functionality without requiring the extension to have access to potentially sensitive user data. This will allow many of the powerful extensions in our ecosystem to continue to provide a seamless user experience while still respecting user privacy. Basically, Chrome is hoping to use the same psychological effect as Apple's "Ad Tracking Transparency" (the opt-in screen for cross-app tracking) to make people opt-in for "read/write data on all sites" permission, to try to transition the amount of adblockers with that permission from 100% (currently) to ~20% (the amount of people who opt-in to tracking on iOS) by scaring users about extension permissions.
- nightpool 4y agoUnsourced comments that cite unsourced comments... this is exactly how FUD spreads. I agree that it's clear that Google wants to reduce the amount of extensions that users opt in to having access to their entire web browsing data. I don't think that's a psychological trick: I think it's very clear that most users don't understand that every single extension they install might have these permissions, and instead just click past the generic permissions dialogue that Google shows. I don't think that that translates to "Google's clearly signalled that they don't want Adblockers to use "read/write data on all websites"". What Google has clearly signaled is that they want users to be able to opt in to using this permission for the extensions that are most important to them, and that they want extensions to gracefully degrade when those permissions are not available. For most users, that's going to be ad blockers: basic features work without full site access, and advanced features are available with more site access. That seems like a good thing to me, not a reason to rip those advanced features out all together.
- Vinnl 4y agoDoes this mean that you're planning to migrate "regular" all-website-data uBO to MV3 at some point as well, with the caveat that some features won't work on Chrome?
- pmontra 4y agoI use cosmetic filtering a lot on Firefox Android. I routinely remove all the sticky-ish headers and footers from sites I visit often, because they are distracting, sometimes move, appear and disappear and uselessly take away space and distract me. Some popups too, even on Firefox desktop. I'm sure that there are other extensions doing that (Stylish? but the element picker of uBlock origin is extremely quick to use) however Firefox allows only very few extensions to run on Android. They are moving to v3 too [1] so I'm worried that I'm going to lose that feature on my phone or that it's going to become so inconvenient to use that I won't hide annoying elements as much as I do (lazyness, other things to do, etc.) I'm more than happy to give "read/modify data on all websites" permission to a trusted extension. I hope that you'll keep maintaining the current permission-full version of uBlock Origin too. [1] https://blog.mozilla.org/addons/2021/05/27/manifest-v3-update/ https://blog.mozilla.org/addons/2021/05/27/manifest-v3-updat...
- Semaphor 4y agoNote that they > have decided to […] continue maintaining support for blocking webRequest
- nightpool 4y agoUsing this declarative approach dramatically reduces the need for persistent host permissions Reduces != eliminate. Obviously, for some features, like adblockerblocker unblockers and cosmetic filtering, you still need persistent host permissions. Nobody has ever disputed that. The fact that DNR can remove persistent host permission for some ad blockers doesn't mean that it needs to remove them for all ad blockers. Also, you're taking that statement out of context: the documentation lists *three* separate reasons for DNR: privacy, performance, and compatibility with service workers. This reduces both the time it takes to process a network request (no need to serialize it to background page and then execute filter list matching in slow javascript) and the memory footprint of the browser (no need to keep an entire DOM background page loaded). It's clear that the performance goals here are at least as important as the security goals, if not more important, and they both go hand in hand. I don't understand what you perceive this negatively. By calling this the "MV3" version of uBlock, you're implying that MV3 has limited uBlock to these features and these features only, when nothing could be further form the truth. It's simply a form of misinformation to label this as the "MV3" version of uBlock. That's why I'm reacting to it negatively—it's hard not to see this as a continuation of your frustration with Chromium development team, and an attempt to paint MV3 in a bad light by purposefully releasing a crippled version of the extension. Users are going to see this extension, see that it's named "MV3", and then blame Google for the lack of features. It's just the same as lying to your users.