16 ms·
Proxy Chrome extensions are not going to be usable in MV3
- bakugo 4y agoLast time I tried to use onAuthRequired in Chrome I found that it was already broken in some contexts. I think it's pretty clear that Google is on track to phase out extensions completely within the next decade.
- olso 4y agoChromium team has not commented on this bug with 650+ stars (within top 10 https://bugs.chromium.org/p/chromium/issues/list?sort=-stars&colspec=ID%20Pri%20Type%20Component%20Status%20Summary%20Owner%20Target%20M%20Reporter%20Modified%20Opened%20Stars&q=&can=2 https://bugs.chromium.org/p/chromium/issues/list?sort=-stars... issues) in months
- aftbit 4y agoAnd after they specifically said: >Sorry no updates yet. Please star the bug if you wish to see this fixed sooner. Okay Google, we've starred the bug. Please fix now.
- MatthiasPortzel 4y agoI think this is the real story here. Google pretends to be listening to real-world use-cases and user feedback and developing Chromium in the open, but at the end of the day, some manager has decided the millions of people using these extensions aren’t worth supporting, and that’s the end of the conversation.
- TheChaplain 4y agoIt's not about support, it's a money issue. Adblocking doesn't generate money, so out it goes.
- TedDoesntTalk 4y agoBut we are talking about proxy extensions, not ad block extensions.
- agilob 4y agoopensource coming from Google, Amazon, Microsoft, OpenAI or even recent garbage coming from RedHat is just a nice facade. It's broken, it's locked to a platform, often no compiling instructions or out of date by 3 years with multiple bug reports. It's just a marketing move that came from Google early 00s' and then was widely adopted by MS: "Microsoft <3 OpenSouce - Contribute Here (for us for free, we can't be bothered to fix this TOP 10 bug or update documentation)".
- IshKebab 4y agoIt's not really any different for Firefox though is it? In fact it's not really any different for any big open source project. Someone ultimately has the power to decide what features to develop and nothing forces them to listen to their users. Look at things like Firefox's Pocket integration, or like all of Gnome.
- concinds 4y ago">Sorry no updates yet. Please star the bug if you wish to see this fixed sooner." Translation: my manager is blocking this; please star this so have a better chance of changing his mind.
- devwastaken 4y agoIt's cases such as these invalidate the "they're not acting with malice". Thousands of google employees see this stuff, and are clearly being told they can't talk about it.
- pessimizer 4y agoYou haven't applied Hanlon's Razor properly. They're just coordinating incompetence that they find beneficial, not being malicious.
- GauntletWizard 4y agoSufficiently weaponized incompetence is indistinguishable from malice.
- babypuncher 4y agoThe act of weaponizing incompetence is itself malicious.
- kwhitefoot 4y agoIf you are coordinating the incompetence then you are malicious even if the incompetent are not.
- devwastaken 4y agoSomeone in authority said or inferred some version of "don't talk about this, don't get involved". That's malicious.
- DangitBobby 4y agoI think it's more likely that no one wanted to take ownership of it, so no one did.
- deleted 4y ago[deleted]
- mjrpes 4y agoChromium team replied as of 10 minutes ago to that thread (thanks to HN exposure): "I'm temporarily restricting comments to keep comments from turning into +1s while this is trending on Hacker News. If you have additional thoughts that you'd like to share with the Chromium team regarding this issue, please return in a few days to leave a comment (and apologies for the inconvenience)." "As a Chromium contributor that shares information about our progress on extensions issues, I sincerely apologize to extensions developers affected by this issue and the broader community for not sharing an update until now. I'm currently working on a "known issues" document for Manifest V3 that touches on several outstanding issues (including this one), but given the attention on this issue now, I'll quickly share our current thinking on this issue." "We have always intended to provide support for this functionality in Manifest V3 (for both user-installed and force-installed extensions), and have been iterating on different possible approaches. Our tentative plan (which is not yet finalized) is that the Manifest V3 version of this capability will require extensions to request a new permission scoped to intercepting authentication requests, but will otherwise allow extensions to handle these requests in a similar manner to how they do in Manifest V2." "The permission string and end user facing warning string have not been finalized yet. Also, we have not yet finalized how this new permission will interact with other permission grants, but extensions that currently have the webRequest permission and broad host permissions will likely not require an additional grant for this permission." "Finally, I want to note that before we can pursue this capability, we first need to resolve issue 1024211 (now formally marked as a blocker). We are actively working on 1024211 and aim to resolve both that issue and this one before January 2023."
- yegor 4y agoOhh that's nice. So we're gonna get a fix last week of December, and will have to dev around a new API in a few days, test everything, and release it to millions of users hoping for the best. Man, Google sucks.
