Stories
Slash Boxes
Comments

SoylentNews is people

posted by chromas on Wednesday January 23 2019, @03:12PM   Printer-friendly
from the bring-back-common-sense-adctl dept.

Google engineers have proposed changes to Chromium which would completely break content-blocking extensions, including various ad blockers, ostensibly for "security" reasons.

Per The Register:

In a note posted Tuesday to the Chromium bug tracker, Raymond Hill, the developer behind uBlock Origin and uMatrix, said the changes contemplated by the Manifest v3 proposal will ruin his ad and content blocking extensions, and take control of content away from users.

Content blockers may be used to block ads, but they have broader applications. They're predicated on the notion that users, rather than anyone else, should be able to control how their browser presents and interacts with remote resources.

Manifest v3 refers to the specification for browser extension manifest files, which enumerate the resources and capabilities available to browser extensions. Google's stated rationale for making the proposed changes is to improve security, privacy and performance, and supposedly to enhance user control.

"Users should have increased control over their extensions," the design document says. "A user should be able to determine what information is available to an extension, and be able to control that privilege."

But one way Google would like to achieve these goals involves replacing the webRequest API with a new one, declarativeNetRequest.

[...] Hill, who said he's waiting for a response from the Google software engineer overseeing this issue, said in an email to The Register: "I understand the point of a declarativeNetRequest API, and I am not against such API. However I don't understand why the blocking ability of the webRequest API – which has existed for over seven years – would be removed (as the design document proposes). I don't see what is to be gained from doing this."

Hill observes that several other capabilities will no longer be available under the new API, including blocking media elements larger than a specified size, disable JavaScript execution by injecting Content-Security-Policy directives, and removing the outgoing Cookie headers.

And he argues that if these changes get implemented, Chromium will no longer serve users.

The Register points out that this will not just affect Google Chrome and Chromium, but also Chromium based web browsers such as Brave Browser and Microsoft Edge.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 0) by Anonymous Coward on Thursday January 24 2019, @08:48AM (1 child)

    by Anonymous Coward on Thursday January 24 2019, @08:48AM (#791142)

    The real problem here is morons use blacklists. How dumb can you be to think you could list all the bad domains online??! There must be millions of bad domains with thousands new springing up every single day. The majority of the internet is evil and there to abuse you, to extract value from your movements and actions. I wouldn't want to administer that mole farm. It's simply impossible. Using a blacklist might give you a warm fuzzy feeling of doing something but all you really got was false feeling of security (and apparently large memory requirement too).

    The only sane way is to use a whitelist. Block everything and the give special privileges to only what you need and want.

    This shit should be built into the browser to begin with, so no extension would be needed. Like somebody said above, you should only need to install some extension to enable them to spy you and get astronomical memory usage...

    Of course, google will never do that because their business model is spying, sadly like most of the web today.

    /rant

  • (Score: 0) by Anonymous Coward on Sunday January 27 2019, @01:43PM

    by Anonymous Coward on Sunday January 27 2019, @01:43PM (#792612)

    Black lists are not moronic. They are an old way to manage a known problem. Same as a standard firewall and domain level filtering.

    True, they are hard to manually maintain. A lot of people don't know to install a filter such as pi-hole.

    Get a grip. We need to help people become technically self sufficient. We all benefit.