Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In case anyone here missed it, there's a native Ublock Origin for Safari. It works great → https://apps.apple.com/us/app/ublock-origin-lite/id674534269...


Mostly so, it's got all the limitations of Manifest V3 which prevents it from doing a good bit of blocking, https://ublockorigin.com/#manifest-v3-section

In particular:

* Cannot use all filter lists simultaneously (rule limits apply)

* No cosmetic filtering in the default mode

* No scriptlet injection by default

* Limited dynamic filtering capabilities

* Requires broader host permissions upfront

But it's definitely still better than no adblockers


> it's got all the limitations of Manifest V3 which prevents it from doing a good bit of blocking

The only mainstream browser left that can still run the full version of uBlock Origin is Firefox.

All the others have the same limitations imposed by Manifest V3.


Firefox has also adopted and supports Manifest v3, but Mozilla did not adopt all of Chrome/Chromium’s Manifest v3 restrictions.

In Chrome/Chromium, Manifest v3 largely replaces extension-controlled network blocking with a more restrictive «declarativeNetRequest», whereas Firefox, by contrast, has deliberately kept support for blocking «webRequest» functionality.

Importantly, the full uBlock Origin is a Manifest V2 extension. The Manifest v3-compatible version is uBlock Origin Lite, which has fewer capabilities.


Brave said they will be keeping its functionality.


Brave has certainly said a lot of good things while doing quite [0] a lot [1] of bad [2] things [3] that make me think it's mostly just marketing to lower-knowledge users that's carrying it forward. I see so many 'privacy' influencers that recommend it and Chromium, and then Firefox with no mention of FOSS options like LibreWolf, Tor Browser, IronFox, etc

[0] https://github.com/brave/brave-browser/issues/15790

[1] https://www.zdnet.com/article/privacy-browser-brave-busted-f...

[2] https://www.xda-developers.com/brave-browser-installs-vpn-wi...

[3] https://www.atlas.science/news/the-shady-world-of-brave-sell...


Yep, I don't trust Brave. A web browser holds so much power over your digital life that it cannot be entrusted to a company that consistently and egregiously compromises its ethics for profit. Most of these examples border on scam behaviour... par for the course for the cryptocurrency space!

For all their faults, Mozilla has never done anything that holds a candle to the kinds of stunts Brave keeps pulling.


Which is even more noteworthy because Brave is led by an ex-CEO and influential top exec of Mozilla's.

I wonder if he'd have done the same at Mozilla.


He was kicked out of Mozilla for being homophobic. No joke.


more specifically, it was for donating to homophobic political groups trying to pass Prop 8 which made gay marriage illegal in California [0]

the measure passed by 5% [1] - people were fairly incensed that Mozilla Foundation money (paid to him via his salary) might go to future donations of the same kind

I'm sure people will say things about 'well of course he's legally free to do as he wants with this money' but then so too is the desire by employees to not want to be working under someone who has done something ideologically abhorrent to them. and given the multiple controversies that crop up about Brave seemingly every year where they push some combination of crypto, browser AI, etc, it's probably for the best

[0] https://www.inc.com/jeremy-quittner/mozilla-ceo-brandon-eich...

[1] https://en.wikipedia.org/wiki/2008_California_Proposition_8


And yet the democratic process was subverted by the measure being overruled. Moot point.


The judicial branch is part of the US democracy, this was not subversion of the democratic process.

Judges are elected/nominated depending the jurisdiction and in this case the decison of a District judge (nominated by George W Bush, through indirect democracy) stands: that proposition is unconstitutional, and the people who tried to appeal that decision in upper courts had no standing to do it (they suffered no personal and concrete injury from this decison).


That's actually incorrect. Democracy doesn't mean allowing mob rule (or manufactured "consent") to trample fundamental human rights.


would love to live in a society where past harms and mistakes could simply be forgotten because the law has moved forward. I imagine a lot of low-level drug possession charges would be forgiven under that ethical conceit

but since we're a long ways from that reality, the least we can do is to look for accountability from influential people with the same strictness we have for the poorest and least powerful


Well no he quit after a few days. He wasn't fired.

That said I do think the uproar was mostly justified. Mozilla is a very progressive organisation and the foundation is basically an NGO. The CEO should fully stand behind its values. At many companies these things aren't core values but at Mozilla they are.

They're not just an employee, they're a figurehead. It's part of the job. Nobody complains if an individual contributor is doing something like this.

And really, if a CEO at a conservative company or foundation would go and join the pride parade I'm sure they would find themselves in trouble too.


Wrong and defamatory. Ouch for your wallet.


All valid.

I'm a Firefox user.

Depending on money from Google is worse than the aggregate of Brave behavior, for me.


Brave also has native rust based psudo reimplementation of ublock, so it also doesnt necessarily need the functionality to accomplish what most people end up needing it for.


Brave and Vivaldi built their own blockers, they aren’t addons.


iOS Firefox the same though.


Thanks Apple for inflicting the Safari monopoly to all iOS users.


