Hacker Newsnew | past | comments | ask | show | jobs | submit | parmezan's commentslogin

Deinstalled. Very sad because this this extension made my life better. Any open source (FLOSS) alternative?


Not exactly the same, but I'm happy so far with Consent-O-Matic:

https://consentomatic.au.dk/


> Although using dark patterns is illegal, the laws are not enforced enough, so many websites get away with it.

The problem with consent pop-ups isn't the European law; it's the failure to properly enforce it.


The problem with consent pop-ups isn't the European law; it's the failure of many companies and persons to properly follow it.


Definitely recommend this one. I have it switched to not consenting to anything, and I haven't seen a cookie popup since.


I have recovered and am hosting the version 3.4.2 source code, the version prior to the Avast acquisition, at the below repo

https://github.com/elgrove/idcac-3.4.2


You can active filters in ublock origin that blocks cookie banners. I think the one I'm using is "Fanboy’s Annoyance".


Blocking cookie popups renders some pages unusable. For instance adidas. I could not scroll when blocking cookie prompt.


THIS. Which is why we don't recommend extensions on privacyguides.org besides uBO (uBlock Origin). If that ever gets bought, you'll hear about it everywhere and there will most likely be a fork.

These days for privacy with Firefox you really don't need anything else. There are a few others that may have something to offer https://github.com/arkenfox/user.js/wiki/4.1-Extensions for specific purposes.


> If that ever gets bought, you'll hear about it everywhere and there will most likely be a fork.

In fact, that already happened, and that’s why it’s called uBlock Origin: https://en.wikipedia.org/wiki/uBlock_Origin

> The uBlock project official repository was transferred to Chris Aljoudi by original developer Raymond Hill in April 2015, due to frustration of dealing with requests. However, Hill immediately self-forked it and continued the effort there. This version was later renamed uBlock Origin and it has been completely divorced from Aljoudi's uBlock. Aljoudi created ublock.org to host and promote uBlock and to request donations. In response, uBlock's founder Raymond Hill stated that "the donations sought by ublock.org are not benefiting any of those who contributed most to create uBlock Origin.” The development of uBlock stopped in August 2015 and it has been sporadically updated since January 2017. In July 2018, ublock.org was acquired by AdBlock, and since February 2019, uBlock began allowing "Acceptable Ads", a program run by Adblock Plus that allows some ads which are deemed "acceptable", and for which the larger publishers pay a fee. uBlock Origin remains independent and does not allow ads for payment.


"IDCAC" doesnt have much to do with privacy, its about convenience. uBO filters dont help you there, as they cant click buttons for you on all the different cookie forms.


If there’s no buttons to worry about clicking (because uBO removed them), what does it matter? GDPR requires you to actively consent, so if you ignore the cookie banner (or block it) advertisers can’t track you.


However it was revealed not long ago that a lot of the third party cookie consent forms used by the majority of sites don't actually have any effect when you interact with them... i.e they tracked everything whether you consented to it or not, I think it was a combination of negligence (incomplete software) and betting on the fact that the vast majority of people just hit accept due to dark patterns that make it extremely inconvenient to do otherwise.

I think using uBlock etc is more likely to result in preventing tracking through blocking known urls and code etc compared to hiding consent forms... I know it's far from infallible but currently most trackers don't bother going to extremes if you block them.


i've found a good few websites break when you don't interact with the cookies banner that IDCAC removed.


I'd rather be actively hostile to the ads and tracking and use Ad Nauseum, instead of passively blocking them with just UbO


> actively hostile to the ads and tracking and use Ad Nauseum

Don't do this, it doesn't work the way you think, but in fact makes your browser easier to fingerprint. Very few people use that extension.


But then you also wouldn’t have been using this extension which defaulted to allowing all possible tracking when it couldn’t figure the popup out.

This was an extension for people who don’t care about privacy.


I have (had, soon) this add-on and I very much care a out privacy. Blocking all cookies from non-whitelisted sites is more or less impossible with all the consent pop ups. Ant many of those pop ups make it really hard to reject cookies.