- cute_boi 4y agoSo, they should also delay blocking of MV 2 if they aren't gonna give time to other developers. But nah, chromium team just wanted to block the comments so they don't get bad PR. Google is such a shame these days.
- aeharding 4y agoIt's extremely frustrating how Google is ignoring this issue. So much for developer relations.
- nitrixion 4y agoThis type of decision has fully cemented that Google is an advertising company. Every decision they make is to benefit advertisers regardless of how it affects users and developers.
- ridiculous_fish 4y agoHow does this decision benefit advertisers? Honest question.
- JohnFen 4y agoIt greatly restricts how effective ad blockers can be.
- TedDoesntTalk 4y agoProxy extensions are not the same as adblockers.
- hakfoo 4y agoMaybe the entire Manifest V3 concept is "Gish Gallop" applied to software design. Create so much of a bag of questionable features that people are just trying to keep up with the nonsense, and hopefully it keeps us divided and unable to actually able to mount a solid response to their (not really buried) real goal, which is to stab at the ad-blocker industry. It would be interesting to consider their business values on proxies too; while on the abstract level, it dilutes tracking data quality (I don't really live inside a data centre in Stockholm?!), it might improve the value of their more broadly aggregated data (we've seen this user's fingerprint elsewhere, so we can give you a more accurate location than Geo-IP lookup does)
- yegor 4y agoAs a proxy extension developer, this is absolutely maddening. We're forced to choose between auth-less open proxies (bad), or baking in a wacky authentication scheme through a side channel (also bad). MV3 drops in 2.5 months, and will leave tens of millions of proxy extension users unable to use products they paid money for. This is all on top of the many other issues with MV3 that Google is pushing under the guise of "improving performance".
- rasz 4y agoV3 will improve performance of ads division.
- yegor 4y agoWhere is EU when you need them with their anti-trust litigation. Google is pulling a 2000s Microsoft.
- eastendguy 4y agoThere is an easy alternative: Use Firefox
- naikrovek 4y agothat doesn't fix the problem, though.
- preinheimer 4y agoIt's telling that the last action from a google employee on the list was ... removing themselves from the notification list.
- cute_boi 4y agoDon't worry these same chromium team will remove MV2 in name of security or performance. Modern software development by Google ...
- andrewliakh 4y agoIt looks like they did this on purpose, otherwise they won't ignore such an important issue.
- superkuh 4y agoI don't want to pile on here but everyone who used Chromium while pretending they weren't supporting google's Chrome monopoly, pretending Chromium was something else, are getting the only outcome that was possible. It was entirely predictable from the start and if you play stupid games you win stupid prizes.
- jerheinze 4y agoIt's not like no one was making warnings about this.
- TedDoesntTalk 4y agoSomeone warned years ago that proxy extensions would no longer be feasible on Chromium? I must have missed that message.
- jerheinze 4y agoNot that explicitly, but many warned about Google abusing their power if it started hitting their profits.
- moffkalast 4y agoI'm more interested why it isn't possible to just fork the thing and maintain a version that's plugin enabled. Isn't Chromium completely open source? Especially for Brave, Vivaldi, Opera, etc.
- AshamedCaptain 4y agoDeveloper effort.
- moffkalast 4y agoDon't underestimate the power of spite.
- guilhas 4y ago2 years without a reply, maybe it's a feature. Could they be afraid of a surge in proxy Adblock extensions since they are trying to cripple the local ones?
- staticassertion 4y agoA proxy extension requires rewriting arbitrary requests on the fly, which is removed from V3 as a general capability.
- TedDoesntTalk 4y ago> A proxy extension requires rewriting arbitrary requests on the fly That is completely incorrect. A proxy extension routes requests through a proxy server. It does not rewrite anything.
- staticassertion 4y agoOK and presumably it does that by taking a request for an address A and rewriting part of it so that it actually goes to B with some additional headers to indicate how to forward it. edit: Apparently I've hit my HN rate limit so I can't reply! Thanks Dang. As for the proxying, obviously something has to rewrite the address that the request is going to. Depending on the type of proxy (ex: HTTP CONNECT) you may also have an x-forwarded-by header set. It sounds like Chrome never allowed you to do this manually, cool TIL.
- TedDoesntTalk 4y agoI mean, you are just completely wrong. It does not rewrite the request. It does not change headers. There is an API that allows the extension to set a proxy server destination: https://developer.chrome.com/docs/extensions/reference/proxy/ https://developer.chrome.com/docs/extensions/reference/proxy... And that API does not change the request, either. That is not how proxying works.
- ltbarcly3 4y ago
- s_ting765 4y agoI thought they were pushing it when they announced MV3, which would purposely can ad blockers. But this would finally put the nail to this coffin. Now I'm even more curious to see how badly Chromium bangles this migration to V3. I'm also curious as to why big internet advocacy organizations such as the EFF [0] have been quiet on this move. -- Edit: It appears the EFF has spoken out about this a couple of times. [0] https://www.eff.org/deeplinks/2021/12/googles-manifest-v3-still-hurts-privacy-security-innovation https://www.eff.org/deeplinks/2021/12/googles-manifest-v3-st...
- forgotusername6 4y agoHas someone tried to fix this themselves yet?
- altdataseller 4y agoDoes anyone know when MV3 will be released, or when this will start to impact a large # of users?
- ajayyy 4y agoMV2 will be disabled by default Chrome in January 2023, and the flag to reenable it will be removed in June
- TedDoesntTalk 4y agoGoogle’s own top 10 extensions with over 10 million users is still on MV2.
- ck2 4y agobtw just like there were enterprise-hacks for Windows v7 to keep it going, manifest v2 will still work if users can be taught to turn on "managed mode" in their Chrome extends v2 from January 2023 EOL until June 2023 January 2023 Chrome stops running Manifest V2 extensions Enterprise policy can let Manifest V2 extensions run on Chrome deployments within the organization. June 2023 Manifest V2 extensions no longer function in Chrome even with the use of enterprise policy
- altdataseller 4y agoDoes this impact VPN extensions like Hola VPN ?
- easrng 4y agoHola essentially puts you in a botnet (Luminati/Bright Data), you shouldn't use it.
- altdataseller 4y agoYeah, I know :) I just want to know if it affects them, because I hope it does :)
- DanAtC 4y agoMV3 sucks and all, but why do you need an extension to set up proxy settings? Is this in lieu of a whole-device VPN?
- TedDoesntTalk 4y agoYes
- somat 4y agoAre proxy extensions just a hook to set the http_proxy? I always have a hard time with chrome. because where firefox has a config area to set the proxy chrome wants to use an environment variable. so do these proxy extensions fill this missing config gap?
- WirelessGigabit 4y agoYes. I can do a per page proxy with extensions which is helpful when doing debugging / mitm.
- perryizgr8 4y agoCan someone ELI5 what are proxy extensions? What are they supposed to do?
- e40 4y agoI use a HTTP/HTTPS proxy in Chrome (and Firefox) to work remotely and access internal things from my work network. The proxy I use has very nice features to allow "auto switching", meaning based on an regex I can use the proxy or go direct. The rules are ordered any way you want them. The proxy we all use at work is SwitchyOmega. Been using it for years and it's fantastic.
- TedDoesntTalk 4y agoFoxyProxy is another popular one with millions of users.
- alcover 4y agoSo.. Chrome is too big to fork. Then why don't we make a bare-bones OSS no-DRM browser with only a subset of JS and CSS and promote at the same time an old-school webring of 'virtous' websites. If it catches on (and it could since it'd be free and fast), maybe some big sites would evolve to advertise themselves as 'virtous'.
- TremendousJudge 4y agoI don't get it, Firefox already exists and is a complete OSS reimplementation of everything Chrome does (and works better imo). Only thing to do is convince sites to test more on Firefox. This strategy worked last time around.
- jeffbee 4y agoFirefox gives up 40-60% of the performance of Chrome on my platform, using common browser benchmarks. I don't see Firefox as a substitute good for Chrome. It has much worse performance, worse security, and lacks features I want. Its performance is equivalent to using Chrome on an 8-year-old CPU. The only thing it has going for it is being perceived as counter-cultural, despite the fact that it is 100% funded by Google.
- reciprocity 4y agoYour claim is that you suffer a _40 to 60_% performance impact by using Firefox from Chrome? Would you like to try that again? I see egregious comments like this of Firefox every so often and I always have to wonder if the last time people making these remarks actually used Firefox was in the pre-Quantum era (assuming one charitable interpretation). To claim that its performance is equivalent to using Chrome on a CPU from 2013 is disingenuous at best. Firefox is not just perceived as 'counter-cultural', its importance lies in the fact that not using Chrome and similar browsers is also a vote not to support a browser monoculture online.
- jeffbee 4y agoI invite you to try Safari, Chrome, and Firefox on an Apple Silicon CPU right now. Firefox is the slowest of these by a HUGE margin.