Let’s be real, this is more of an anti-monopoly


i only wish updates weren't tied to OS version


I agree with this, but on macos they are not entirely tired. On iOS because of the way iOS gets performance (as far as I understand it to be the case) through the iOS shared cache, there really isn't a way to totally decouple safari from iOS.

I guess you could allow an alternate newer safari, but the one that comes with the OS would have to be linked into the blob.


If they can do it on the desktop, Apple can do it on mobile as well.


No, the two are not architected the same. I believe it’s shipped as a dylib on macOS.


It is not


It's a really huge deferent from chromium reaching 90%+ browser share. So yes, it is in fact an anti-monopoly browser. iOS isn't even at majority market share in most places in the world.


It is not, because a random user is not able to use it. A thing only affects a monopoly when it is a choice a consumer can make.

You could say that iphone is an anti-monopoly option vs android, but not that Safari is an anti-monopoly option vs Chrome.

Then on top of that, even for users that do happen to "live in Canada"(1) already, Safari isn't a choice, it's the only allowed option, and full octane firefox is also not available as a choice. (firfox as a front-end to safari is essentially meaningless)

(1) saying "you can use Safari, because you can switch to iphone" is the same as saying you can have something, just move to Canada", ie, invalid and likely disingenuous, because likely the speaker understood that perfectly well.

So, yeah "let's be real" indeed. There is no way to paint Safari as any sort of anti-monopoly.


This user choice argument isn’t what makes safari monopolist. It’s that for some countries iOS has majority share these days, and safari is pushed on users through it.

That’s why I was kinda trying to say it is anti-monopoly monopoly.

If Apple supported read+execute pages for third party applications, it might give users more choice but it would also have the consequence of ushering in the way for total browser domination by chromium. I’d argue that is an even worse scenario as far as monopoly is concerned.


That is a not entirely bs angle.


I’m weighing two bad outcomes here. I think it’s a lot worse if there’s only one browser for the entire web than it is for there to be one browser for one singular platform.


Cosmetic filtering and script injection both work fine, they’re just off by default. Everybody works around rule count limits by making the one app register itself as like six different “Safari extensions”, it’s just clutter not a limitation. It requires no permissions up front and later permissions only granularly and rarely, for me only on YouTube, while the Firefox version does require unrestricted access to all domains. I have never seen a “dynamic filtering capability” it lacks or an ad it can’t block, do you have any examples?


yea but also idk if its OT but i pay for apple news premium and its just all ads in safari. like whats the point, like its cheaper to bundle and share with my family. but why am i see ads withing News app when i pay this should be a given.


You're seeing ads while paying because you're paying. If you stop paying you won't see ads while paying anymore. Why would you reward such behavior?


That's one way to look at it, but in theory, you're paying to access news stories that otherwise would not be available. I've never seen a feature of paying for the "plus" to be ad free. That's like suggesting paying for a subscription to a newspaper or magazine would be ad free when paying for it just gave you the access to it. This is how it has always been, so expecting the leopard to change its spots is kind of silly


It's not silly. If you're satisfied with seeing ads in a paid product then that's fine, but the other person clearly is not. Cancelling a service because it doesn't meet your expectations is perfectly reasonable. It doesn't matter how "it's always been".


What I like about uBO Lite in Safari is that I can use it without allowing it access to any of my data (it works in a purely declarative mode if you want). Even if it’s unlikely that uBO would be sold to a sketchy company, at least this provides protection against any supply chain attacks.


Yes, that was Google’s justification for killing MV2. It isn’t wrong, of course, but I insist on defining my own security posture and I prioritize adblocking.


Regarding the cosmetic filtering and scriptlet injection, are these even relevant? Most uBO users already give full access to the extension, so they'll probably do the same to uBOL to (most permissions + complete filtering mode). So basically they will have these features anyway.


Cosmetic-based filters and scriptlet injection-based filters work by default, they are enforced in _Optimal_ and _complete_ filtering modes. The default filtering mode is _optimal_.


You can have virtually unlimited amount of rules, its just a limit per list, the number of lists aint really limited.


FYI uBlock Origin Lite on iOS is inferior to AdGuard and (I think) Wipr as it's just a WebExtension, so it'll only block ads within Safari itself.

AdGuard and Wipr use both the Web Extension and Content Blocker APIs, so they'll block ads in all web views system wide on top of within Safari itself.

However as far as trustworthiness goes, uBlock is (imo) #1.


wBlock by an MIT student is open source and seems (just!) about as trustworthy as uBlock, though of course without the track record. Light & fast, especially to update.

  “wBlock runs entirely within Safari's content blocking API. There's no data collection, no tracking, and no system-level extensions that can monitor your browsing.“
https://apps.apple.com/us/app/wblock/id6746388723 / GH: https://github.com/0xCUB3/wBlock

On AdGuard: can act as your PiHole and allow you to see network requests when run in non-native mode.


Just a comment on the narrative:

> wBlock by an MIT student is open source

It's funny to me that some find that narrative appealing.

Here's another narrative: Many of those MIT students go on to be SV founders and employees who build, operate, and make millions or billions from the mass surveillance and ad industry. And I'm sure some participated in FOSS in college - what better way to build your resume for the surveillance/ad industry?

(I'm not commenting on the wBlock developer; I think all such narratives are deceiving and should be ignored.)


The "narrative" above is that they're both made by seemingly well-intentioned solo developers, that's it. Use your own judgement for something that wants to inject JS into every website you visit.


> The "narrative" above is that they're both made by seemingly well-intentioned solo developers

Our comments don't disagree (though I was only responding to the comment parent to mine). My point is to question how 'MIT student' is a signal for 'well-intentioned'.


No offense to the author, but I don't trust a college kid the same way I trust the team behind uBlock. The latter have a well-established track record with substantial external eyes (including Firefox directly.)


Age of author shouldn’t be of relevance. Experience and/or team size should.

A kid reading up on security from age 6 through college could have a decade of experience, for example.


I'm not sure whether this comment is serious or not. Poe's law strikes again.


Nice, last time I heard about wblock felt like years ago and I'm not sure why I didn't consider it.

These days I don't run on-device adblock, I just do DNS filtering for the most part but I'll check it out, not sure I wanna keep tunneling all my DNS queries to ControlD perpetually lol


Thanks for the link, I like it so far


Never heard of this but looks good to me. Nice to have another tool for the arsenal.


I think Wipr is also very trustworthy. It’s developed by an indie dev who’s responsive over email, and gives you a lot for free. And it has a $5/yr subscription (or one time payment) that unlocks system-wide ad blocking, not just in web views.

I’ve found it to work exceptionally well after trying other free adblockers.


Yeah my comment wasn't me trying to say they weren't trustworthy, I've actually purchased both AdGuard and Wipr but I stick with AdGuard since I felt like it was better. And the dev of Wipr seems to be transparent for sure.

However of the three I trust AdGuard the least, for no objective reasons.


uBOL bug report: https://github.com/uBlockOrigin/uBOL-home/issues/438 , from discussion https://github.com/uBlockOrigin/uBOL-home/discussions/408#di...

    uBOL doesn't work in apps, it works only in Safari, it's a pure browser extension, the "app" part of uBOL is an Apple requirement just for the sake of installing the extension.

    Copied from #408:

    uBOL will stay a webextensions-based browser extension, I do not plan to go further than this, I do not have the time and motivation to take on more work than I already do.
    What people may ask though is that Apple maybe supports webextensions in WebApp, if that is possible at all.
I hope this changes, it’s what keeps me on AdGuard :-/


I have been happy with my workaround for this issue which is using uBOL along side the AdGuard content blocker extensions (main AdGuard web extension disabled).


FWIW AdGuard dev team is in Russia. Letting them proxy all your traffic is probably not the wisest move.


If you use the Safari adblocker, it will use rule lists, not proxy all traffic.

That said, IMO on Safari Wipr all the way (though I use Brave Origin with its built-in blocker now, which is stellar).


I think they relocated but yes that’s partially why I don’t use it anymore.


Also, if you use Orion Browser, they did implement the full Manifest v2 extension spec on top of WebKit, which lets you use full uBlock origin directly.


Does that really matter if virtually no one is going to develop extensions according to the Manifest v2 spec?

Developing for that spec means your extension is incompatible with idk, 98% of the browser market?


Well, uBlock will maintain support, and Orion also supports Manifest v3


This is why I started using the Orion browser. It's not perfect, I've had a few freezes and occasional weird behavior but well within the "tolerable" range for me, and not noticably worse than the glitches that any ad blocker causes on some sites.


I try Orion periodically but always find it to be buggy


We'd love to hear from you about specific bugs.


This is not a true uBlock Origin. It's a best effort attempt at converting UBO rules to Apple's declarative blocking framework, but is nowhere near as capable as actual UBO.


> It's a best effort attempt at converting UBO rules to Apple's declarative blocking framework

uBlock Origin Lite uses the cross-platform DeclarativeNetRequest extension API: https://developer.mozilla.org/docs/Mozilla/Add-ons/WebExtens...

Google invented this API for Chrome, and the other web browsers are adopting it. uBlock Origin Lite does not use Apple's content blocker API.


Works well enough for me



Does it work on YouTube?


Yes, in practice I have noticed no difference between uBO and uBOL. The only thing I've seen it not block are Twtich ads which the normal uBO doesn't block anyway.

There are probably additional things behind the scenes just due to the limitations of uBOL but you again in practice don't see it.


Twitch ads are a nuisance. If you have a VPN switching to Romania or other eastern european countries can work.


I agree. I only really watch one or two streamers though both who I’m subscribed to so whatever. It is painful if I check into a random stream though lol


I had missed that! Thanks a lot, saved me a lot of annoyance on my phone.


Is this new? I thought adguard was the only option




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: