HN user

ghostwords

1,107 karma

https://github.com/ghostwords

[ my public key: https://keybase.io/alexei; my proof: https://keybase.io/alexei/sigs/_Wx0Ql1tQXR8Me59VHsoIVEy38ZPTMg6I47YDBF3eY8 ]

Posts11
Comments105
View on HN

Moving the toggle for "accounts.google.com" to full blocking in Privacy Badger ought to do it.

Heads up, full blocking of "accounts.google.com" will break some login pages entirely. But it is a good domain to fully block as long as you're comfortable using the "Disable for this site" button when something goes wrong.

You need multiple extensions

(I develop Privacy Badger.) There are significant benefits to adding PB or uBO to a browser that doesn't already ship with a real built-in ad blocker. While PB and uBO work well together and you may want to use both for various reasons, I wouldn't say you need both. Either one is enough by itself for most people.

HTTPS Everywhere

HTTPS Everywhere has been deprecated and eventually removed from extension stores a few years ago: https://www.eff.org/deeplinks/2021/09/https-actually-everywh...

Phishing detection

Why isn't what's built into browsers enough?

Cookie auto-delete

Why bother when blocking trackers and ads?

Pop-up blocking

Is that the same as the various "annoyances" ad blocker lists?

Hey, that's such a nice response, I appreciate it.

I think the thing on uBO's side is here on https://github.com/gorhill/uBlock :

Do NOT use uBO with any other content blocker. uBO performs as well as or better than most popular blockers. Other blockers can prevent uBO's privacy or anti-blocker-defusing features from working correctly.

My perspective:

- uBO is good enough by itself

- PB is good enough by itself

- uBO comes with unique features

- PB comes with unique features

- While using uBO with PB may indeed cause some problems like anti-blocker-defusing features to break, it doesn't seem like a big deal for most people

- uBO alone is good, PB alone is good, uBO + PB is also good

A better, more-to-the-point title might be the following quote from the post:

Safari makes it extremely difficult to use a custom search engine that's not in Safari's defaults.

(Yes, I know about this site's title guidelines.)

some functionality couldn't make it to his MV3 adblocker

One of the things that didn't make it is the entire request control dashboard. No more granular reporting or controls, at all. No more "medium mode" or "hard mode" (blocking unknown domains by default and making exceptions as you go). Sure, if you didn't use it before, you won't miss it.

Google can keep talking about user safety all they want but their talk is hollow because:

(A) Chrome Web Store is full of malicious extensions. Google doesn't appear interested in consistently enforcing their own policies.

(B) Requiring DNR does nothing about all the other avenues for stealing user data. The fundamental problem is that a totally safe set of extension APIs is a totally limited set of extension APIs. No real innovation or differentiation is possible.

Yeah I get it, but I think we're talking past each other. You're a knowledgeable user and the new APIs made it possible not to worry about uBlock getting hijacked. I'm an extension developer, and I see an appalling disconnect between what Google says and the reality of Chrome extensions and Chrome Web Store for regular (non-technical) users.