Big win for Firefox.
Not really. UBlock Origin Lite works really well. They even added content scripts recently. From a technical perspective MV3 offers more security by default.
The following filter options can’t be translated into DNR rules:
strict1p, strict3p: whether a network request is same-origin as its initiator Entity-based values for domain= filter option (webextensions #394) redirect-rule=: the DNR API does not support redirect-if-blocked concept (webextensions #493) Click-to-load embedded contexts through redirect=click2load.html filter option Regex-based removeparam= modifier filter options Exceptions for all modifier filter options are not possible Workarounds exist for removeparam= and csp= by carefully tuning the priority property. Many very useful regex-based filters used in uBO are not allowed, or are rejected by the DNR API (webextensions #344) replace=, can't modify the response body (full support is only possible with Firefox MV2) ipaddress=, can't use IP address as a condition to block/unblock (full support is only possible with Firefox MV2) urlskip=, this requires programmatic steps to extract a URL from another URL (partial support, for strict-blocked pages only)aside from that it is somewhat better than default ublock but that’s a pretty big list of issues.
There’s also pretty restrictive length limits on filter lists iirc, so ubo lite would have to select top filters at some point. This getting worse as websites add more ads or obfuscate more requiring more rules.
Like FB putting every character in every [w][o][r][d] on the site into a unique code block
Some of those limitations were never supported in Chrome to begin with. MV3 still supports webRequestBlocking at the engine level but it is gated behind enterprise policy (ExtensionInstallForcelist in the Windows Registry, macOS MDM, or Linux managed policy JSON). If an extension with webRequestBlocking is installed via policy, it restores programmatic interception.
Not all users are able to do that, as not all users are (or have to be) that tech savvy. That’s an exclusionary barrier towards inclusion and accesibility of security and sovereignity features.
In practice, I found it breaks sites more, lets some things through, triggers more adblock detectors, and doesn’t work as well with the annoyance list.
It doesn’t work on YouTube. And the maximum number of entries to block is limited.
Its not catastrophic though.
So UBO Lite is not wholly ineffective, no. It works great, mostly. Buts its definitely more of a nuisance to use, which is exactly what Google wants.
No, they’re intrinsically less secure.
They generate memory issues (
use-after-free, dangling pointers,double free(), zombie processes, uncomplete teardown, GC failures or abrupt stops, race conditions, etc.) because of their shitty isolation, and their poor service-workers and IPC architecture.What’s worse, they greatly limit the network APIs needed to active defense (DNR instead of
webRequest).No, they’re intrinsically less secure.
GrapheneOS disagrees with you:
https://grapheneos.org/usage#web-browsing
I agree however that Chromium has some issues still. I have personally managed to crash my browser when calling the Mojo APIs via JavaScript. However, it wasn’t related to security. As GrapheneOS notes, no other browser engine provides the same levels of sandboxing. Recognizing the effectiveness of Chrome’s sandbox, Microsoft began evolving Windows kernel access control to formalize and harden these techniques at the OS level. The upcoming Windows Updates implements this in its new ProcessContainer support.
Blaming process isolation and IPC for memory bugs like Use-After-Free and dangling pointers fundamentally confuses language-level C++ problems with OS containment architecture. Memory corruption exists across all C++ engines (Gecko, WebKit, Blink); isolation is what prevents those bugs from compromising the host OS.
Handing third-party extensions blanket permissions to inspect and modify live plaintext traffic across all tabs creates a massive MITM exfiltration surface. Moving rule matching to declarativeNetRequest enforces least privilege by executing filters in the native engine without exposing sensitive network payloads to extension code.
webRequestBlocking is not deleted in MV3. The synchronous blocking engine still exists in Chromium. If an extension is installed via local policy or the Windows Registry (ExtensionInstallForcelist), full programmatic webRequestBlocking executes in Manifest V3 just as it did in MV2.
Blaming process isolation and IPC for memory bugs like Use-After-Free and dangling pointers fundamentally confuses language-level C++ problems with OS containment architecture. Memory corruption exists across all C++ engines (Gecko, WebKit, Blink); isolation is what prevents those bugs from compromising the host OS.
Yeah, but they instead greatly compromise the browser, and the problem is that these are not as likely to happen in MV2 (i.e., Firefox).
Why? Simple:
- You have a long operation running inside an extension.
- Your system (or the browser itselfs) suspends or even kills the associated Service Worker.
- A new one has to be created.
- If the previous memory chunk goes unreferenced, then you have a double free and/or an UAF.
- If the previous memory chunk doesn’t get unreferenced, then you get a dangling pointer.
- Either way you get a race condition if it’s something concurrent.
The problem is, if an attacker and/or a malicious process do compromise that unreferenced or unallocated memory, then any and all sandboxing will be esentially irrelevant and thus vulnerated, vulnerating not only the browser (something that itself can compromise sensible information), but even the OS.
Then you have the zombie processes because the current memory model in V8 causes SWs to forcedly stop before they can do any cleanup.
MV3 is not about security at all, is about more control over your own computer and about more control over the network (that way they can let more trackers, zero-days, ads, malvertisers and even malware to pass because browser-level blockers and firewalls won’t be able to block them).
Edit: MV3 is a perfect example of inverse tivoization.
webRequestBlocking is not deleted in MV3. The synchronous blocking engine still exists in Chromium. If an extension is installed via local policy or the Windows Registry (ExtensionInstallForcelist), full programmatic webRequestBlocking executes in Manifest V3 just as it did in MV2.
It is in practice.
Not all users are able to do that (local policy install), as not all users are (or have to be) that tech savvy. That’s an exclusionary barrier towards inclusion and accesibility of security and sovereignity features.
Handing third-party extensions blanket permissions to inspect and modify live plaintext traffic across all tabs creates a massive MITM exfiltration surface. Moving rule matching to declarativeNetRequest enforces least privilege by executing filters in the native engine without exposing sensitive network payloads to extension code.
You’re doing a false equivalence here.
It’s not about blanket permission vs. almost no permissions.
You can have granular ACLs (which are being hindered by MV3), or OCap/CapSec, or even other security and permissions approaches.
They’re or incompetent or malevolous, these are the only two options left when you think a bit about it.
Thanks for the laugh! Keep telling yourself that.
Firefox is Chrome with extra steps
Care to elaborate? It’s actually not like chrome at all. The engine is different, it’s not Google, they haven’t blocked manifest v2 plugins… Other than being a web browser, how would you classify it as Chrome?
Not only are they different, Gecko is like 12 years older than Chromium.
I guess they could be referring to how much money Google throws at Mozilla to keep Google Search as standard in Firefox? Still, it’s a tenuous link at best
In about:config check with what google services, urls, relays, vpns browser communicates. What organizations donate most money.
Hardly makes it “Chrome with extra steps”.
Did you actually look inside?
I don’t have to. Yea, it shares some backend Google services, but the rest of the browser, like the other 90% isn’t Chrome. It’s like comparing Windows and Mac OS and saying that they’re the same because they both connect to the same Internet and that their operating systems. Just like Chrome v Firefox, they are two distinctly different products.
That doesn’t even make sense. You bots need better prompts
Huh, do we have engagement bots in Lemmy already?
We’re thriving guys!
Probably just young
Maybe used Chrome for years before ever hearing about Firefox
You can say that about almost every browser, but not Firefox.
Still time to delete this
I’ve never seen a more downvoted comment. This is true for every single other mainstream browser except Firefox.
Some forks of Firefox are ok, but if you actually dig and look inside about:config you’ll see with who it communicates, what telemetry it collects. What organisations fund it.
Thanks for the laugh!
Lol no


Ah, the Sam Reich of browsers
Just a crying shame Mozilla has turned into a commercial nightmare making them relatively poor custodians of the only free choice we have left.
Mozilla needs to die so Firefox can live.
The income stream from Firefox is plenty for a highly technical, deeply competent, widely dispersed team could work full time on the product using something like OpenCollective.
Instead what we get is prime SF real estate offices, “competitive” SF salaries and a commercial organisation that seeks weird and increasingly desperate income streams to justify looking like “real company”.
I want an actual non-profit governing Firefox.
It’s called the forks, dude.
Also, hopefully the
ladybugthing or whatever gets off the ground someday.Edit: Servo is the better project to follow.
I think you mean ladybird, right?
Just FYI The core maintainer is very close to the alt right open source sphere.
Rejecting inclusivity as he deems it as too political and just rubbing shoulders with really weird guys.https://drewdevault.com/blog/Cloudflare-and-fascists/
https://kvibber.com/reviews/software/ladybird-inclusivity/There is servo though which is picking up speed lately, im following their rss for a while now.
https://servo.org/
The money behind is also a lot more public and the project is more open to people. originally developed internally at mozilla it is now in the hands of the linux foundation europe.Ah ty. I wasn’t keeping track of either project, but good to know servo’s the one to look out for instead.
But it isn’t really. The forks rely on the majority effort of Mozilla and they would never be able to maintain Firefox on their own.
This this true but if Mozilla closed it doors tomorrow there would be enough support for a team to be built to maintain it. The market share is small compared to chrome but it’s still an enormous user base.
Given how long ago this was announced, anybody still using Chrome doesn’t care.
deleted by creator
Or they just installed uBlock Origin Lite, which still works for most things.
I don’t use chrome, but this thread is the first I’m hearing of this.

This is gonna be so bad because now there is only uBlock origin lite and “uBlock”, if you couln’t guess: the 2nd one is a scam that google never tried to remove(it’s been up for some years IIRC) and i am sure that everyone will try to install this scam because they can’t find the original uBlock origin (and everyone just refers to uBlock origin as uBlock which makes it worse)
1 million users…
“1 million deceived users”.
There, I fixed it for you. You’re welcome.
company which makes most of it’s revenue from advertising fucks with their browser’s ability to remove ads. Go figure!
i am surprised it took this long, but i know that getting everybody using chromium, or at least webextensions, was part of the plan that had to exist first. and the path down mv3 started not long after both mozilla and microsoft were both roped-in.
I have to say I’m not surprised. No one wants to pay for a browser.
The irony is that Chrome’s rendering engine was a fork of WebKit, which was a fork of KHTML, a free and open source rendering engine created by KDE for Konqueror. They basically took something free, used Microsoft’s “embrace, extend, extinguish” tactics on it. Now KHTML is vestigial, only found in the UserAgent string.
But we could have had a truly free open source cross platform browser with Konqueror.
Best we have now is Firefox, but the bulk of Mozilla’s development funding comes from setting Google as the default search. So it is also hijackable.
We could maybe have done that. But Konqueror has never been that good every time I tried it.
In circa 2003-2004, it was as close to on par with browsers at the time as it would get. I think the WebKit fork did damage to the momentum. By 2008 with KDE4, the rework that split it and Dolphin into to products was basically the final nail I think, as development work effectively stopped.
I think it’s the shear cost of operating a browser. I would hope Mozilla are looking to diversity there income but without ads or sales to end users I’m not sure where it can go.
If you pay, do you get a say or is it the same play but you paid?
Chrome? What is that?
A thin layer of chromium on the surface of a metal to make it shiny and protect from corrosion.
Delicious when hexavalent
I used to work in manufacturing and we made a sort of tube socket that was cadmium plated on the outside and chrome plated on the inside.
I wonder how many people got cancer plating those things. Ironically, all of the platers were in California because it was banned for new plating centers in most other states.
A browser forked from KHTML by KDE
Chromium is the browser that I open a few times a year for websites that don’t support Firefox. A few may be a gross over estimate.
Fair, I just abandon the site. It’s their problem not mine.
It’s really seldom, but a few years back there was a government website that only worked with chrome or edge that I had to use. I had one the other night and found a work around. It’s a rare occurrence, and usually I can avoid it, but sometimes I have to just suck it up, do the deed, and bail.
I don’t design web apps but I’ve heard from some that do that firefox occasionally has problems with them, because it relies a lot on caching (actually they used the term “aggressive caching”, with a few extra choice words).
Anyway, usually not a problem. I use edge only for work since it’s the default browser and I barely do any actual browsing with it, mostly light app clients. On my own devices, it’s been firefox only for years.
Nowadays, just changing the user agent would be enough to make the site work again.
Isn’t that the shiny stuff you hang from trees in the winter?
No that’s tinsel
Oh yeah, Gretel’s brother
Nah, you’re thinking of Hansel. It’s actually an online community of people who can’t get laid despite really wanting to.
The data pimp with a loading bar
Google is all in on evil.
Time to degoogle
I think I’ll be switching to librewolf at home. It can install mozilla extensions and comes with ublock origin baked in. Pulling a stunt like this is just going to drive people away from the Chrome environment. Corpos can’t help but shoot themselves in the foot.
Most people I know simply don’t care. They will use it because it’s convenient and they don’t care about the privacy dangers. I can’t comprehend it myself though. Drives me up the wall.
They will use it because it’s convenient
Using web without ublock is amongst the most inconvenient things I’ve experienced
I think most people who don’t know better just think that’s “the internet” and that it’s the same no matter how you access it. The whole concept of browsers and extensions is just not in the realm of concern.
I’ve seen some shift among the tech illiterate in my immediate vicinity, but most are still in the “I got nothing to hide” category of clueless twits.
Funnily enough my two kids have expressed hatred of AI. It’s mainly people around my age or higher that can’t let any sort of convenience go even if shown the dangers.
Otherwise I’m just “scaremongering”.
The kids are alright, then.
My 14yo hates the current AI but says most peers are using it and can’t understand how to write an essay or such without it.
I think only some of the kids are alright. Many, if not most, are in trouble.
Fair. I said that out of hope. I’m young. Just 24. But I’ve always been progressive. I want younger people smarter, and not dumber than me, LOL.
I hear this nightmare stories of kids lacking basic comprehension skills. AI should be severely limited in educational settings, though not outright banned, as it can supplement learning when used appropriately.
The problem is that everyone’s internet experience is very different these days. Your friends might be boring and actually have nothing in their lives that need compartmentalized/obfuscated. It’s unlikely but not impossible.
The easiest way to demonstrate the problem would be when they show you something on an unprotected device you note the ads and give them shit for it. Those ads are likely targeted, and so your jabs would be targeted and personal too. Then point out that those ads are tied to THEM. Just ask every time, “have you been looking at X? Gross dude.” It doesn’t matter what it is. It’s the point that they are uncomfortable with your guess and it’s an opening to explain that, yeah it’s not just those ads buddy.
People who share every intimate detail of their life online don’t care about privacy.
Install Firefox with https://adnauseam.io/, it’s basically ublock origin but internally clicks on every add destroying your adds profile and damaging economics of adds and conversion.
Doesn’t this just track the shit out of you? Does it also click malicious ad banners?
Well, it anonymizes you by “faking” the tracking. I would hope it takes steps to sandbox the ads.
What does it fake about the tracking? The tracking is very real and the tool is clicking every tracking link available on the site like its life depends on it
Step 2: install Privacy Badger
And Facebook Container is another useful one.
Don’t, privacy badge and adnauseam will interfere eachothers and as result you will get worst results, you are better off using a DNS level adblocker (eg: Pihole or NextDNS if you don’t/can’t self host) alongside uBlock/adnauseam
Ublock already does the job of privacy badger… Well as far as I know…
They overlap; Ublock does it through lists, and badger does it through heuristics.
Running just badger, it can miss things, if you can use both, you get all the lists and heuristics, but they’re probalby not both necessary
Firefox users right now:

Sing it with me:
Chrome, huh, yeah.
What is it good for?
Absolutely nothing, uhh….Damn it.
Gotta use chrome at work.
Firefox “isn’t secure and isn’t supported” - my it director
isnt secure… tell you dont understand security without telling me you don’t understand security.
They’re probably using google workspace and accounts, you can do a lot of monitoring with that
Work at a larger organization and the only browser we’re allowed is fucking Edge. All other browsers are blocked as malicious processes.
LOL. from one data mining company to another data mining company.
This guy?

Company hardware isn’t checked by user agents but actual running processes
You’re saying they have some sort of app that actively blocks firefox from running on their laptop? I fortunately never worked in a company that did something like this. I would say it’s more likely that the web application simply checks user agent and blocks unsupported browsers.
Yes, companies have software running on company property usually that checks what you’re running and installing. I can’t even get admin perms on my work machine without asking IT with a good reason. They can also see your browser history and what websites you go to, as an fyi to not browse anything that you wouldn’t feel comfortable talking to your boss and HR about on a work machine.
I know of people that also had a no activity log, just in case you didint input something on your PC for 2 min
Yeah that is also done in some places but afaik it’s not legal to do so in most places without letting you know what is being monitored. It’s a pain in the ass
I once saw a company block Firefox through its corporately mandated antivirus software.
It’s called Microsoft
Company Portaland it’s the worst
Then just use vanadium at work
EDIT I no Loguer recommend brave
Fuck Brave. Their CEO is a homophobic transphobe asshole who actively donates money to help take away peoples rights, they are shills for a bunch of AI and crypto BS that is inbuilt in the browser, and they at least used to steal affiliate links.
Prove it
Thanks I’m now going to uninstall brave fuck they ceo
Brave has been severely disappointing not because of Brave company or the browser itself, but because it marked a point of tech illiteracy. The affiliate link insertion should have and would have in the past been enough to end them all together.
Pretty sure Vanadium is mobile only, so unfortunately not really an option.
Not using firefox should automatically brand you as not knowing what you are talking about in IT. wtf
deleted by creator
Don’t blame Firefox, some sites don’t comply with industry standards.
ublock origin lite, the natural replacement but not automatically enabled by google or microsoft. you have to go get it. https://github.com/uBlockOrigin/uBOL-home
an alternative is adguard’s browser extension. it is free to use and open source (gpl). https://github.com/AdguardTeam/AdguardBrowserExtension#installation
No you get Firefox
Ah, thank god I am using Zen (Firefox fork) now for 2 years already. I totally forgot about this manifest bs. Now that Chrome introduced vertical tabs I was thinking to myself “ah, I could give it a try, having less breaking things and so on”. But thanks for this reminder I will gladly stay with Zen.
Switched to Zen as soon as I switched to Linux about a year and a half ago. Love it.
Another Zen user chiming in to say, all the other ones seem confusing and cluttered now.
FWIW I do think you should give it a go.
Firefox is main browser, on desktop and mobile, and I’m not changing that.
Still, I do have Chromium installed for very specific usages, e.g. WebXR tests, WebBT and WebUSB devices, e.g. flashing keyboard firmware, controlling Lego bricks, etc. I’d rather only have Firefox to be clear but some things are not supported, marked as not planned, and I believe using Chromium on specific Websites, not for browsing, is perfectly fine when no alternative is available.
Giving Chrome a go? Why would I? Zen has everything I need, plus Chrome does not have an ad-blocker. I also sometimes need WebUSB and such things, but well, then I’ll use chrome once for that and be done with it.
I strongly suggest you nuke Chrome every time you are done using it.
Well then you are already doing what I suggested.
I’m not saying adopt Chrome as your main browser, I’m saying if Chrome alone has unique feature you think you might need, try it there. For example that allowed me to discover https://github.com/ArcaneNibble/awawausb
Consequently if you are curious about vertical tabs, do try it, even in a container, e.g. Webtop, if you want to be extra safe. I’m not suggesting to switch.
I switched to Zen a week ago and I haven’t ran into any issues with it, what do you find is broken with it?
I had some websites which didn’t work in some way. Can’t remember, which websites it were, just some big company websites where random buttons would just do nothing or similar. But I think it were only 2 or 3.
Other than that it’s fine. Sometimes it seems like tab management is a bit weird, I once had the browser open with about 100 new tabs besides the other ones I had saved. Just had to close them and done. On my Work-Laptop I have a folder pinned in one space and the popup for it’s contents is shifted down ~200px permanently for some reason. It’s all manageable.
That’s a web site design and architecture issue, not a browser issue. Most web sites are made for Chrome (Chromium-based) browsers, and anything based in Gecko is an afterthought, if anything.
I’d rather just not access a site if Chrome use is mandatory. LibreWolf has been fantastic for me the last 3 years or so. If I really need to access a “Chrome-exclusive” site, I use Brave, and then clear and reset everything in it in case I need it again.
I’d say it’s 50/50… actually 33/33/33.
First, in 2026 I think you need to fuck up pretty bad or use very special stuff in order for your website to only work on Chrome.
But of course Mozilla should behave just like every other browser (well there is basically only chromium right now) and all browsers in general should display websites in the same way. Back in the day you did choose which browser to support when you developed your website, but today you are basically just using browser standards.
Then… there is Google. They are blowing up and poisoning the web standards so much, for their own good and just to bring technology forward. They surely could be more careful and considerate while doing this, so that Mozilla would have a chance to participate.
Edge will soon follow. They announced it. Polly will switch to helium or brave
Brave is kinda shady with their whole cryptocurrency thing, Helium seems fine but it’s still based on Chromium. I’ve been recommending people check out Librewolf
Simple Firefox is perfectly fine.
Ungoogled Chromium is my standby for the instances when a Blink browser is needed, though it’s not entirely simple to set up.
Librewolf doesn’t do anything that Firefox can’t do with extensions + tweaking settings, but it’s nice to not have to install all the extensions
Yeah that’s why I’m debating brave. Firefox is good to especially after the huge engine overhaul a few years ago.
Yeah, I’ve been on brave for a few years but switched to Firefox because it’s a different base. I don’t think it’s necessary better, but if that’s the way the wind is blowing on chromium browsers the it’s the best option.
Or better yet LibreWolf
Or better yet LibreWolf
I cannot count how many things I had to change in settings to get the browser to just work right, I mean I appreciate them locking everything down to the nth degree but… damn. Finally switched to waterfox, the out of the box experience is a lot friendlier.
I tried LibreWolf for a little while, but too many sites just wouldn’t load at all with it, so I went back to Firefox.
Maybe give waterfox a look-see too
I get the frustration. It could have a tutorial / wizard to make it easier to set and understand.
If some parts are not loading, check the top left of the address bar for some icons, by default LibreWolf blocks canvas and anything that can identify you, and you have to press on them to allow them to render the elements.
Security unfortunately implies more inconvenience, which is what companies like Google love, but if it was a lot friendlier it would probably be less safe.
Zen-Browser
I’m using Zen now. it took me a while while to get the hang of the UI. But once I did I found it to be very nice to have those spaces that I can organize for different tasks.
I’ve used Zen for about 9 months, possibly more, and have had a largely positive experience.
It has crashed a few times recently for no obvious reason but not enough to bother me. There’s probably new release version again even though I updated my Linux instance a couple of weeks ago.
First time hearing of Helium, thanks for mentioning. Sounds interesting, will be keeping an eye on it.





























