8 ms·
>I am down to zero third-party developers that can get compromised and silently push an update that compromises all my web sessions. It's my understanding that
by e2le 3y ago
>I am down to zero third-party developers that can get compromised and silently push an update that compromises all my web sessions.
It's my understanding that because uBlock Origin is a "recommended extension", it must undergo a formal code review each time a new update is published. A malicious update would not face zero obstacles.
https://support.mozilla.org/en-US/kb/recommended-extensions-program https://support.mozilla.org/en-US/kb/recommended-extensions-...
- Timshel 3y agoThe switch from full acces to white-listing for full blocking is just awesome imo. You can just decide for each case the tradeoff between advanced blocking and security.
- e2le 3y agoI'm unsure of how it exactly differs and whether there are features missing. I will admit that if I were to install uBOL today, I would be worried that it would be less capable and my browsing experience less-safe.
- eipi10_hn 3y agoThere are many features missing, more prone to anti-adblock/ads-reinsertion (problems with `redirect-rule` and unable to fast updates) and ads/trackers/popups can slip through if cannot be caught by regex filters.
- odo1242 3y agoalso: - one thing that is much less powerful is cosmetic filters, which means ads may be replaced with gray squares if uBOL can't remove them entirely - less filters overall, because the limits on how many filters are possible are pretty strict - extension updates will be both larger and much more frequent because filter lists can no longer be updated separately from the extension
- flangola7 3y agoWhy is there a filter limit at all? Why did Firefox add that? Can config change it?
- postalrat 3y agoFilters aren't free
- wtallis 3y agoThey are quite often better than free, blocking unwanted content that would consume more memory and CPU time than the filter itself.
- JacobSeated 3y agoFilters take a minuscule amount of resources. E.g. Even if you had to loop over a list with thousands of entries this would be unlikely to matter, and can in fact even be optimized quite significantly with various algorithms. However, because a database is most likely used, this is not even an issue, and the resource use will in fact be truly minimal. I can not give you an exact number, but it is massively bigger than the number of trackers / elements that any usable web page can realistically implement. Probably you can do several thousands database calls in less than a second due to indexing; and that can be further optimized by doing it in batches, bringing it up to tens of thousands, if not in the hundreds on modern PCs. It is literally not an issue.
- postalrat 3y agoIs the limit still around 30,000 or is it higher? That could be 600,000 filter checks on a page load with 20 requests. I'm sure it's fast but if people want unlimited number of rules that number could start exploding.
- bornfreddy 3y ago> Why did Firefox add that? They didn't, Google did. It is part of MV3 specs, afaik.
- winter_blue 3y agoHmm, it looks like the uBO "Enter element picker mode" feature is not available. I've found that pretty useful occasionally in the past on websites where uBO doesn't catch an ad.
- deleted 3y ago[deleted]
- yellowapple 3y agoThat tradeoff is already possible with the normal uBlock Origin; it just has a different (preferable IMO) default. The only apparent upside to this version is if you don't trust Raymond Hill to refrain from spying on your browsing sessions via his add-on. By every other metric this seems like a downgrade.
- akyuu 3y agoIf you use a non-declarative adblocker, you're not just trusting the developer, but also all the third-party filter lists you've subscribed to. These filters have powerful capabilities and can even exfiltrate website data [1], and they are updated in real time, so if a bad actor pushed a malicious update (e.g. by gaining access to any EasyList contributor account), you would most likely be affected. However, it's true some websites (like YouTube) are especially problematic and a declarative adblocker is not enough. What you can do is combine both approaches: use a declarative adblocker (uBlock Origin Lite) as a baseline, and selectively enable non-declarative adblockers (uBlock Origin) for specific websites (see [2] for a detailed overview). I like this layered approach because it gets you the best of both worlds: the security and performance of a declarative adblocker, and the functionality of a non-declarative adblocker when you need it, without compromising your entire browsing session. [1] https://portswigger.net/research/ublock-i-exfiltrate-exploiting-ad-blockers-with-css https://portswigger.net/research/ublock-i-exfiltrate-exploit... [2] https://seirdy.one/posts/2022/06/04/layered-content-blocking/ https://seirdy.one/posts/2022/06/04/layered-content-blocking...
- nottorp 3y agoWhy do you think so? Say I open HN on my morning coffee and open 5 links in new tabs. They don't have to be to sites I've opened before. I will be tracked until i go to each tab and add it to uBlock Origin. How is that an improvement?
- mattstir 3y agoIt truly does seem like a misinformed take on security, believing that being actively tracked is better than the possibility of being tracked if uBlock Origin were ever to be compromised.
- nottorp 3y agoThose evil hackers always compromise open source code first, never the ads that no one is reviewing!
- mmis1000 3y agoActually every extension on AMO must go through manual inspection to push as auto update. You may push new version to market without manual inspection. But it won't auto update to users' computers until then. So human review really isn't the real difference on firefox's side. Because it is required since day one
- Semaphor 3y agoDo you have a source for this? I always thought they long ago stopped manual inspections for most extensions.
- mmis1000 3y agoI literally wrote one. And it had been taken down due to reviewer unable to reproduce the achieve I uploaded (it turns out to be a \r\n \n line ending issue. Thanks windows and git).
- zagrebian 3y agoOk, when adding a new extension to the store. But “recommended extensions” get manually reviewed whenever they update.
- Semaphor 3y agoI maintain one as well, and had it approved despite the source having a bug, so that doesn’t sound like much of a source.
- mmis1000 3y agoI don't think they ever care about whether your extension has bug or not. They probably only review whether your extension has weird minified code or dependencies.
- Semaphor 3y agoIt was a bug that prevented building it. If they just look at the source code without building it, they’ll have no idea if it’s the same code at all, and it would be useless.