http-observatory
uBlock
http-observatory | uBlock | |
---|---|---|
33 | 2,992 | |
1,821 | 43,401 | |
0.4% | - | |
7.8 | 9.9 | |
4 days ago | 5 days ago | |
Python | JavaScript | |
Mozilla Public License 2.0 | GNU General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
http-observatory
-
What are the actual security implications of port forwarding?
Detectify once made an offer of making free scans which I took them up on. There are plenty of free Content Security Policy (CSP) and other vulnerability checkers around such as Observatory or Pentest. Shields UP!! will identify which ports you have open.
-
200 Web-Based, Must-Try Web Design and Development Tools
Website Headers Analyzer (Mozilla)
- Open source cookie scanner
- I made inline styles CSP-compliant in .NET 6+. Here's how
-
Deploy a static site to AWS S3 and CloudFront using AWS CDK
scan our site with Mozilla Observatory and improve our grade by registering a domain name, enabling HTTPS, adding a certificate and setting security headers
-
Simple "Frictionless" Authentication that is Secure "Enough"
First, for session persistence, go with the default Django session with cookie storage. Set your cookie to HTTP only and ensure your application uses the most common HTTP security headers and controls. Test your application with https://observatory.mozilla.org/ to have an idea of what you're missing.
-
Any tool to check the security of my server?
Mozilla Observatory
-
How to explain styled-components to a vanilla JS fanatic
See https://observatory.mozilla.org and https://github.com/styled-components/styled-components/issues/2363 and https://content-security-policy.com/examples/allow-inline-style/
-
My wordpress page sends a lot of "shady" requests to a site called "brounelink.com". Why? How to debugg where this is coming from?
Rank your site on https://observatory.mozilla.org/ and it will give you some suggestions.
- WaPo: Stealthy Kherson resistance fighters undermined Russian occupying forces
uBlock
- Apr 24th is JavaScript Naked Day – Browse the web without JavaScript
- Mobile Ad Blocker Will No Longer Stop YouTube's Ads
-
Some notes on Firefox's media autoplay settings in practice as of Firefox 124
Check out uBlock Origin's per site switches [1]
[1]: https://github.com/gorhill/uBlock/wiki/Per-site-switches#no-...
-
Brave's AI assistant now integrates with PDFs and Google Drive
If ads, in particular on YouTube, are the problem, anything Chromium-based is probably only going to get worse and worse (see [1] and [2]). So that basically leaves you with Firefox and Safari.
I work for Mozilla (speaking for myself, of course), so I'll leave you to guess which I'd recommend :P
[1] https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b...
[2] https://arstechnica.com/gadgets/2023/09/googles-widely-oppos...
-
X.org Server Clears Out Remnants for Supporting Old Compilers
https://github.com/gorhill/uBlock
Or if on mobile, it is well worth it to look up adblock options for the browser you use.
-
Mozilla thinks Apple, Google, Microsoft should play fair
What are the compelling advantages of Chrome nowadays?
Chrome is working to limit the capabilities of ad blockers:
https://www.malwarebytes.com/blog/news/2023/11/chrome-pushes...
Whereas a compelling advantage of Firefox is that uBlock Origin works best in Firefox:
https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b...
Advertising networks have often been vectors for malware. Using an ad blocker is an important security measure. Even the FBI recommends ad blockers:
https://www.malwarebytes.com/malvertising
https://theconversation.com/spyware-can-infect-your-phone-or...
https://www.ic3.gov/Media/Y2022/PSA221221?=8324278624
-
Brave Leo now uses Mixtral 8x7B as default
> It allows for 30,000 dynamic rules
That is not what we mean by dynamic filters. From https://developer.chrome.com/blog/improvements-to-content-fi...
> However, to support more frequent updates and user-defined rules, extensions can add rules dynamically too, without their developers having to upload a new version of the extension to the Chrome Web Store.
What Chrome is talking about is the ability to specify rules at runtime. What critics of Manifest V3 are talking about is not the ability to dynamically add rules (although that can be an issue), it is the ability to add dynamic rules -- ie rules that analyze and rewrite requests in the style of the blockingWebRequest permission.
It's a little deceptive to claim that the concerns here are outdated and to point to vague terminology that sounds like it's correcting the problem, but on actual inspection turns out to be entirely separate functionality from what the GP was talking about.
> Giving this ability to extensions can slow down the browser for the user. These ads can still be blocked through other means.
This is the debate; most of the adblocking community disagrees with this assertion. uBO maintains a list of some common features that are already not possible to support in Chrome ( https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b... ) and has written about features that are not able to be supported via Chrome's current V3 API ( https://github.com/uBlockOrigin/uBOL-home/wiki/Frequently-as... ). Of particular note are filtering for large media elements (I use this a lot on mobile Firefox, it's great for reducing page size), and top-level filtering of domains/fonts.
- uBlock Origin – 1.55.0
-
In 2024, please switch to Firefox
> "Its happened before"
> That's not an argument
It's a subheading to "2. Browser engine monopoly". The subsection's purpose is describing how bad things were during the IE monopoly to reinforce that it's something to be avoided.
> in fact you could counter-argue that IE left a lot of technical debt
That would be agreeing with the article, unless I understand what you mean.
> On top of that, the internet was very different back then.
In a way that now makes it harder for truly new competing engines to pop up due to increased complexity of the web.
> I'm still not convinced, why would I change my browser?
The points made in the article are:
* Increased privacy, opposed to willingly giving your data to an ad-tech company
* Helps avoid a browser engine monopoly which would effectively let Google dictate web standards
* It’s fast and has a nice user interface
Onto which I'd add:
* Content blockers work best on Firefox (https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b...), doubly so when Manifest V3 rolls out
* Allows more customization of interface and home page
* UX improvements, like the clutter-free reader mode, aren't vetoed to protect search revenue as with Chrome (https://news.ycombinator.com/item?id=37675467)
-
Ask HN: Is Firefox team too small to do serious security tests?
Advertising networks are vectors for malware:
https://www.cisecurity.org/insights/blog/malvertising
https://www.malwarebytes.com/malvertising
https://theconversation.com/spyware-can-infect-your-phone-or...
So if you're concerned about security then you want the browser with the best ad blocker.
uBlock Origin works best in Firefox:
https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b...
What are some alternatives?
django-csp - Content Security Policy for Django.
VideoAdBlockForTwitch - Blocks Ads on Twitch.tv.
ssh_scan - DEPRECATED - A prototype SSH configuration and policy scanner (Blog: https://mozilla.github.io/ssh_scan/)
Spotify-Ad-Blocker - EZBlocker - A Spotify Ad Blocker for Windows
http-headers-security - HTTP Headers Security Cheat Sheet
bypass-paywalls-chrome - Bypass Paywalls web browser extension for Chrome and Firefox.
observatory-cli
duckduckgo-privacy-extension - DuckDuckGo Privacy Essentials browser extension for Firefox, Chrome.
tls-scan - An Internet scale, blazing fast SSL/TLS scanner ( non-blocking, event-driven )
ClearUrls
jspaint.exe - 🌂JS Paint ~~ as a cross-platform native desktop app. In other words, the "🎨 Classic MS Paint, REVIVED + ✨Extras".exe hehe
AdNauseam - AdNauseam: Fight back against advertising surveillance