- lizardactivist 4y agoI don't know the full scope of consequences and Google's reasoning for this, but I'm going to guess it's either done under the false pretenses of improving performance, or improving security. Could there possibly be a positive outlook for improving ad revenue as well? Time to settle with Firefox.
- GolegN 4y ago
- TedDoesntTalk 4y agohttps://github.com/w3c/webextensions/issues/264 https://github.com/w3c/webextensions/issues/264
- btown 4y agoDoes this mean that (non-open-proxy) VPNs will no longer be usable on a per-Chrome-profile basis? So one would need to either route all traffic through a VPN at the OS level, or none at all?
- olso 4y agoYou can still authenticate via basic auth popup, but you can’t automate it (UX friendly). There are some workarounds mentioned in the bug comments, but they are workarounds with their own issues.
- HellsMaddy 4y agoManifest V2 deprecation is likely going to break extensions that inject userscripts, like Tampermonkey [0] and SurfingKeys [1]. The Chrome team has been rather unhelpful. They've promised to add support for power-user tools like these in MV3: dotproto from the Chrome team commented on May 27 [2]: > @mon-jai, the short answer is no, I don't have any updates to share. That said, I'll reaffirm that we plan to support userscript managers in Maniest V3 before the Manifest V2 deprecation. But the deprecation is approaching and the Chrome team hasn't released any more information about this AFAIK. These extensions are going to require large refactors to support MV3 and they can't meaningfully start until the Chrome team elucidates how script injection will work. With MV2 deprecation coming so soon, I worry there won't be enough time. [0]: Manifest V3: examine the effects · Issue #644 · Tampermonkey/tampermonkey: https://github.com/Tampermonkey/tampermonkey/issues/644 https://github.com/Tampermonkey/tampermonkey/issues/644 [1]: Migrate to Manifest V3 · Issue #1821 · brookhong/Surfingkeys - https://github.com/brookhong/Surfingkeys/issues/1821 https://github.com/brookhong/Surfingkeys/issues/1821 [2]: https://github.com/Tampermonkey/tampermonkey/issues/644#issuecomment-1140110430 https://github.com/Tampermonkey/tampermonkey/issues/644#issu...
- dotproto 4y agoHey, I'm that Simeon/dotproto guy! We discussed Chromium's current plan to support user scripts managers in Manifest V3 during our WebExtensions Community Group (WECG) session at TPAC[1] last week. The notes for that meeting haven't been merged yet, but there's an open PR[2] and when they are they will live here[3]. In short, the current plan in Chromium is to require end users and extension authors to opt into execution of arbitrary scripts via a Chromium UI setting and new permission, respectively. During the meeting Firefox folks raised some questions/concerns about this plan and it's probably best to try to align with them on next steps if possible. And typing this out is making me realize we don't have a great tracking issue for this in the WECG repo. Just threw together a placeholder issue[4] to track discussion in this area. [1]: https://www.w3.org/events/meetings/7bbba4a3-8305-45cd-a998-67ede8b0a1a1 https://www.w3.org/events/meetings/7bbba4a3-8305-45cd-a998-6... [2]: https://github.com/w3c/webextensions/pull/277 https://github.com/w3c/webextensions/pull/277 [3]: https://github.com/w3c/webextensions/blob/main/_minutes/2022-09-15-wecg-tpac.md https://github.com/w3c/webextensions/blob/main/_minutes/2022... [4]: https://github.com/w3c/webextensions/issues/279 https://github.com/w3c/webextensions/issues/279
- PostOnce 4y agoOnce upon a time many years ago, Chrome was marginally better than Firefox. That time has long since passed. I know, I switched from Firefox to Chrome and used it for a couple of years, but Firefox got better and Chrome got worse, so I've been back on Firefox for many years again now. If Chrome doesn't do what you want or what you like, use Firefox. It does everything Chrome does, and more.
- d3nj4l 4y agoI like Firefox and am a loyal, long term user - used it before quantum kind of loyal - but it is by far the least efficient browser on macOS with M1. In my rough personal testing Brave (based on chromium) is significantly more energy efficient, getting me up to 30% more battery time. I'm not sure why, but it's making it harder and harder to justify sticking with FF.
- okasaki 4y agoBizarre. To me firefox looks like it's falling apart at the seams. Here's a new profile, just default zoom set to 150% (ublock origin installed system-wide) https://i.imgur.com/Z3MO8sr.png https://i.imgur.com/Z3MO8sr.png https://i.imgur.com/hgscGrb.png https://i.imgur.com/hgscGrb.png https://i.imgur.com/07QI1IU.png https://i.imgur.com/07QI1IU.png https://i.imgur.com/owZm12J.png https://i.imgur.com/owZm12J.png What is even going on?
- yoasif_ 4y agoNot sure what you are frustrated with (can't read minds), but in my testing, the zoom setting you showed doesn't affect browser chrome, just web pages. Not sure why the rest of your chrome seems oversized, but you may be experiencing a bug. I'd report it.
- okasaki 4y agoYou can't read minds, that's why I posted screenshots. Surely you can see the difference between the font sizes for the ublock origin popup, and the enormous fonts on the settings page. It's totally broken?
- AlexanderTheGr8 4y agoNot trying to throw ML at the wall, but could it be used for this problem (considering all other options seem to be failing)? As far as I understand, after MV3, ad blockers won't be able to use a long list of ads to remove them. How about using a simple ML algorithm to detect whether the request is a genuine one or an advertisement? I am sure that getting training data wouldn't be too hard (all the ad lists that will get useless after MV3 are good data). I don't make chrome extensions so I don't completely know how MV3 will cripple ad blockers. Any feedback would be appreciated!
- jimmydorry 4y agoThe point of the change is to go from allowing extensions unfettered access to read, rewrite and exfiltrate everything you request, to forcing them to declare upfront what they will block. Sure, there are still going to be some work arounds that still allow extensions to read and change what a user sees, but anyone looking at this honestly can see what the intention is. Throwing ML at this problem doesn't make sense at all as reading and then rewriting requests is exactly what Google doesn't want extensions doing anymore.
- mastazi 4y agoI keep seeing sentences like "MV3 is approaching", "when MV3 drops in x months", but the reality is that MV3 is already here and affecting extensions! New extensions that use MV2 have been prevented from being added to the store since last January [1] and this has already affected some extensions which, as a result, have to be installed manually [2][3] The time to switch to Firefox is right now. [1] https://developer.chrome.com/docs/extensions/mv2/ https://developer.chrome.com/docs/extensions/mv2/ [2] https://github.com/libredirect/libredirect/issues/45#issuecomment-1059010144 https://github.com/libredirect/libredirect/issues/45#issueco... [3] https://libredirect.github.io/faq.html#chrome_web_store https://libredirect.github.io/faq.html#chrome_web_store
- XorNot 4y agoThe time to switch was yesterday, really. Google controls Chromium (don't kid yourself that it doesn't) and Google's business is ads. They are fundamentally misaligned with your interests on the net.
- olso 4y agoFinally, chromium people have spoken https://bugs.chromium.org/p/chromium/issues/detail?id=1135492#c92 https://bugs.chromium.org/p/chromium/issues/detail?id=113549...
- scoopertrooper 4y agoLooks like we caught someone's attention: > I'm temporarily restricting comments to keep comments from turning into +1s while this is trending on Hacker News. If you have additional thoughts that you'd like to share with the Chromium team regarding this issue, please return in a few days to leave a comment (and apologies for the inconvenience). > As a Chromium contributor that shares information about our progress on extensions issues, I sincerely apologize to extensions developers affected by this issue and the broader community for not sharing an update until now. I'm currently working on a "known issues" document for Manifest V3 that touches on several outstanding issues (including this one), but given the attention on this issue now, I'll quickly share our current thinking on this issue. > We have always intended to provide support for this functionality in Manifest V3 (for both user-installed and force-installed extensions), and have been iterating on different possible approaches. Our tentative plan (which is not yet finalized) is that the Manifest V3 version of this capability will require extensions to request a new permission scoped to intercepting authentication requests, but will otherwise allow extensions to handle these requests in a similar manner to how they do in Manifest V2. > The permission string and end user facing warning string have not been finalized yet. Also, we have not yet finalized how this new permission will interact with other permission grants, but extensions that currently have the webRequest permission and broad host permissions will likely not require an additional grant for this permission. > Finally, I want to note that before we can pursue this capability, we first need to resolve issue 1024211 (now formally marked as a blocker). We are actively working on 1024211 and aim to resolve both that issue and this one before January 2023. https://bugs.chromium.org/p/chromium/issues/detail?id=1135492#c92 https://bugs.chromium.org/p/chromium/issues/detail?id=113549...
- int_19h 4y agoWhat's really maddening is that it's the first comment from Google on that issue for over a year, despite numerous pleas of extension developers to provide guidance as the clock is ticking down.
- propogandist 4y agomay aggressive antitrust legislation compromise their core business and collapse their stock price
- dizhn 4y agoThe issue seems to be specifically about authentication of proxies. Something I could never find a good extension for in the past. What I ended up doing and found to be better is to connect to the proxy over a wireguard IP. I can recommend this solution to individuals and people who don't need granular authentication.