8 ms·
This is the uBlock Origin edition based on the much-maligned WebExtensions Manifest V3, which implements blocking declaratively instead of allowing/requiring li
by FiloSottile 3y ago
This is the uBlock Origin edition based on the much-maligned WebExtensions Manifest V3, which implements blocking declaratively instead of allowing/requiring live request interception.
Firefox—my daily driver—still supports the "main" uBlock Origin (and I'm a somewhat heavy user of features unavailable in Lite like custom filters), but I had been waiting for Lite to be available and immediately went ahead and replaced uBlock Origin with uBlock Origin Lite.
The security win can't be understated: with its permission-less design (enabled by MV3) I am down to zero third-party developers that can get compromised and silently push an update that compromises all my web sessions. Sure, attackers could still get into Mozilla, Apple (as I run macOS), or cause a backdoored update to be pushed via Homebrew (how I install unsandboxed applications when no web app is available, which thanks to the likes of WebUSB is getting less common), but unsandboxed browser extensions were clearly the lowest hanging fruit, so this update (and MV3) significantly raised my security posture (and transitively that of projects I have access to, and that of their users).
- deleted 3y ago[deleted]
- sneak 3y agoYou could also just turn off extension autoupdate.
- captn3m0 3y agoThat only makes a difference if you’re auditing each extension update. Switching to extensions with per-site permissions reduces the attack surface drastically and you don’t have to worry about auditing or disabling updates.
- FiloSottile 3y agoI considered that a few times, but eventually complex things like modern ad-blockers rot, so I would be forced to update every once in a while, and let's be honest: I am neither qualified nor prepared to audit the diff. I guess deferring updates would give me lead time to let others get targeted / detect an issue before it's likely I would get the update. Still, installing the permission-less version is so much simpler and reassuring.
- sneak 3y agoI rely on the latter. I am much more concerned about supply chain attacks of mass exploitation than I am about 0day in my Signal client or my browser extensions. If there is something big enough to warrant quick update, my HN addiction will make sure I find out about it before it is a 1day. There really isn't a great configuration for browser security rn, is there? The gold standard I think is Qubes, which afaict is not practical.
- huydotnet 3y agoTurn off extension autoupdate sounds like a bad choice, not all updates are mallware injected, many of them may contains security updates anyway
- sebzim4500 3y agoHqng on, MV3 still lets extensions read web traffic, right? It just can't block it.
- minedwiz 3y agodeclarativeNetRequest (https://developer.chrome.com/docs/extensions/reference/declarativeNetRequest/ https://developer.chrome.com/docs/extensions/reference/decla...) involves loading a ruleset into the browser, which then does the blocking itself inside the network process.
- FiloSottile 3y agoFirefox's implementation of MV3 allows both async permission-less blocking (declarativeNetRequest API) and permissioned synchronous blocking (webRequest API). uBO Lite uses the former to provide an ad-blocker without read/write permissions. You can still write a unsandboxed extension with MV3 (and in Firefox it will still be able to intercept requests, while in Chrome it will not be on the network hot path) but the point is that you can also write a permission-less ad-blocker now, which is what I want.
- npace12 3y agoYou need the webRequest API (that uBO Full is using) from manifest v2 to be able to read the traffic. Without it, you can just block/allow based on rules. Chrome is deprecating it with v3, Firefox supposedly no.
- sebzim4500 3y agoUnless I'm misunderstanding the docs, the webRequest permission isn't going anywhere, just the webRequestBlocking one. So it doesn't sound like there has been any security win here.
- npace12 3y agoYeah, I think you're correct. The security win is that you can block without needing the permissions for webRequest which are "can read and modify everything you do"
- Timshel 3y agoThe issue with v3 is when it's the only solution. Which is not the case here : > However, uBOL allows you to explicitly grant extended permissions on specific sites of your choice so that it can better filter on those sites using cosmetic filtering and scriptlet injections. Which I would expect allow it to work as well as uBO.
- zamalek 3y ago> Which I would expect allow it to work as well as uBO. Note that there are still some adblocker workarounds that will foil MV3, such as CNAMEs. uBO will always be more effective than MV3, unless some substantial improvements are made to MV3.
- cookiengineer 3y agoNote that CNAMEs is literally caused by GDPR, and the pathway every single ad or tracking company seems to go sooner or later. For people not understanding how it works: you can set a CNAME entry on your tracker.domain.tld to bypass all Browser's third-party tracking preventions, and make it look like it's a normal subdomain of your website. You need to make a CNAME tracker database manually by resolving the reverse entries for known IPs. Usually there is hundreds or thousands of CNAME entries pointing to the same IP address. The AdGuard team also made a database for this, in case anyone needs it for UBOL [1] Most, if not all of those trackers use assets that they serve from there (like a tracking pixel gif socket), so I highly doubt that uBOL will catch those; because the cat and mouse game is now in the ad tracker's favor and it is impossible to keep up now. And that was the intended purpose. We now have to play our hand with marked cards. [1] https://github.com/AdguardTeam/cname-trackers https://github.com/AdguardTeam/cname-trackers
- eurg 3y ago> Note that CNAMEs is literally caused by GDPR How so?
- cookiengineer 3y ago
- stefan_ 3y ago> attackers could still get into Mozilla, Apple (as I run macOS), or cause a backdoored update to be pushed via Homebrew [..] but unsandboxed browser extensions were clearly the lowest hanging fruit This is a total non-sequitur. The source of all malicious browser extensions is Google, Apple and Mozilla, and none of them have demonstrated any willingness whatsoever to fix the problem, even when a mere grep across their distributed extension base can trivially identify all the various openly advertised trojan SDKs that cause millions of users to be tracked or have their internet connection reused for various shady proxy websites.
- kccqzy 3y agoYou have a different definition of "malicious" than the general public. In fact most of us on HN do. That shouldn't be dictating what browser vendors think of as malicious extensions. Consider an extension that tracks your browsing in exchange for giving you promo codes to get 5% off on some purchase. Plenty of users have considered this kind of trade off and decided that the 5% discount is worth the privacy impact. Most HNers would consider it malicious. But if browser vendors start to block these extensions we would sooner hear news reports of tech companies being overly paternalistic. You are not speaking for all users and you know it.
- e2le 3y ago>I am down to zero third-party developers that can get compromised and silently push an update that compromises all my web sessions. It's my understanding that because uBlock Origin is a "recommended extension", it must undergo a formal code review each time a new update is published. A malicious update would not face zero obstacles. https://support.mozilla.org/en-US/kb/recommended-extensions-program https://support.mozilla.org/en-US/kb/recommended-extensions-...
- Timshel 3y agoThe switch from full acces to white-listing for full blocking is just awesome imo. You can just decide for each case the tradeoff between advanced blocking and security.
- e2le 3y agoI'm unsure of how it exactly differs and whether there are features missing. I will admit that if I were to install uBOL today, I would be worried that it would be less capable and my browsing experience less-safe.
- eipi10_hn 3y agoThere are many features missing, more prone to anti-adblock/ads-reinsertion (problems with `redirect-rule` and unable to fast updates) and ads/trackers/popups can slip through if cannot be caught by regex filters.
- odo1242 3y agoalso: - one thing that is much less powerful is cosmetic filters, which means ads may be replaced with gray squares if uBOL can't remove them entirely - less filters overall, because the limits on how many filters are possible are pretty strict - extension updates will be both larger and much more frequent because filter lists can no longer be updated separately from the extension
- flangola7 3y ago
- dealuromanet 3y agoWhat do you think about using Brave on Apple with its built-in ad-blocking?
- predictabl3 3y agoSo can you tell Firefox to only allow MV3 (or MV3+sandboxed, I guess) extensions then? Or have you manually audited your list of extensions? I was sort of aware but your post clearly reminds me that Firefox extensions are probably my single biggest point of general vulnerability on my phone and computer, given how much is done in browser. Appreciate your original thoughts either way.
- 4bpp 3y agoIt seems like this issue could also be sidestepped by simply not silently pulling updates, especially in the case of something like browser extensions where the extension is sandboxed (so the potential negative impact of not immediately getting out a "critical security update" is bounded) but the developer is not fully trusted. Have we normalised micromanagement of the user by software vendors so far that this is no longer a default that anyone would consider?
- chii 3y ago> not silently pulling updates a regular user would not have the capability to audit an update. A power user, with entirely too much time on their hands, could of course, but one should not be designing systems based on such niche scenarios.
- Jach 3y agoThe scenario is: don't enable automatic updates. How long will a compromise exist before someone notices? Often, not very long at all. It's entirely common to avoid an issue because you haven't bothered to update. It's also part of why corpos have their own repository mirrors too since dev supply chain attacks have gotten more common and no one's going to audit their dozens/hundreds of NPM dependencies every update.
- Dalewyn 3y agoA regular user would also not not care about "web sessions", "permissions", "silent updates", and all the other techno-mumbo-jumbo they will file away in their folder of Do Not Care. Essentially, there's an issue of hypocrisy in the threat model and type of user proposed.
- eviks 3y agoBut one should be designing systems, unlike today where there is bad design of forced autoupdates For example, they could be a system of distributed code reviews where an update is offered to the users only after some review
- arsome 3y ago
- MC68328 3y ago> I am down to zero third-party developers that can get compromised and silently push an update that compromises all my web sessions Yeah, but is this really a risk for anyone who isn't the sort to have installed Bonzi Buddy back in the day? That attack surface, compared to that of brew, npm, pip, gem, etc., is miniscule. And browser plugins don't yank in obscure dependencies at install time. I only run uBlock, and I suspect I'm in the majority here, and my choice of browser is predicated on the availability of a non-crippled ad blocker, because malicious ads are the primary threat.
- anadem 3y ago> I only run uBlock, (as noted by fsckboy): uBlock was the original name for the add-on that subsequently was ethically compromised/"sold out to" advertisers uBlock Origin is the 2nd version written by the original author (gorhill) and is not compromised.
- boomer_joe 3y ago>as I run macOS How is the FDE story on macOS? Isn't it closed source - how can you tolerate that as a cryptographer? (Not saying Linux is perfect, cryptsetup doesn't have a secure AEAD mode)
- saagarjha 3y agoApple’s crypto implementation is.
- boomer_joe 3y agoAnd what's the use if you don't know they're not compiling against a backdoored version under the hood?
- saagarjha 3y agoThat's a different question.
- boomer_joe 3y agoNo, you're just moving the goalpost (and you're pretty bad at it too)
- saagarjha 3y agoPerhaps I’m bad at it because I wasn’t doing it at all? You asked how someone can trust a crypto implementation that isn’t open source. I replied to the to it directly: it actually is open source. Personally I see the source being available largely irrelevant but I replied to exactly what you asked for. Your second question is an entirely different topic, which is how you can trust that something isn’t backdoored. Notably, this has nothing to do with whether source is available. How I would typically do that is by inspecting the compiled artifacts themselves, which is the same whether the code is available or not. Of course, this requires that the OS or the AP or the crypto engine isn’t backdoored, for which there exist more involved verification processes. Whether this is possible to do in general is a difficult research area. It is, however, completely divorced from your view on how this works because auditing the properties you’re looking for does not rely on source code at least in a traditional sense.
- josephcsible 3y agoI'm pretty sure that once you factor in the security reduction from ad blocking being less effective, switching from uBO to uBOL is actually a net worsening of security posture.
- xvector 3y agoIf you're getting targeted with major browser zero-days, ads are the least of your concern.
- bboygravity 3y agoWhy do you assume you need to be targetted to be a victim of being pwned by ads?
- paulryanrogers 3y agoBecause exploits that can break out via ads are not usually worth burning on randos?
- saagarjha 3y agoTargeted ads let you make sure they don’t get deployed on randos.
- vGPU 3y agoThen you should be running more powerful tools like noscript and the full version of this, not a pared down version. Or a significantly more locked down version of Firefox on qubesOS. Manifestv3 will have negligible improvements on potential security risks and will significantly decrease overall security.
- flexagoon 3y agoIn what way does ad blocking improve your security? It significantly improves your user experience and slightly improves privacy, but it doesn't have anything to do with security, unless you click on random "download" links, which I assume people on HN don't do
- vachina 3y agoIf you don’t trust the OG ublock what makes you think you can trust the Lite ublock?
- Barrin92 3y agothe fact that it cannot do a lot of untrustworthy things under the new v3 policy, like remote execute code, that is literally the point.
- postalrat 3y agoThe point is to neuter extensions to the point where they can't effectively block ads.
- pritambaral 3y agoCan uBOL be autoupdated to a v2 extension? That would negate this point.
- tech234a 3y agoIt would only partially negate the point. Any new permissions would trigger a prompt for the user to accept the additional permissions before installing the update. Also there is some aspect of human review for updates to extensions on the Mozilla Addons site.
- pgeorgi 3y agoAt that point it would request the global "read and modify all sites" permission, which makes it kinda obvious.
- Dalewyn 3y ago>I am down to zero third-party developers that can get compromised and silently push an update that compromises all my web sessions. Why would you even have autoupdates in the first place if that is your threat model?
- dancemethis 3y agoYou use Mac. You are already being attacked by Apple. Both on the permissions to run the computing you want, and your data being harvested by them. Good on you nonetheless to check one less, but the one still open is much larger, so the fight goes on.
- downWidOutaFite 3y agoI don't like the goal of giving less power to extensions. Extensions have traditionally generated independent innovation, when they're allowed to. They're an escape hatch.
- eviks 3y agoIf you sideload an extension, you can achieve your 0 third-party silent autoupdate goal without compromising on any functionality (though this misfeature should be a per extension toggle at the browser level)
- justinclift 3y agoIn Firefox, you can disable automatic updates per-extension. So you don't need to sideload to achieve this.
- eviks 3y agoEven better, thanks for the correction
- deleted 3y ago[deleted]
- vGPU 3y agoLack of custom filters is an immediate no-go.
- wredue 3y agoAnd the security problems of malicious ads slipping through at higher rates aren’t an issue?
- the_gipsy 3y agoYou could just disable automatic updates on extensions. uBlock origin is a featured extension, so it's already audited. MV3 is safer, but so is running no adblocker at all. There is a tradeoff. I get much more ads on Safari+AdGuard (iPhone) which uses MV3 or some similar declarative approach, than on Firefox+uBlock-Origin where I get basically none. I still prefer to trust one extension like uBlock Origin, just like I trust other software packages on my system, and to really fend off all the web tracking nonsense.
- MasterYoda 3y ago> The security win can't be understated: with its permission-less design (enabled by MV3) I am down to zero third-party developers that can get compromised and silently push an update that compromises all my web sessions. Can you or someone else elaborate way it would be more secure? I dont quite follow or see the benefit.
- raxxorraxor 3y agoLook at the security on mobile OS. It is perfectly secure for Apple and Google. But seriously, the benefit is theoretical and only with the assumption that you believe Apple and Google to treat your data better than a third party. Brave assumption in my opinion.
- raxxorraxor 3y agoFor me this security scenario isn't relevant at all. It reminds me of the dysfunctional situation on mobile OS. Sure, theoretically a plugin could get compromised and an update would be malicious. That is true for any software I run on my machine. But it also comes with costs. The browser is less customizable and further locked down. That reduces possibilities without netting advantages for me. Overall this is security FUD in my opinion. And the negatives can be observed in mobile OS.
- account42 3y agoRight, I would rather have a slightly less "secure" computer that I control than a super secure walled garden client.
- pipes 3y agoIs there any benefit to ublock origin full fat Vs lite? I've been using it for years on Firefox and android but it sounds like I should switch?
- bobby_the_whale 3y ago[dead]
- googleismalware 3y ago[dead]