Firefox is also the only browser that vets uBlock's code on every update to make sure the developer hasn't inserted spyware or malware into the extension.

They don't do it for every extension, but they do so for a wide selection of popular options.

> Recommended extensions differ from other extensions that are regularly reviewed by Firefox staff in that they are curated extensions that meet the highest standards of security, functionality and user experience. After receiving Recommended status, safety standards are maintained through automated checks, monitoring, and periodic technical reviews

https://support.mozilla.org/en-US/kb/recommended-extensions-...

Complete, authoritative list of Firefox extensions officially recommended by Mozilla.

https://addons.mozilla.org/en-US/firefox/search/?promoted=re...

Some quite informative discussion on Firefox subreddit when I discovered and posted the above list there a few months ago.

https://www.reddit.com/r/firefox/comments/1pyvx2v/complete_a...

The Recommended Extensions program description: https://support.mozilla.org/en-US/kb/recommended-extensions-...

I seem to remember TamperMonkey being on there but not ViolentMonkey, which I didn't agree with. However, I see neither of them on there. Both are available but not recommended. I wonder what is going on with that.

Probably just resources. Mozilla has to vet each update to give them the "recommended" badge and so they probably focus on the most popular extensions

They should have vetted ViolentMonkey instead of TamperMonkey the last time around.

I’m a huge fan of Mozilla and Firefox specifically, but I don’t think that the way classical adblock extensions are made is the right way. Instead, it should be done as Apple/Safari do it [1]: the browser provides an API to hook/set a block list of identifiers that should be blocked, it could be resource hostnames, html signatures, need to think how to improve the API, but this way it’s completely safe, extension has zero access to the actual page content. Apple does the same for caller id apps. Afaik, Android has this API too, but the last time I checked, all relevant extensions were just “give me your whole phone control or web page access”, so Google clearly doesn’t enforce it

Yes, it kinda gives more control to the platform, but so far, iOS extensions that use this API worked surprisingly well for me

Please, correct me if I am wrong and uBclock can already work in this restricted mode

And the last thing, if people really want to give someone a full page content access, they surely should be able to do that, so kudos to Mozilla

[1] https://developer.apple.com/documentation/safariservices/cre...

One of my biggest annoyances about my iPad is how much less effective the content blockers on Safari are than on real Firefox and ublock origin that I have on my Android phone and had on my previous windows tablet. Also iOS “Firefox” can’t run any adblockers, whether ublock origin or iOS content blockers so I have to use Safari and put up without consent-o-matic or tab sync

For example, ublock origin is able to patch out anti-adblock scripts that Safari content blockers cannot. Try tvtropes for an example. Works fine with firefox and ublock origin, displays a “allow ads of subscribe” instead of the content on safari.

Absolutely not. This is exactly why people have a problem with Chromium, which now has some of the same restrictions on extensions as Safari (Manifest V3).

- uBlock Origin works best on Firefox: https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b...

- uBlock Origin Lite FAQ: https://github.com/uBlockOrigin/uBOL-home/wiki/Frequently-as...

You can only get a very limited uBlock Origin facsimile, not the real thing. A lot of browsers have a uBlock Lite. It's missing a lot of useful features IMO.

I think that would limit its capabilities so much that it would be much easier for ad platforms to find ways to circumvent it.

That's pretty cool. Thanks for pointing that out. I don't see where it says 'on every update' unless you're referring to the automated checks?

I've always wished extensions had more granular permissions though (a la phones, but more so). I think automated ai security checks sound promising soon.

Automated checks are done for every extension on every update. But their recommend extensions they feature on the Extension store, they do other extensive checks for each update.

what permissions do you suggest?

I'd like a way to easily specify exactly what sites an extension can run on. There are extensions that I'd like to run on a subset - often just one or two sites - without giving them access do anything else. For that matter, a way to only activate an extension as a one-off when I click it and on no other tabs.

What about container specific permissions? If they implemented that it would be enough for me since I tend to split up my services by type (eg: shopping, banking, work, hack) so enabling an extensive on a specific set of containers would rock. Right now I think the only control we have is over private tabs/windows?

I'm using an extension that does exactly that¹, actually every update of the extension is mostly about then supporting more websites and asking permission to access those.

So maybe more developers could do a all sites and manually select sites option?

¹BPC extension

The extension can declare which websites it can access, but the other commenter was looking for the ability for the user to declare which websites it can access.

> Firefox is also the only browser that vets uBlock's code on every update to make sure the developer hasn't inserted spyware or malware into the extension.

They could save themselves the trouble if Firefox simply baked in its own ad-blocking, but since Google basically owns them, we all know that will never happen.

Ladybird browser is going to be awesome.

Websites already can barely be assed to care about supporting Firefox users, doing adblocking by default is a great way to get websites to start putting up banners that say "our website does not work with your browser, please switch to Chrome" en-masse.

And Mozilla did develop anti-fingerprinting tech, but they can't enable it by default because it breaks lots of websites and when a website doesn't work they're not going to appreciate Mozilla for protecting them, they're going to be pissed that it doesn't work.

Brave has native ad-block and anti finger-printing, enabled by default, and the web works excellently as in I don't know of a single site that doesn't work with it.

Brave is based on Chromium and inherits basically all compability, that this brings.

Firefox with Gecko is a different engine entirely and that sometimes causes compatibility issues or different behaviour, that websites have to account for.

Not saying your wrong, but the number, and type, of sites you browse is going to be a very narrow slice of the sites that all Firefox users browse

> start putting up banners that say "our website does not work with your browser, please switch to Chrome"

That's how IE 6 was killed.

It was killed by a lawsuit, mostly.

Also FE devs using all new Chrome shinny APIs, and their Electron junk are also to blame, and they aren't going to throw their toys away.

If nothing else, I really do hope that the greater AI usage leads to more adoption (and hopefully interest) of native frameworks.

If only, everyone brags about Claude and Fable, yet they can't do anything better than Electron and React for TUIs.

Websites blocking Firefox because of ad blocking has happened before:

https://web.archive.org/web/20070817224229/http://whyfirefox...

> banners that say "our website does not work with your browser, please switch to Chrome"

Which in practice means "switch to using a Firefox extension which fakes looking like Chrome, and just to selected shitty sites like ours".

Which in practice would only be executed by the same crowd of people who would have opted-in to the security features on the first pass.

Which in turn should be built into the browser and done automatically

With a normal Firefox on desktop on Linux, I get unsolvable recaptchas all the time, especially on cloudflare pages.

Ironically, if I fake instead a chromium to be on Windows (UA and Sec-CH headers), I am allowed most of the time even though my TCP fingerprint must mismatch then.

It's annoying to see what the normal web has become. Can't even read news anymore.

Ironically, all these bot defenses make it easier for bots to scrape their website, but make it harder for actual users to use them.

The only bot defense web app firewall that still works with Firefox seems to be Anubis. Pretty much all others autoflag Linux users as bot users, which feels insane if you think about less web developers must know about how botnets work.

> With a normal Firefox on desktop on Linux, I get unsolvable recaptchas all the time, especially on cloudflare pages.

I get this with Chrome on MacOS.

I'm becoming more convinced that Cloudflare is the bane of the internet.

> I get unsolvable recaptchas all the time, especially on cloudflare pages.

If you really mean reCAPTCHA (the one with a “select all squares that have X” kinda challenges), then Cloudflare hasn’t used that for quite a while now. archive.today uses a Cloudflare-looking (old style) page with a reCAPTCHA (and they do serve it quite often), but I don’t think I’ve seen other sites do that.

The level of mental gymnastics in this thread denying the extent to which companies like Google (and their puppets like Mozilla) control the internet is too damn high.

Fortunately if projects like Ladybird gain enough momentum, websites might be forced to cater to it. Time will tell.

You know you can make a browser based on Firefox's core and don't need to make a new one from scratch that'll never get past Cloudflare?

> You know you can make a browser based on Firefox's core

If you want to inherit all of Firefox's flaws, I suppose.

> and don't need to make a new one from scratch that'll never get past Cloudflare?

Considering Cloudflare is a sponsor of Ladybird, something tells me they're going to grant an exception for it.

What flaws exactly?

People on here love to moan about Firefox because Mozilla did one thing at some point in the existence of the company they didn't like. But then just cede the Internet to Google and chromium clones because at some point when they were a crappy junior JS dev, Chrome had some better tooling over Firebug so they just got used to testing in one browser. Maybe they also like to remember how Firefox, a decade ago, couldn't handle 1000 tab sessions.

I hope Firefox keeps up the fight but HN loves to crap all over them for not being perfect.

People complain about Chrome as often as about psychopaths, because it can't be fixed.

Can’t speak for all users, but at least as of about six months ago, there appears to be a bug in Firefox in NixOS where the shader cache doesn’t appear to be able to write properly, and as such video acceleration doesn’t work. It became most evident when I was trying to watch 360-degree videos in Immich.

Entirely possible that this is an issue specific to NixOS or my machine, but because of that issue I switched over to Brave.

I would like to go back to Firefox at some point. Maybe I’ll see if I can make a patch to fix video acceleration on NixOS.

the obvious thing to do is keep using firefox as your daily driver, and load up the other browser as needed for the video etc.

I'm being tongue-in-cheek here because it seems most people just give up on safari/firefox if one thing doesn't work and go to some chromium-based browser as their default driver. That's sad.

I don't understand it. I do keep an ungoogled chromium install around for the few times when I suspect a site is intentionally breaking itself for firefox, and it's not a big deal to open on occasion. Otherwise, if you value customization at all, you have to use firefox.

What you say is what I do, Firefox is open all the time, I switch to brave or edge if ff won't load something. I use adnauseam as adblocker.

I have never had chrome on windows 10 or 11; nor chromium.

For a year chase.com wouldn't allow me to login from Firefox. Dumb.

Did you go to your local Chase branch with Firefox on your phone and pretend you have no idea why it doesn't work?

Thats what I do - that 1 page in 100, if at all, goes to chrome. But basically 100% of pages I ever use work fine.

They will have to pry with significant force firefox with ublock origin from my old dusty finger bones... fuck the rest for selling us all out.

Even if it won't move the needle a bit, I can look at myself in the mirror in this specific regard and be content that I didnt bow my head like bland masses did and didnt work towards massive enshittification of our global society from now on.

Because thats what its all about, nothing less. With our choices, we shape future for our kids and grandkids. Shame on you, all you rich faangs who are directly helping this. Godwin's law is never too far in such cases and history wont be kind to you, no reason to be

Aw man, one issue you don't even know is Firefox's fault?

Sadly Cloudflare's browser detector is the main barrier to using Servo for most websites, so they're not the angel they seem

They literally didn't deny that. They made a separate point you appear not to have actually read.

Regardless, I don't want baked-in Firefox adblocking in part because I don't trust Mozilla with that task either. They'd absolutely end up allowing their own "acceptable" telemetry and ads. Even if they didn't, it would be unlikely to ever be as effective as Ublock Origin. Much like how Chromium browsers' built-in adblocking is barely anything in comparison, even on Manifest V2.

And yet, for now, Firefox and Mozilla is by far the lesser evil. I like a few of the Chromium browsers well enough, but they are ultimately at the mercy of Google.

I hope Ladybird does well, too.

Their separate point was ignored because it was an irrelevant tangent.

> Regardless, I don't want baked-in Firefox adblocking in part because I don't trust Mozilla with that task either.

This is in a thread about how we should be happy that FF is vetting code for us. Do we trust them or don't we?

> And yet, for now, Firefox and Mozilla is by far the lesser evil.

I'm instinctively tempted to agree, but the difference is so negligible at this point that the only sign I would is the fact I'm still using FF due to momentum (as well as Ladybird not being ready from prime time yet).

FF/Mozilla has proven itself to be controlled opposition, so I'm not very interested in games of "lesser-of-two-evils" abuser logic that has infected politics and many other spheres in a race to the bottom.

> Do we trust them or don't we?

GP trusts them for reviewing external extension code, and ensure that it does not contain malware, but not for not inserting exception to their own telemetry if they wrote the code themselves.

Or, more likely, they feel that having two independent actors collaborating on the extension (one by writing and the other by reviewing) yields a more trustworthy outcome than either actor on their own.

That was a rhetorical question.

Mozilla have given us plenty of reasons to not trust them, which makes it hilarious that anybody would think it's noteworthy they're reviewing the code of Raymond Hill of all people.

We could tell it was rhetorical, to imply the position was ridiculous. But when accepting nuance there is a real answer.

> Raymond Hill of all people.

As good as he's been, he's still just one person with a hobby project. Yes please review it!

And what if he gets hacked?

>> Regardless, I don't want baked-in Firefox adblocking in part because I don't trust Mozilla with that task either.

> This is in a thread about how we should be happy that FF is vetting code for us. Do we trust them or don't we?

Are you joking? You brought the claim to the table, and now that people see the flaws in it you deny them talking about it? You're some mental gymnast..

That's like suggesting that someone using LLMs to assist coding, could save themselves the trouble by writing the code by hand.

Yes, Firefox could do everything, but then it'd turn back into Mozilla. The whole point of the extensions framework is to allow modular extensibility. And it's much easier to vet for malware than to code afresh and maintain.

What stuns me is that most people still use browsers that cannot block ads, seem genuinely annoyed by ads, but don't want to even try switching to a browser that will easily block those ads. It's amazing how much crap people are willing to wade through when the alternative is trying something new.

> That's like suggesting that someone using LLMs to assist coding, could save themselves the trouble by writing the code by hand.

No it's not.

> Yes, Firefox could do everything, but then it'd turn back into Mozilla. The whole point of the extensions framework is to allow modular extensibility. And it's much easier to vet for malware than to code afresh and maintain.

No, quite the opposite. FF has a history of adopting extensions as baked-in functionality if they prove useful/popular enough. There are tons of examples of this from the past for various features, which is great.

But that fact makes it even more absurd that they refuse to do the same for what is likely their most popular extension of all time: uBlock Origin

Waterfox, a Firefox fork, has actually built a builtin qdblocker. (And yes, they do whitelist their search partner by default, but you can turn that off.) Apparently it’s faster than uBlock Origin, but there’s been problems on some websites, so I’ll be sticking with uBO for now.

Edit: actually, it seems the underlying functionality was built by Mozilla themselves, just not exposed in the UI yet: https://news.ycombinator.com/item?id=49309020

Not "everything", just a few common things that almost every user wants.

> Yes, Firefox could do everything, but then it'd turn back into Mozilla.

It's been 20+ years, nobody cares about that anymore.

Admiral and several other of the more obnoxious ad networks already claim that Firefox is an ad blocker simply because of its out-of-the-box blocking support for third-party cookies and those ad networks nag you to use another browser. If Firefox added actual ad blocking out of the box I can't imagine the havoc that would cause and how many more websites would claim that they don't work at all in Firefox.

A sharp point in this context because yet again, Mozilla faces contradictory demands in every direction. In today's edition, they are failing their users by not hard coding the ablocking in but also they need to give up on ad blocking because if they try they'll simply be blacklisted.

"Do X." versus "Don't do X." is a set of demands faced by most programs.

Firefox started shipping adblock-rust in March (Brave's built in adblocker). It's not properly wired up in the UI yet but you can enable it and add filter lists in about:config.

>since Google basically owns them

Google has been trying to kill them since they moved the Chrome team into the same building as the now defunct SF office.

(Apparently they offered people a lot of money? There are some words I could use to describe people who do things they think are unethical for cash I'll leave unsaid.)

People believe ublock because it's reputable and not affiliated with browsers IMO.

If Firefox baked in ad blocking, they would have to then deal with the financial incentive to make it worse. Sponsored ads, 'good' ads, government announcements, election propaganda... there is a slippery slope they are better off not getting on. A trusted 3rd party from the wider community seems a better option in many ways. The alternative is starting a web browser with a manifesto welded on that essentially states 'death to all advertising', and until that can be crowd funded I can't see that happening in today's world.

What I am surprised about is that none of the browsers or forks have created a specialist plugin API for adblocking and maybe other filtering. Provide what is needed and only that (keeping the surface tiny), and then evolve the general purpose API in the way they need. I don't think we need V2 of the API any more, except for keeping this one absolutely critical plugin working, do we?

Firefox has baked in adblocking (using adblock-rust, brave's built in adblocker), but it has to be enabled through about:config and not the settings UI.

In one of the monthly update videos Andreas mentioned that although they are working on a basic built-in adblocker for Ladybird, long-term they want extension support and the adblocking functionality to be in an extension.

Why does ad blocking always have to be relegated to an extension? Browsers build in so many things. Why do they all draw the line at a feature like ad blocking that every user wants?

Because they want a level of plausible deniability.

The way uBO works already provides a layer of plausible deniability. It's just a content blocker that loads filter lists maintained by other people.

See, this is the kind of thing that makes Firefox cool. They have not only just as good of developer console tools as Chrome, they have forward thinking, truly user-oriented policies. They have had trouble in the recent past at securing funding, but something tells me their user philosophy might save them when all the others turn completely to corporate greed as their main operating mechanism (if they already haven't).

Your reply makes no sense. To the original point, if they had user-oriented policies, they'd have ad-blocking baked in by now. But they don't, and likely never will.

> Your reply makes no sense. To the original point, if they had user-oriented policies, they'd have ad-blocking baked in by now.

It's not black and white, and your inability to see the larger context is disturbing.

You could, by the same logic, criticize Mozilla for not serving you coffee which is certainly a "user-oriented policy" "baked-in" or rather "brewed-in". But we must be realistic about how far UOPs can be stretched, Mozilla is better than the rest, which includes large corps with far more money than them. If you can do better than Mozilla, I'm all ears.

Next, an ad-blocker needs continuous maintenance - someone started a good one long time ago and apparently loves to improve it and maintain the various lists it uses - why should Mozilla strain to compete with one of their best contributors? - that would be both rude and dumb, and they'd be wasting resources too. There's absolutely no upside to your proposition but you keep insisting.

> Next, an ad-blocker needs continuous maintenance - someone started a good one long time ago and apparently loves to improve it and maintain the various lists it uses - why should Mozilla strain to compete with one of their best contributors? - that would be both rude and dumb, and they'd be wasting resources too. There's absolutely no upside to your proposition but you keep insisting.

One would hope that's one of the more useful things an LLM could assist with if not now, very soon. In the meantime, there's no reason they couldn't have uBlock kept as an extension but bundled by default like they've done with other functionality over the years. Wait, never mind. There's one rea$on why they wouldn't, and it's already been $tated.

You're absolutely right.

[flagged]

"RIP Charlie Kirk

I hope many more debate nerds carry on his quest to engage young people with words, not fists."

If this statement - a urge to engage in peaceful debate, not violence - makes you hate him, then I see the problem rather with you. I mean seriously, do you like civil war? Because this is what happens when people don't talk anymore about their disagreements, but physically fight.

https://www.youtube.com/watch?v=AkKo1_RP_0c

Mildly funny, but not sure what your point is here?

I didn't know who Charlie Kirk was, and no facts about DHH other than him being Rails creator.

"will never be awesome" is missing some quantifier about US-centricity.

> US-centricity

Andreas Kling is Swedish, DHH is Danish, fascism originated in Europe.

Italian fascism originated in Italy, but if you broaden the definition of "fascism" to include Nazism (as Adolf Hitler did), then there's an argument that it originated in the 19th century, in many parts of the world, including the United States. Among others, Adolf Hitler took inspiration from Madison Grant, Henry Ford, and the Jim Crow laws; and the Nazi regime took inspiration from Harry Laughlin, the KKK, and American eugenics. (WWII might be a bigger contributor to eugenics going out of fashion in the US than its lack of scientific merit was.)

Yikes, that is a twist I was not aware of.

I don't see how someones personal politics could dictate the "awesomeness" of there software.

Considering enough developer on this very site "stan" Charlie Kirks assassin and other people that are violent towards anybody less left wing than them: "your boos mean nothing, i have seen for what you cheer"

Exactly, the German autobahn is also awesome. /s

After watching them butcher their own side tabs implementation, I don't know if we really want that, unless they're actually hiring the uBO team directly.

Also for youtube download plug-ins. yt-dpl does not work for youtube anymore.

Still works for me. The occasional 403 has always been an issue

I recommend two more:

1. pass paywalls clean.

2. Social Fixer

Rather than introducing additional attack surface and privacy risks with yet another extension you can just use archive.is/archive.ph instead of Bypass Paywalls Clean.

Or, just pay for journalism since it’s not free to do.

You mean Bypass Paywalls Clean? It's illegal and it's not even on the Firefox extension store. You have to download it from some Russian Github alternative and manually install it.

I will say however, it works remarkably well. I haven't seen a paywall in years!

Why should it be illegal?

I don't think it should but it was taken down from Firefox's store because of a DMCA copyright takedown. Firefox was required by law to remove it. Using the extension itself is a legal grey area, but distributing it is usually illegal.

> because of a DMCA

That law doesn't apply to many HN readers

It’s not illegal. But it’s a step too far for some.

It's not. Op is wrong

It's been taken down by DMCA copyright strikes on every western platform that could distribute it. That's why you can't find it on the Firefox extension store anymore

[flagged]

I don't like telemetry being defaulted to opt-in but relax. It's anonymized and it's far and away the least intrusive of the major browsers

It's not anonymized, because your communication with Mozilla has plenty of identifying information.

Also, Mozilla officially un-committed to not using sell this and any other data it collects from you:

https://arstechnica.com/tech-policy/2025/02/firefox-deletes-...

That article is well over a year old. The current privacy FAQ right now explicitly states:

> We never sell your personal data. Unlike other big tech companies that collect and profit off your personal information, we’re built with privacy as the default. We don’t know your age, gender, precise location, or other information Big Tech collects and profits from.

https://www.mozilla.org/en-US/privacy/faq/