So I went for a solution that makes browsing less annoying, whithout storing many cookies:

- Have this add on accept all cookies - Block third party cookies - Delete cookies from websites as soon as I close a tab

I (and you) don't know if many users of this add on do something similar, but it is what's recommended on the website

> Please educate yourself about cookie related privacy issues and ways to protect yourself and your data. For example, you can block 3rd party cookies, install ad blocking extensions and then block tracking tools, delete browsing data regularly, enable Tracking Protection in your browser etc.


You got lied to. The popups are rarely about cookies, and mainly about tracking. The GDPR barely even mentions cookies for a reason. With this addon, you say "Hey, use whatever method you’d like to track me in whatever way you want". But then you delete the browser cookies. I mean, that’s nice, but that doesn’t remove your tracking consent freely given.


I know that that's what GDPR is supposed to be about, but it's not what the fast majority of the pop-ups are about. Most pop-ups I've encountered are explicitly about cookies, not about any other kind of tracking.

And besides that, I think it's really naive to assume you've got any influence on tracking that sites do on their site. With cookies I know I can choose to save them on my machine or not. If a website uses the fingerprint of my computer to identify me, they'll almost certainly keep doing that after I've rejected their cookies.


You can already see it with Google Ads. Some ads don’t get delivered if you don’t allow "create a profile on me". Now, if you think companies will ignore even explicit laws every time instead of finding loopholes, then yes, it’s useless. But at least for some part of it, it’s easily provable that they don’t.

Consent-o-matic is the extension that people use that do care about tracking (or believe that most companies will mostly follow the law, I guess).


Yeah, Consent-o-matic is what I've started to use after today's news. Didn't know it existed until a couple of hours ago. I'm just not convinced it'll be a huge improvement over using (pre Avast) I don't care about cookies. And I still think that saying "This was an extension for people who don’t care about privacy" is a pretty big overgeneralization.


I'm not a browser extension developer -- but I wonder how long it would take for another extension that does exactly the same thing.


Practically all famous Linux distro's offer built in encryption when setting up a new system using luks/dm-crypt. But you don't have to worry about it.

To encrypt a Windows 10 system u can use Veracrypt to boot the whole OS or just a container.

For Windows (Enterprise) you can also use BitLocker by Microsoft although the source code isn't trusted and I believe you have have a more expensive license in order to use it.

Yes you should encrypt your laptop. It's worth it in case you lose a laptop or it gets stolen nobody can read the data.


> BitLocker by Microsoft although...

A further reason to avoid BitLocker is that it is incredibly easy to give Microsoft the decryption keys to your data if you're not extremely careful. I think the default setting was (and still is?) that Microsoft gets the ability to decrypt your data. I don't understand why anyone would think that is desirable.


Truth is people don't care what operating system they get as long as it 'just works'. LibreOffice is IMO too ugly and unusable to use for tech illiterates.

Windows 10 and defender does a bloody good job of blocking lots of malware. Think of tools like mimikatz. You don't see Ubuntu blocking a mimikatz-like binaries.

Firefox is slower compared to Chrome. People care about speed. Firefox is also not privacy friendly. Lots of telemetry to mozilla/google.

You are out of touch and have embraced the cult that is Linux, Open Source. I don't understand why the algorithm pushes your post to the top.


Firefox is not slower than Chrome. Some things are faster in Firefox (optimized JS, starting workers) and some are faster in Chrome (WASM).


It has been less than a month after fixes emerged for kernels and your PoC exploit has already been released into the public. Should you not have waited at least a bit longer (for example 2 months) before disclosing this vulnerability so that people/companies can keep up with patching? Don't they need more time to patch their servers and legacy etc before this becomes yet another log4j exploitation fest? That is if this really is the new dirty cow vuln.

I get responsible disclosure is important, but should we not give people some more opportunity to patch, which will always take some time?

Just curious.

Also, nice work and interesting find!


It's the absolute opposite. It's insane that this commit wasn't flagged as a patch for a major vulnerability. Why am I finding out about this now? Why is it now my job to comb through commits looking for hidden patches?

It puts me, as a defender, at an insane disadvantage. Attackers have the time, incentives, and skills to look at commits for vulns. I don't. I don't get paid for every commit I look at, I don't get value out of it.

This backwards process pushed by Greg KH and others upstream needs to die ASAP.


Personally, I just enable automatic security updates and forget about it.


Once the commit is in the kernel tree it's effectively public for those looking to exploit it. Combing recent commits for bug fixes for the platform you're targeting is exploitation 101.

The announcement only serves to let the rest of the public know about this and incentivize them to upgrade.


Max did everything right here, and in this case I’m not sure the distribution process exists to have done better.

(Thanks Max for handling this well and politely and for putting up with everyone’s conflicting opinions.)


FWIW, if it in any way comes off like I'm blaming Max for this, I'm not. Anyone blaming Max for how vulnerabilities are disclosed is completely ignorant of the kernel reporting process.


Just wanted to note that your replies come off as quite confrontational/aggressive. I think you have valid points, and it's clear that this topic is important to you, but you're heating up the atmosphere of the thread more than necessary.


That part I'm ok with. Upstream has treated security researchers with contempt for decades.


Why not three months? Why not six? I do not get it. How is this same conversation still happening? This was public the day the patch was sent to the list or pushed to a public git server. Do you think adversaries are sitting around for a POC? Or for you to decide to get around to patching?

I can't help but physically shake my head as I write this. I can't imagine actually asking people to try to play pretend security through obscurity because folks still can be arsed to implement some sort of reasonable update strategy. I have enough experience in tiny and huge shops to say that it's a matter of prioritization and it's just a blatant form of technical debt and poor foresight.


You never know if it was already being exploited, but once thing is sure, once the patch gets merged, it's a race and only a matter of time before an exploit is written. Two weeks is already long and may leave distro users exposed, which is why it's important that it doesn't stay too long in the fridge. Ideally we should have a "patch day" every week that distros would align on. That would allow users to adapt to this and get prepared to applying fixes everywhere without having to wonder about what fix addresses what, and more importantly it would remove the surprise effect. The distros process doesn't make this possible at the moment.


Impressive dude.

Also from a security perspective don't forget to update those very out of date nginx webservers :)

My tool detects version 1.10.3 which was released on 31 Jan 2017


Good tip, thanks. Will make it a priority.


What tool do you use?


wget -S ?


Ofcourse it does. And ofcourse even with all settings 'off' to gain privacy, data is still being sent. It's Microsoft. They earn money with your data just as Google does. We know they do. And we don't know the full source code.

Useless clickbaity article IMO.


YubiKeys! https://www.yubico.com/ a tool to increase your security. But can be expensive.

His/her favourite programming language or tool as a mug/sticker/tshirt on redbubble.com

Some cool mug that automatically warms up or stirs with a button. Because techies need coffee.

Laptop webcam blocker sticker/shuffle to keep ur privacy.

LED stuff. Like a led strip or something because cool lights are nice.

Smarthome stuff like a smart plug! It shows power usage of devices and u can program it using automations with homeassistant https://www.tp-link.com/en/home-networking/smart-plug/hs110/ - cool to automate ur home with it.


Librem Key is a FLOSS alternative: https://puri.sm/products/librem-key.


Happy with solo keys (also open source and hackable)


doesn't support FIDO/U2F though?


+1 for the YubiKeys. Can't really have too many.


Wow this looks neat, modern and clean! I wish other similar toolkits for other languages look as great, blue style for the workplace. Love it.

Sadly their docs github webpage is not built with that toolkit. It would be logic and cool if it did so that we immediately can see what it looks like. Load in the button as a real application would do etc.

Also the docs webpage could be clearer, easier to navigate etc.


Totally agree, I really like the design but documentation should be improved.


Alternative yt desktop app is https://freetubeapp.io/


Or the native cross-plattform opensource Minitube from https://flavio.tordini.org/minitube . Is already available on most systems through the package manager.


This is such a beautiful post. Easy reading. It's good the author got over his struggles and documented here. Wish the author well.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: