Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ameshkov
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
91.
▲
Apple brings Safari web extensions to iPhone and iPad
(developer.apple.com)
5 points
by
ameshkov
5y ago
|
0 comments
92.
▲
by
ameshkov
5y ago
Well, to be fair, not really. Scriptlets will continue to work just okay. To be completely honest, Manifest V3 technically is not THAT bad and it's capabilities at the current moment are really close to what major ad blockers can do. T
93.
▲
by
ameshkov
5y ago
Running the app is not mandatory and neither is adding buttons to the interface. If you just need content blockers, you can simply enable just them, close the app and forget about it until you feel the need to check filters updates.
94.
▲
by
ameshkov
5y ago
I do honestly believe they want to make content blockers good. Maybe the problem is that we don't communicate our pains good enough, maybe it's that they don't hear us sometimes, but I think that we have the common goal and t
95.
▲
by
ameshkov
5y ago
> SFSafariExtensionHandler implements SFSafariExtensionHandling protocol, which has this function First of all, shame on me for missing this, and thank you for pointing this out. Unfortunately, this still does not solve the issue in ques
96.
▲
by
ameshkov
5y ago
All those browsers have to use Safari (WKWebView) internally so they are close. There’s an important difference, these browsers can also run additional JS on web pages and partly compensate for missing content blocking capabilities. This co
97.
▲
by
ameshkov
5y ago
Well, I have the same exact experience and frankly, it is not what I intend to repeat again. At least developers can do that. But most of the people who maintain filter lists are not developers and cannot afford enjoying compiling WebKit fo
98.
▲
by
ameshkov
5y ago
As someone who contributed to the post we're discussing, let me please respond. > There’s SFSafariExtensionHandler API which you can use with blockers as another extension with higher privileges to track who blocked what. I am not s
99.
▲
by
ameshkov
5y ago
Safari on macOS supports executing custom JS on web pages since forever, regardless of what version of API is used. It’s not supported on iOS, though.
100.
▲
by
ameshkov
5y ago
Note that YT changes aren’t yet rolled out everywhere. Also, if you’re not authorized there’ll be no issues, but it won’t stay like that forever.
101.
▲
by
ameshkov
6y ago
Thank you for the very detailed explanation!
102.
▲
by
ameshkov
6y ago
Proving IP address ownership is done via HTTP challenge, nothing too problematic.
103.
▲
by
ameshkov
6y ago
So there would be ClientHello with greased ECH and SNI and ClientHello with real ECH and without SNI? Regarding blocking, what prevents Chinese firewall from simply removing ECH extension from all ClientHello packets? Servers that don’t exp
104.
▲
by
ameshkov
6y ago
If we're keeping this simple, then I'd say have IP address in subaltnames. Obtaining such certs shouldn't be a problem for CDNs, and possible for others as well (regarding free options: Let's Encrypt doesn't support
105.
▲
by
ameshkov
6y ago
As someone suggested in a different comment: handshake with one certificate, then send a new ClientHello that contains the desired hostname and "re-handshake" with the real cert?
106.
▲
by
ameshkov
6y ago
I've been loosely following ESNI/ECH drafts, and I am not sure this approach (double handshake) was ever seriously considered despite that it sounds perfectly fine to me. It'd make the handshake heavier, but on the other hand
107.
▲
by
ameshkov
6y ago
> it appears they assume people are using DoH or DoT Things changed since then, now plain DNS is also allowed.
108.
▲
by
ameshkov
6y ago
Can anyone explain why is it designed this way? Why was it necessary to involve DNS into this? Was it unavoidable or is that all in the name of keeping 0-rtt possible? Tbh, with the current implementation, ECH setup seems rather complicated
109.
▲
by
ameshkov
6y ago
AdGuard dev here. Can confirm - it’s not sufficient. But the reason it got less criticism is a little different. Content blocking in Safari was never good, and content blocking API when it just appeared was a move forward. The problem is th
110.
▲
by
ameshkov
6y ago
All free software that we make is open source. Paid - closed source (save for AdGuard for iOS, it's open source despite having some premium features).
111.
▲
by
ameshkov
6y ago
This just makes me extremely sad. Server products is what made us purchase Atlassian software. There are numerous reasons why our company (and a lot of other companies I presume) would like to avoid cloud. And if we really had to go cloud,
112.
▲
Atlassian moving to cloud-only, will stop selling server licenses
(atlassian.com)
380 points
by
ameshkov
6y ago
|
298 comments
113.
▲
Kickstarter: Open-Source Sciter Engine
(kickstarter.com)
18 points
by
ameshkov
6y ago
|
3 comments
114.
▲
Promoted Add-ons Pilot
(blog.mozilla.org)
153 points
by
ameshkov
6y ago
|
130 comments
115.
▲
Russian anti-trust agency decides against Apple App Store
(nytimes.com)
1 points
by
ameshkov
6y ago
|
0 comments
116.
▲
by
ameshkov
6y ago
1. SSL pinning is not actually that widespread. However, it is used by quite popular apps - Facebook and Twitter. Unfortunately, there is no way to deal with it without patching the apps itself. Also, modern Android versions limit the trust
117.
▲
by
ameshkov
6y ago
If all pages were static this would’ve worked beautifully. But they aren’t, and uBO approach also implies that there is a mutation observer constantly monitoring DOM changes and adding new rules when they are needed. In a browser extension
118.
▲
by
ameshkov
6y ago
1. Yes, it basically injects a CSS stylesheet into every page + a JS script that does additional filtering. 2. Yes, in order for this to work, AG will need to access response body. 3. Yes, and in this case we'll need to use JS-based fi
119.
▲
by
ameshkov
6y ago
Just a quick note about that: > does not have to wait for a DNS resolver to respond The browser (or the system) caches DNS responses and the query for a blocked domain won't be repeated for quite some time.
120.
▲
by
ameshkov
6y ago
Well, to be honest, AdGuard not-the-extension technically cannot be the fastest. It does a lot of things to do system-wide blocking - analyzing the connection, passing network packets, parsing protocols, this all adds some overhead. Brows
More ›