What browsers lack per-domain cookie controls?
HN user
kretor
Sounds like "377071" is the correct response.
From the article:
"In this cohort, the risk of MS increased 32-fold after infection with EBV but was unchanged after infection with other viruses."
Not "very few other sites", it's around 700 sites: https://news.ycombinator.com/item?id=24819473
I don't think those tweets are gone.
The "Tweets & replies" section of your profile (https://twitter.com/eggsome/with_replies ) has two tweets that seem to match your description:
The 30k rules limit is not final.
we are currently planning to change the rule limit from maximum of 30k rules per extension to a global maximum of 150k rules.
(https://blog.chromium.org/2019/06/web-request-and-declarativ...)
With Google's new API, all ads can still be blocked. There will be a limit for network request blocking rules, but it's very high so that normal users don't reach it. And for those that reach it, only network requests are affected, so adblockers can still use other APIs to hide the ads.
we are currently planning to change the rule limit from maximum of 30k rules per extension to a global maximum of 150k rules.
(https://blog.chromium.org/2019/06/web-request-and-declarativ...)
Fixed: https://www.reddit.com/r/chrome/comments/dgoymg/warning_ubo_...
Hey all, I'm Simeon, the developer advocate for Chrome extensions. This morning I heard from the review team; they've approved the current draft so next publish should go through. Unfortunately it's the weekend, so most folks are out, but I'm planning to follow up with u/gorhill4 with more details once I have them.
But then there's also this -- leftists preferring the Financial Times: https://www.cjr.org/special_report/why-the-left-cant-stand-t...
There's a browser extension which clicks away the consent dialogues for you:
https://www.i-dont-care-about-cookies.eu/
It lets you specify a global setting to what extent you want to be tracked, and communicates that to sites that support the extension's "standard".
Tavis Ormandy, who discovered the latest and several other Lastpass bugs, has these password manager recommendations:
"KeePass and KeePassX are both good choices. If you really must use an online one, at least LastPass are responsive to researchers and have a competent security team, I would use them."
Asked about the experience he had reporting a 1Password vulnerability, he says:
"Astonishingly bad"
(source: https://twitter.com/taviso/status/1167311357957435392)
Password manager recommendations from Tavis Ormandy, who found the bug:
"KeePass and KeePassX are both good choices. If you really must use an online one, at least LastPass are responsive to researchers and have a competent security team, I would use them."
He adds about Lastpass:
"I consider them competent, I've reported some pretty complex issues and found they handle them well. Attack surface is definitely massive, I always recommend KeePass or just use a book if that's too complicated"
(source: https://twitter.com/taviso/status/1167311357957435392)
This report has a screenshot of one of the domains:
https://newfoodeconomy.org/grubhub-domain-purchases-thousand...
tl;dr after reading Google's blog post (https://blog.google/technology/safety-security/advanced-prot...):
Google Chrome will now detect, if you have sync turned on, if your account is enrolled in Google's Advanced Protection Program (https://landing.google.com/advancedprotection/), and in case you are, give you stronger protection from malicious downloads.
The ZDNet article adds a lot of fluff around this, and weirdly calls the Advanced Protection Program "Gmail Advanced Protection Program".
This has been reported before, though not for extensions specifically: https://bugs.chromium.org/p/chromium/issues/detail?id=329125
The result back then was that the reported behavior is in accordance with the CSP spec, so the issue was closed.
Maybe Chrome should change their default CSP for extensions that haven't declared one though to disallow blob: URLs.
The parent didn't encourage companies to use any legal means necessary. You can't know their stance about this.
Prediction: In a year, adblocking extensions on Chrome will still block the same percentage of ads from Google's networks as they do on Firefox. Care to make a bet?
Chrome security lead Justin Schuh says he is responsible:
"The sole motivation here is correcting major privacy and security deficiencies in the current system. I know, because I set that focus, and the team reports up through me."
https://twitter.com/justinschuh/status/1134092257190064128?s...
The rule limit will be increased:
"We are planning to raise these values but we won't have updated numbers until we can run performance tests to find a good upper bound that will work across all supported devices."
https://groups.google.com/a/chromium.org/forum/m/#!msg/chrom...
Problem doesn't occur for me. Sounds like a bug
He starts talking about it at 1:04:08: https://www.youtube.com/watch?v=WGchhsKhG-A&t=1h4m8s
The webpage you linked is from last year I think. Article 13 has since been updated
When users try to install a Chrome extension, the browser is telling them what permissions it needs, e.g. the capability to read browsing traffic. So you could just decline the installation and install a different ad blocker that works without that permission.
There's a third possibility: The advertiser guessed the email address.
I think you meant CSP (Content Security Policy), not SCP
The title ("Chrome will stop displaying ads that are repeatedly flagged as disruptive") is wrong in a couple of ways.
According to the post:
"... Chrome will stop showing all ads on sites that repeatedly display these most disruptive ads after they’ve been flagged.
To determine which ads not to show, we’re relying on the Better Ads Standards from the the Coalition for Better Ads, an industry group dedicated to improving the experience of the ads we see on the web. ..."
They are a bit vage in this post, but as we know from other posts and press briefings, this means:
The site owners will get a notice when Google has found that their site is displaying ads not compliant with the Better Ads Standards. When they don't fix this until after 30 days, all ads on the site are blocked, even those complying with the standards. The site owners can then of course still fix it, and get removed from the block list.
So the "flagging" is actually done by Google, and means the owners of the site get a notice.
It's important to note that the "flagging" is not done by users, but by Google themselves. And they do this based on the Better Ads Standards. After the initial flagging, the site owners are notified, and have 30 days to fix it, until the ads on the site are blocked. They then of course can still fix it, and get the ads unblocked.
The "flagging" is done by Google, not users. And according to the post: "Chrome will stop showing all ads on sites that repeatedly display these most disruptive ads after they’ve been flagged."