No credit card required
Browse credit cards from a variety of issuers to see if there's a better card for you.
Be careful when you get some website wanting to add an extension or toolbar to your browser. It may not be as benign as you think
https://tech.yahoo.com/cybersecurity/articles/4-3-million-installed-malicious-142300271.html
"Google removed extensions, Microsoft slower to respond"
Typical. Microsoft products just don't have a good record of security. They tend to be overdesigned. Lately, they've been prioritizing layoffs and "AI" spending. Windows has fallen to a very low priority.
However, with extension takeovers, essentially what will happen is the author of the extension, who has undergone verification, will sell the extension off, and then whoever buys it inherits the entire installed base and can modify the extension and use automatic updates to push out a version that does malicious things. It takes advantage of the time between when that happens and when Google notices and removes that extension.
Once most people install an extension they never think about it again and it's just there, even if they don't use it. The more of them you have the higher the odds that this happens to you at some point, so you should only install extensions that you actually use a lot and which are from trusted people with a long record of providing good software.
Mine are ublock-origin lite for ad blocking (the ManifestV3 version), SponsorBlock for YouTube, Video Download Helper, Capital One Shopping, Web Archives, RECAP (adds federal court records to RECAP so other people can view them without paying PACER after I look at them), MediaPlayer (turns Chrome on my Chromebook into a media player for offline files), and Old Reddit Redirect.
Mozilla used to track who installed extensions. They said the majority don't have any, and out of the people who do, it's usually an ad blocker if they have any at all. The average number of extensions among users who had some was only 3 extensions.
So I doubt most people are in serious risk, but if you just go jamming extensions in and never consider what you need, you might be at higher risk.
Also, most extensions don't run in private browsing mode unless you let them, so save private browsing mode for handling things youu don't want to risk having an extension see. The only extension I let run in private mode is ublock-origin lite.
On my Android phone, I don't use Chrome because that one has never had an ad blocker. I have Fennec F-Droid. Which is a de-blobbed version of Firefox. I also have Privacy Browser from F-Droid, which uses a webview from the system, but turns many "features" like javascript off by default. This has a side effect of busting through many paywalls.
Recently, Mozilla made an update to Firefox that got down into LibreWolf. It crashes on my Chromebook now when I run it in Crostini, but Brave, Vivaldi, and GNOME Web do not crash.
I am eagerly awaiting Google fixing the remaining hangups so that I can upgrade the container to Debian 13 "Trixie" which should bring in a much newer set of graphics drivers, and Vulkan support. Hopefully that fixes a lot of the issues I experience with some accelerated graphics.
Thankfully Steam for ChromeOS runs outside the container.
I've never been very patient with computer software that isn't secure or very stable. Out of all of the software I've used, Microsoft's is always the worst. The people who can't figure out Linux seem to prefer Apple I guess.
I just watched The Silence of the Lambs again, and as Hannibal Lecter put it, simplicity.
"Simplicity. Read Marcus Aurelius. Of each particular thing ask: what is it in itself? What is its nature?"
With malicious software, it's usually not trying to just wreck your computer and make it work poorly. That doesn't gain a financial criminal anything. They want to write malware that you won't notice, while it's stealing all your login data or doing ad reinsertion fraud or changing affiliate links or something.
If they make your computer run badly, you might notice and take action.
Most security mechanisms that protect the OS don't do anything against financial fraud malware, because it's not even trying to manipulate the OS. That's not where the money is. So, increasingly you're seeing things that these layers of security don't do much about even if they are working correctly. And the browser extension takeovers are part of that group.
Interestingly, I had an argument with Alan Pope when he worked for Canonical, AKA Ubuntu Linux, they're the company behind that.
I liked their early work, back when Debian Linux was "raw" and "rough" and even Linus Torvalds himself had trouble installing it properly.
Canonical came and developed an Ubuntu live CD where you could boot off of it, check that everything basically worked, see if you liked it, and if you wanted to commit to installing it, there was a self-help program (wizard) that guided you through it, and other than setting a username and password and your time zone, you could basically smack next a bunch of times and get a working system even if you did not understand what you were doing.
But then they went off the deep end and started wasting literally millions of dollars developing the Unity desktop, which is now abandoned from their perspective (community forked), and I said it wouldn't work out for them and I was right, then they developed a "containerized application format" called Snap, and it competes with the better designed, fully open spec, and more universal Flatpak format.
(Note: Universal containerized apps bring Windows concepts to Linux, and not in a good way. They're extremely bloated because they rely on their own shared objects instead of the system's, and they frequently end up with areas of poor integration and bugs because of sandboxing and being walled off from shared resources.)
For a time, Canonical even themselves engaged in "affiliate hijacking" by changing the monetization referral link in Rhythmbox so it would not generate donations for GNOME (which wrote that program), but rather themselves, when you bought MP3s from 7Digital.
I said on Reddit that with Canonical in charge of a "store" and allowing proprietary software in that they did not build themselves, and had no way of verifying, that it wouldn't be long before "Linux malware" which was never much of a thing, to arrive, and it would happen the same way malicious extensions end up in Chrome. You'd end up with apps that were fake and malicious to begin with, or the person would get something innocuous in, and then slip a bitcoin miner or something into it later (which happened), or people would sell their approved app listing to malicious people and you'd get malware that way (also happened).
Today, I have three laptops. One is a Chromebook Plus, blinged out, lots of RAM and fast CPU, it has Debian in Crostini. I also have a 2020 Lenovo that's running Fedora with KDE, and a 2016 Lenovo that's running KDE NEON. NEON is based on the Ubuntu base system. It has Snap, but no Snaps are installed, and they fixed Firefox so it's actually a Debian package.
The reason "app stores" are actually a sewer and "software repositories" provided by the OS tend not to be, is because much more care and caution go into the "software repositories". Most software is open source, so you couldn't slip malicious programs in easily because everyone would see the code and sound the alarm, or even make a new version without the malicious features and recompile and ship that one, and it's been carefully selected and built by the OS vendor themselves, and the packages are digitally signed, so if a malicious person tampers with a mirror, you get an error from your package manager, not a malicious replacement.
Simplicity.
Of any thing, ask what it is in itself, what is its nature?
Does Google or Microsoft care if your computer gets infected with financial fraud software? Not really. They'll remove it eventually if they become aware of it, but it's not hurting their stock price so they don't truly care.
And in many ways, that sort of heavy handedness that you need to have security on a platform like iPhone makes the User Experience objectively constrained and horrible in different ways. It gives the vendor total control, and they will abuse that by banning entire categories of software they do not want you to have, and use it as a buttress of their monopoly, to extract higher rents and drive prices up.
So the two dominant mobile platforms are both convicted monopolists, one is rent-seeking control freak that demands high prices, and the other is an ad company. This situation is....not ideal for the user.
Despite Apple's touted campaign of "privacy", iPhone apps have almost all the same malicious trackers and adware and spyware that Android apps do. There are certain fences around some of it, but for the most part the bad stuff Android apps can do, so can iPhone apps. And what's worse is a lot of these fences at Apple start reeking of "alert fatigue" like Windows Vista's infamous "Cancel or Allow" pop-ups that Apple themselves made fun of in 2007.
In the open source community, we tend to watch out for each other, so malware and financial fraud doesn't tend to go far in a thing like Debian Linux or most distributions for that matter.
Also, Alan Pope later left Canonical during downsizing. Once he was no longer paid by them he recommended removing Snaps and even wrote a small utility that would uninstall all of them for you.
When I was 14 years old, I started developing privacy software.
I contributed to one of the first real "ad blockers" that set up a local "proxy server" between the browser and the networking stack, and it would simply recognize and strip out requests to ad servers based on blacklisting of domains/subdomains. Back then it worked well enough, today they're trickier.
I also wrote some programs to deal with very early adware on Microsoft Windows, either by removing it entirely or replacing the dll's with dummy stand-ins. The program you were trying to use would load the stand-in and figure the adware was working when it wasn't. That became particularly handy with PKZip for Windows.
But as time went on the bad guys got a lot more sophisticated, and I lost interest trying to solve an unsolveable (on Windows, anyway), problem of an increasing amount of malware.
Yeah I used to install all the browser extensions and toolbars... Got lucky that nothing bad ever happened other than some hijacked search engines and lots of pop ups.
I keep things lean these days - Bitwarden, Proton VPN, SimpleLogin. That's it. Not worth the data exfilatration risks and I use Brave so the built in popup and ad blocker functions are good enough for me.
@crystal626 wrote:Yeah I used to install all the browser extensions and toolbars... Got lucky that nothing bad ever happened other than some hijacked search engines and lots of pop ups.
I keep things lean these days - Bitwarden, Proton VPN, SimpleLogin. That's it. Not worth the data exfilatration risks and I use Brave so the built in popup and ad blocker functions are good enough for me.
The ad blocker functions of ManifestV3 really aren't THAT bad. People shouted that it would be the end of the world, when basically the only major downside is that the user can't load their own lists or write custom rules. The rules have to ship with the extension and the extension has to be upgraded to push new rules.
That means that the rulesets can become outdated, because under the old "subscription" model, you could push a ruleset change and the extension would occasionally look to see if there was a new list.
Google actually had good reasons to change MV3 in general. If they had made an exception and allowed ad blockers to load arbitrary remote resources, anything could. Part of the security problems with extensions have been that you (the browser maker) can audit the extension itself, but if it can load new resources from remote servers, then you can't really tell what they'll do. A compromised remote server or an author that gets an extension approved then uses it to sneak in malicious code just does that, and there was not anything malicious in the code you saw.
In the case of ad blockers, that was reasonably benign but not so with programs that load executable code.
The other problem with MV3 was a limited set of rules. The original limit was too low, ad blockers would have been able to only block "the worst offenders", but Google listened to the feedback and set the limit higher (especially on rules that are simply block or allow) than proposed. Also, the size of the lists was able to shrink a lot because the API itself became case insensitive, which reduced the size of the ruleset by over 20%.
The new API is a lot cleaner. When developers are not resource constrained, they tend to leave a mess because the sky is the limit. When they are constrained, they go back and look at things and figure out how to do more with less.
That said, if you just want to use a ton of dynamic rules in your ad blocker, Chrome isn't the browser for you (and neither is Microsoft Edge, or Webkit browsers that don't even support WebExtensions anymore and have a much more limited ad blocking feature).
I'm a cautiously optimistic person on MV3 because it gets a lot of things right, like eliminating potential race conditions that can deadlock a browser tab and crash it. Most users would like to see less of this.
I put out a proposal to change GNOME's web browser (GNOME Web, codenamed Epiphany) to Apple's Content Blocker format, which is also essentially parsing a JSON file at startup, the rules are pretty much entirely static, which is worse than ManifestV3, but in scope for GNOME Web, it made sense. It used to run on top of MozGTKEmbed and use the Gecko (Firefox, previously Mozilla Application Suite) engine.
It had a badly broken ad blocker that tried to hide undesired elements, but could not block them. It never worked well and in fact worked even worse after the transition to WebkitGTK (a variant of Safari's rendering engine, which Apple in turn took from KDE's KHTML/KJS).
When the old ad blocker code was removed, it not only dropped tens of thousands of lines of code from Epiphany, but it gained the ability to actually block ads, and we observed a drop in RAM consumption along the lines of 25-57 MiB per browser tab.
One of the worst things about web browsers is that users tend to leave a lot of tabs open. Some of the newer ones have logic to suspend unused tabs but we don't have that yet.
Brave's ad blocker is built in Rust. It is open source. It does work well. But the Achilles' Heel is that it relies on private (browser chrome) access to a blocking implementation of WebRequest, which for now is how Google is implementing DeclarativeNetRequest. But in the future, Google could completely drop WebRequest and then the Brave Adblock code would be useless even though they can give it access to private APIs.
I'm a big supporter of ad blocking.
They're not just annoyances, they're spyware that violates the US Constitution.
When the government doesn't want to go to court and convince a judge to sign a search warrant, they can do other things, like go to "cloud" providers and in the case of iPhones, get an entire copy of what's on your phone unless you disabled iCloud Backups, they don't even need to hack your phone. The requests for backdoors are a smoke and mirrors show. For 99.999% of iPhone users, they don't need that.
But Google gets tons of info from Android users too, GMail, GDrive, Cloud Office software, search history, mobile ads.
Then they will get info from any "social media" companies you use.
Then if they still want more, they'll go to ad companies, which know a ton about you if you're not blocking ads/trackers/mobile ads on your phone (I use TrackerControl from F-Droid as a local proxy to block these requests.)
They can go to Microsoft and get your BitLocker drive decryption key, because the default setting in Windows is to give it to Microsoft.
Back when the government wanted to know if people were "compliant" with COVID lockdowns, they just went to the mobile ad companies and the cell phone carriers and asked for user-level data about where people were at and if they were staying in their houses or not.
Believe me, most people who use cell phones have much bigger problems than some criminal network trying to get money.
But for what it's worth, the NSA uses ad blockers internally as a matter of policy. They noted that a lot of malware gets installed by ads somehow, whether it is remote code execution or simply tricking the user.
On Google and Bing, a lot of ads are actually scams and phishing attacks.
Removing ads from your search protects you from clicking on those by accident. It's not just about clutter.
I don't even use Google, I use DuckDuckGo, because Google has been sticking worthless "AI slop" all over the place lately adding even more crap that I don't want to see, which is frequently also incorrect since it just pulls the thing it's telling you off what someone on Reddit said, or other such nonsense.
I think the main danger to humanity isn't that "AI" becomes self-aware or takes jobs, from what I'm seeing the main danger is it will just tell people a lot of things that aren't true and they'll believe it because the program has been mislabeled as some sort of "intelligence" when it is not.
In some cases, it does cause jobs loss, but in many cases, those CEOs that jumped the gun and fired everyone then go back and say on second thought the technology didn't work right and then they had to pull their remaining people away from their job to go babysit what the chatbot is spewing out and stop it from saying things to their customers that are not right.
If you'll forgive some dark humor for a moment. I asked Penny the AI chatbot on Priceline (a derivative of GPT), what I could do for a date night in Skokie, and it suggested going to the Holocaust Museum and then seeing the Leaning Tower of Niles, twice.
Then I asked it what there was to eat next to a hotel, and it said there was a good ramen restaurant next door, then I looked on Google and it didn't exist, and the restaurant was actually an hour away in a different city.
Brave supports MV3 as well as older extensions and I trust that if Google ever shuts down the way they're blocking ads now, they'll work around it. These are the guys that have worked around every block that Google has put in place to block people from viewing YouTube with ads blocked within a day while other solutions scrambled for weeks at a time.
I use Advanced Data Protection so all of my iCloud besides iCloud Mail (don't use it), calendars (meh), and contacts (meh) is fully end to end encrypted.
https://support.apple.com/en-us/102651
I do this in case Apple ever gets breached but it obviously has the benefit of keeping everyone out.
I have FileVault enabled for full-disk encryption across my Mac's internal drive and the two externals, I also use Duplicati to encrypt backups that I send to OneDrive, Proton Drive to store important files (also end-to-end encrypted), and I have a VeraCrypt file that I keep a copy of everything that goes into Proton Drive that is encrypted with three different encryption algorithms (one on top of the other) with a long random encryption key and that file is stored on my Mac as well as my iCloud. I set up the VeraCrypt file today so I deleted everything off my Google Drive for good but I suppose since I have 2TB of Google Drive for a year from getting a Pixel 10 Pro XL I might as well set up another Duplicati backup to that for extra redundancy.
I use Bitwarden and back up my Bitwarden vault and keep a copy that can only be restored to MY Bitwarden account, with my Bitwarden master password, on my machine, and a copy that can be restored to any Bitwarden vault, also using my Bitwarden master password, on Proton Drive and in that VeraCrypt file. My Bitwarden vault is itself locked down with Yubikeys and Authy plus a Passkey in Apple Passwords (set for 2FA only, it won't log in).
I'm all in on the encryption. Even my Parallels linux virtual machines are encrypted at boot. I have nothing to hide from a legal standpoint though, it's to keep hackers out of my crap even if they get ahold of it through breaches.
I use StartPage for searches as often as I can but I find myself using Google a lot because even though StartPage pulls from both Google and Bing, while respecting your privacy by not saving or selling your search history, searching directly with Google gets me better results at times and sometimes having Gemini involved is actually useful.
I never knew anyone actually used Epiphany... I figured it just existed to exist but everyone replaced it.
And yeah, AI hallucinations are something else sometimes.
I'll just touch on ManifestV2 for a moment. Brave probably supports it because the code hasn't been entirely removed from Chromium yet.
Google has plans to let Enterprise users switch a flag and continue using those extensions for a while, but new ones are not being signed by Google and the Extended Support period is only a couple of years.
The writing is on the wall. Mozilla's extensions model for Firefox is basically ManifestV3 with a few MV2 features held over. They've said that those features may or may not continue to be supported in the future.
For now, you can write classic style ad blockers for Firefox browsers, but I've found that uBo-Lite is enough when using the Optimal or Complete setting. Chrome will prompt you to give it more permissions. The only reason to use Optimal instead of Complete is if you're on a slower computer where the Generic Filters in Complete might cause too much resource consumption.
Some of the Annoyances filters you can enable include things like "AI Widgets".
We're deep into things that are not ads, just a time wasting screen-cluttering annoyance there to do something nobody wanted.
@AndrewF wrote:I'll just touch on ManifestV2 for a moment. Brave probably supports it because the code hasn't been entirely removed from Chromium yet.
Google has plans to let Enterprise users switch a flag and continue using those extensions for a while, but new ones are not being signed by Google and the Extended Support period is only a couple of years.
The writing is on the wall. Mozilla's extensions model for Firefox is basically ManifestV3 with a few MV2 features held over. They've said that those features may or may not continue to be supported in the future.
For now, you can write classic style ad blockers for Firefox browsers, but I've found that uBo-Lite is enough when using the Optimal or Complete setting. Chrome will prompt you to give it more permissions. The only reason to use Optimal instead of Complete is if you're on a slower computer where the Generic Filters in Complete might cause too much resource consumption.
Some of the Annoyances filters you can enable include things like "AI Widgets".
We're deep into things that are not ads, just a time wasting screen-cluttering annoyance there to do something nobody wanted.
Brave has decided to continue supporting four V2 extensions themselves - AdGuard, uBlock Origin, uMatrix, and NoScript. Brave plans to continue patching in support for the time being.
"While Brave has no extension store, we have a robust process for customizing (or “patching”) atop the open-source Chromium engine. This will allow us to offer limited MV2 support even after it’s fully removed from the upstream Chromium codebase."
https://brave.com/blog/brave-shields-manifest-v3/
Obviously, if the devs of those extensions decide it's no longer worth the effort to support such a small (comparatively) install base, then Brave will remove the extension rather than leave it, so the end result will probably be the same anyway, it will just take longer to get there.