New Update Need testers for the new V5.0 of uBol-stripped which has a new feature called Privacy Inspector

What is better a predefined set of rules to block fingerprinting on 10 adult websites with most visitors (add it to no eval protection) or offer a don't show adult websites in custom rules manager, what is your take?
The former. Or neither and let users configure for themselves.
I thought that you would value Privacy Inspector as your on demand JShelter lite without the CPU impact and hassle, maybe these examples can convince you to check out the websites you visit often but (nearly) never log in to.
I'm already convinced and have been testing on different sites.
Dear friend @oldschool try NBC news and CBS news with Privacy Inspector :)
Surprisingly CNN and Fox news come clean, no fingerprinting
Yes, I tried them with µBol-stripped only. They show little or nothing when used alongside 3P-Matrix lite with Medium mode startup level. I won't be missing MV2 with the merged functionality of µBO, µMatrix and JShelter in 2 MV3 extensions.. Excelllent work my friend! (y) (y) :cool:
 
This is all I get with the current version of uBoL-strippen on the two Dutch news sites?

View attachment 299016

View attachment 299017
Yes, curent CWS version has 7 signals, new version 5.1.1 (already submitted to CWS) has 10.

The three new (in 5.1.1) Privay Inspector signals are existing scriptlets adopted for this purpose.

So uBol-stripped now has in total 4 "own" scriptlets (the Noeval in Security & Privacy only looking for specific obfuscators is also an adopted existing scriptlet).
 
Pushed V5.4.1 (correction) V5.4.2 to Chrome Webstore for review.

Added credits to ´NoScript for user interface'on Custom DNR monitor and J́Shelter for fingerprinting signals' on Privacy inspector.

Now there are in total 13 signal categories (some looking at more API's) so I added a BLOCK ALL button to enhance the user workflow, see picture.

When a website triggers many fingerprint signals, you might repeat the block all, until the monitor shows empty. When AI has told me the truth these are all low risk mitigations (should not break website functionality). When in the worst case it should breake the website, you can use remove all in the custom rules manager and have to find-out which ones to block 1-by-1 (but I don´t expect that to happen). As posted many times USE privacy Inspector only on websites you visit often but never log into. This reminds me to put in the window title, so version will be 5.4.2 :-)


1784961971367.png


V 5.4.2 with warning :-)

1784962825094.png


P.S. when V5.4.4 (yes two minor things polished away) is available in the CWS, could someone tell Brummelchen on Wilders how stupid it is to have an opinion without factually checking the code (proud to be a copy-cat :ROFLMAO:) I understand that this is Chinese for most, but maybe @Trident can comment on Chat's comparison.
1784964216223.png
Around 50% of the code is based on uBO-lite (refactored, but sometimes only grouped differently with added comment's to prevent coding landmines because of the smart coding constructions of mr Hill).
 
Last edited:
But I also see an already imported host file list (Dan Pollock's host file), @9724anon7537 seems to have successfully imported a third-party list , I am afraid I am goung to disappoint you: read this W3C_annual_most_used_survey_blocklist/README.md at master · Kees1958/W3C_annual_most_used_survey_blocklist
Sadly you did, anyway i'll continue to keep an eye on your excellent extension in case something will change in the future on this front, keep up the good work!
 
Last edited:
Great job, my friend. (y)(y)(y)
I have two questions from my daughter and her coworker, who use uBoL at work, and I advised them to switch from uBoL to uBol-stripped.

At work, my daughter uses Edge, which obviously has built-in privacy features similar to Firefox.
If I understand correctly, her coworker uses Brave with Ad-Shields disabled and fingerprinting enabled.
Keep in mind that they will never apply cosmetic rules or DNR.

They’d like to know if you recommend enabling all the protections in the Security & Privacy options.
And for the colleague who uses Brave, do you recommend disabling the built-in anti-fingerprinting feature?

I could have replied to them myself, but you’re the developer, so you have more of a “say” than I do when it comes to your extension.;):)

Many thanks from Irene and Sandra.

P.S.

Keep in mind that my daughter and my colleague work as "Italian Chartered Accountant and Tax Advisor", so they often have to log in to government websites.;)
 
Last edited:
Great job, my friend. (y)(y)(y)
I have two questions from my daughter and her coworker, who use uBoL at work, and I advised them to switch from uBoL to uBol-stripped.

At work, my daughter uses Edge, which obviously has built-in privacy features similar to Firefox.
If I understand correctly, her coworker uses Brave with Ad-Shields disabled and fingerprinting enabled.
Keep in mind that they will never apply cosmetic rules or DNR.

They’d like to know if you recommend enabling all the protections in the Security & Privacy options.
And for the colleague who uses Brave, do you recommend disabling the built-in anti-fingerprinting feature?

I could have replied to them myself, but you’re the developer, so you have more of a “say” than I do when it comes to your extension.;):)

Many thanks from Irene and Sandra.

P.S.

Keep in mind that my daughter and my colleague work as "Italian Chartered Accountant and Tax Advisor", so they often have to log in to government websites.;)
No keep Brave fingerprinting enabled. There are a few known fingerprinting.js libraried which are hard (in terms of preventing website breakage) to block as extension which can be disarmed by the browser.

Yes those protections have a minimal chance of website breakage. That is the reason I moved some of the protections to Privacy Inspector.

Better PM me the websites and I make sure they are whitelisted (in next version) and keep it off until they are whitelisted.

Other members can do the same. I want to make it a seamles hardening mechanism.
 
when V5.4.4 (yes two minor things polished away) is available in the CWS, could someone tell Brummelchen on Wilders how stupid it is to have an opinion without factually checking the code
It's not worth the bother because he's a know-it-all.
 
Pushed 5.6 to CWS, no functional improvements over 5.4.4, but some funtional changes to reduce the size of what is injected on every page.

To implement AG scrjptlets in V5 I had to drop the smal´ chunks approach of uBol (which is more efficient than the big chunk approach of AG), found some optimizations to reduce it by 40% (uBol does that still smarter).

In future I can go back to uBol's way of doing it,but that has to be done in small steps (needs a lot of regression testing). For now I wanted to make the improved Privacy Inspector functionality (of 5.4.4) available with the safe optimizations (now already staying below the advice max of Google, so performance wise 5.6 fits the biĺl).

Hope 5.6 is available soon on Chrome webstore. 5.6 is on Github.
 
Okay new breakthrough while implementing @Sampei.Nihira whitelist request.
  1. I moved the Window name and Tab monitoring protections to Privacy Inspector
    These two protections have zero breakage risk on websites you don´t log in to. Added two new options in Privacy columns of Security & Privacy tab
  2. Added a confirmation to allow auto-creation of above two rules when users chooses Block All in Privacy Inspector
  3. Added an apply apply fingerprint protection to high risk websites (sames websites on which the hard noeval block is applied)
  4. Added a general allow rule for GOV websites for the extra Security * Privacy protections
Now all protections in Security & Privacy have a very low (near zero) breakage risk, so when the user conforms he/she is an advanced user, all protections are enabled.

While investigating easier and safer ways to change from large chunks (AG's simple and solid approach to facilitate scriptlets in user rules) to small chunks (uBO-lite efficient but complex way of doing it), I found another way to reduce size by another 25% percent. When discussing it with Claude AI, we came to the conclusion that for future compatibility with AG Mv3 it is better to keep large chunk approach (but now only 35% of size and half the size as adviced by Google to stay within soft adviced limits) and let's be honest, I am a former sales & marketing director who by accident was an IT-er for a few years some 40 years ago. So I am by far not the skilled programmer as mr Hill, meaning the benefits are so low, while risk (AG future compatibility and stepping on a code landmine) are so high, that I decided to keep on the big chunk track.

I think v6.0 is battle test ready (y)🏆:) hope it will land soon in CWS already available on github

So a lot of under hood improveents, this is all you notice from V6.0
1785053253333.png

1785053414165.png

1785053540662.png
 
Last edited:
@LinuxFan58

What do you mean by “battle test”?:unsure:
I obviously won't be participating.
I'm just curious.;)
Battle tested in the meaning that it takes some time for an extension to evolve and mature. I took until v5.4.4 to refactor uBO-lite code and implement AG functionlity. It is normal in IT to first get it right and then optimize. V6 is the optimized version of V5.0.3 so it is ready. Compare it with the second release of a car, it has only a few cosmetic changes, some functional extra's but has a lot of quality improvements (for reliability and maintenance ease). uBol-striped V6 is battle ready (can compte head to head with uBO-lite and AG Mv3)
 
Last edited:
  • Like
Reactions: LinuxFan58
I am afraid you have to wait a little longer (pushed 6.4 for review).
What is new in 6.4
- lot's of code optimizations (completed the refactoring and stepped on some code landmines along the way, hence he bump to 6.4 :-) )
- ran through to-do's and fix-me's in the original code, solved them where possible (link to uBO-lite issues)
- added a temporary pause filtering option like in AdGuard
- restructured Privacy Inspector and reporting in Custom rules manager

Reason to restructure Privacy Inspector is that I found out that some webistes apply counter measures against anti-fingerprinting. When you block WebGL 2D and Canvas fingerprinting in New York times, it does not show images anymore an does not throw a warning or error in the developer console (so it is done on purpose).


So I made some changes
  1. Make the anti-fingerprint protections harder to detect (many websites in below image have red markers and function normally)

  2. Made an assessment of the counter fingerprint measures applied and added risk scores to the anti-fingerprint measures itself (the red-yellow-green-grey dots in the custom rules manager picture below).

  3. Added an explanation and visual marker in the custom rules manager.
    For NY Times don´t use Block all, block all except graphics (WebGL and GPU-card) related stuff. As you can see, most websites have high risk ANTI-ANTI fingerprint indication, but don´t throw errors. This practice proofs that anti-fingerprinting is better suited for ON_DEMAND (like Privacy Inspector) than ALWAYS-ON (like JShelter).

    1785221355144.png



  4. Added a (disabled by default) legitimate signals category, which you can enable to see whether website is tracking you using signals which can´t be blocked because they have very high chance of website breakage.
    You can still block very high risk legitimate manually by looking at the drop down scroptlet rule explanation and add a scriptlet block rule for that website in ABP-import. This high usage threshold is set on purpose. A rule of thumb is never put breakage risk in easy to use GUI-automation's (like the block all), add a threshold, but allow power user CLI functionality (manually adding a scriptlet in ABP-import). This si also the reason you can able this signal only category.

    1785222252809.png

New popup with temp disable
1785221659418.png

Note: because of Mv3 restrictions disabling or pausing protection only works on NEWLY opened tabs/domains (a refresh does not remove he already applied rules)
 
Last edited:
I don't visit that site often, but when I do I use Firefoxes VPN. Is that a good habit?
Well it hides your VPN and depending on your VPN provider maybe more. I use VPN on demand when I am not at home and only for sensitive transactions (I am using Proton VPN free, so I don´t have the extra's which make surfing through a VPN harder to fingerprint).