Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"""In our tests, uBlock is unable to block the port scans in the new Microsoft Edge or Google Chrome as the extension does not have adequate permissions to uncloak the DNS CNAME records."""

Seems highly relevant...



I remember when Chrome started making these permission changes and claimed that it wouldn't affect things like ublock, despite the ublock authors saying otherwise. Google is going out of its way to use the power it has as the dominant web browser to weaken ad blocking, and anyone who cares about a free web should run screaming away from Chrome based browsers.


Chromium did not remove the dns API as a result of manifest v3[1], it was never supported in the first place[2].

* * *

[1] https://developer.chrome.com/extensions/migrating_to_manifes...

[2] https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web...


Google's new permissions model and APIs are actually great for weakening the power and abuse potential of extensions. Honestly, the vast majority of them aren't very trustworthy. I've seen extensions from banks that simply take over the entire browser for "fraud prevention" or some other nonsense. The new declarative APIs are great because extensions don't actually get access to user data.

Blockers just happen to be so important and trusted that they shouldn't be subjected to these reasonable limitations. Extensions like uBlock Origin and Privacy Badger are so special and important that they should probably be fully integrated into the browser itself instead of being optional.


Exactly. Ublock and privacy badger is trying to make the browser a user agent again.


Exactly. These extensions empower the user to such an extent they should just become part of the browser instead. Browsers that lack these features could hardly be classified as user agents. They're more like generic clients for corporate websites.

Browsers are supposed to act on our behalf by showing us the information we want to see. They aren't supposed to show us advertising noise for someone else's benefit, much less allow websites to track our every move. All such attempts should be resisted.


Ublock should just release a browser and be done with it


Don't worry, in 15 years they will use all the money they gained doing this, and start acting well again. Better even.

And everybody will forgive, and people will defend them on HN for being redeemed, and they will be alright.

That's been the trend.


Microsoft only seem to be acting well again because they're in the company of entities acting worse.

Google will have to be specifically not leading the charge, which may well be the case in 15 years. Google will be hiding behind a shield of some other companies worse behaviour in order to seem to be behaving well.

Windows is still going backwards in terms of hostility to users.


Truly, I don't know how one can look at Windows 10 and think Microsoft has in any way improved: the entire OS spies on you at every corner now, bloatware automatically installs in the background, updates are installed without your consent, and more.


> Windows is still going backwards in terms of hostility to users.

Do you mean that Windows is becoming more user-hostile, or less?


Hahaha, yes, my wording is ambiguous, but you can probably gather from the tone and content of the first sentence that I mean it's becoming more user-hostile.


All the more reason to stay with Firefox.


One problem I seem to be having with FF (on Win 10 anyway) is it's not checking my hosts file for a domain lookup before using dns. Overriding the hosts file makes some things easier so I tend to do it. But now, my first time trying from Win, and it's not getting my page. Chrome works, ssh from WSL works, but FF uses dns first, apparently.

It's the first development usage I've found that Chrome works better than FF.


Yeah I had that problem too after they shipped encrypted dns. You can turn that off and it'll work normally.


OK thank you!


If you want to use DNS-over-HTTPS, you can add domain names to "network.trr.excluded-domains" in "about:config" (if, for example, you always use the .dev TLD for custom hostnames in your hosts file, you can simply exclude that domain name).

If not, well, just disable DNS-over-HTTPS entirely.

See https://wiki.mozilla.org/Trusted_Recursive_Resolver for even more DoH-related settings you can tweak.


Thank you- that's very helpful!


Well, that just means Firefox is winning this war by, what, 79–1 rather than 80-0


Agree.


Are you using (or have been subjected to) Firefox enabling DNS over http? IIRC it's auto enabled for users in the US.


And/or NextDNS.io - Uncloaking cloaked domains is primary what brought me to the service. Added benefits include service across all browsers, all devices, local/mobile etc.


But that is just swapping one privacy issue with another, as NextDNS is also free to sell user’s private metadata to data brokers.

https://news.ycombinator.com/item?id=23318830


Or Chromium variants, if security is important to you.


See: per site isolation, Firefox X11 exploit, etc


Interesting. Anybody knows if these changes to the blocking API affect brave? I think I remember they said they wouldn't include them, but I don't really trust them.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: