Hot Take uBlock Stripped - Dynamic Filtering is available on the webstore

Mhh, Vivaldi on older (150), Chrome on 152 and both Edge and Brave on 151, so that kills the Chrome version hypothesis

Pushed V8.6.2 to Chrome Webstore

Changes
1. Cosmetic element picker closes again automatically
2. Solved a bug which made the Cosmetic element picker to respond slow (not starting), same bug for Cookie consent clicker
3. Changed the text in Filter (block) lists to make it clear users can also enable/disable these options
4. Added a download protection which works along side (but seperately) to the 3P-script and frame block for "non-Western world Top Level Domains"

1787843620259.png


Please check your setup after update, adding a notification woud require an additional permission, so I dropped that.

When you enable the TLD filter rules (third and fourth of the listed Worry-free protections) ChatGPT assesses

1787844719788.png


But the benefit is big according to AI (when I asked ChatGPT to lookup actual numbers)
1787844875220.png

Note one (the first) of the extra Security & Privacy protections which are enabled specifically targets malware-hosting domains.

Bottom line enabling the TLD-protections (3P-code and download) halves the attack surface while 80-90% is still usuable (that is the smart idea behind Easy Medium often promoted by @Jan Willy)


When a website might break, use the Dynamic DNR filtering option (move switch to show blocked)
(NBC is just an example, it works fine in wory-free safe surfing mode)
1787845013498.png
 
Last edited:
Version 8.6.2. In Worry-free safe surfing mode dismiss cookie-consent prompts doesn't always work. F.i. on nrc.nl and on volkskrant.nl. But o.k. on trouw.nl. (I didn't test more sites). In those cases of course I use Cookie consent klicker. It might be practical to add this option to the browsers context menu, similar to Cosmetic element picker.
 
Version 8.6.2. In Worry-free safe surfing mode dismiss cookie-consent prompts doesn't always work. F.i. on nrc.nl and on volkskrant.nl. But o.k. on trouw.nl. (I didn't test more sites). In those cases of course I use Cookie consent klicker. It might be practical to add this option to the browsers context menu, similar to Cosmetic element picker.
Good suggestion thanks

Shall I add Dynamic DNR filtering and Privacy Inspector to?
(y)
 
Bottom line enabling the TLD-protections (3P-code and download) halves the attack surface while 80-90% is still usuable (that is the smart idea behind Easy Medium often promoted by @Jan Willy)
Of course I never realized that and even didn't intend. My goal was and is to use a practical way to block third party scripts and iframes (3P-code). So not directed to domains but to questionable third party (3p) resource types. Excluding often used TLD's prevents breakage, but (from the perspective of privacy) suspicious 3p trackers (linked at a 'trusted' TLD) can slip through. To fill this gap filterlists enter the game. A large list isn't necessary anymore. IMO is Kees1958 most used advertising & tracking networks list, enough. It can be useful to add other lists for other purposes. Besides that I use Hagezi-Multi Light on NextDNS.
 
Last edited:
Submitted to versionn 8.6.4 to the chrome store

Changelog
- updated filter lists
- added context menu items (see pic)
- added NEW CMP decline handler for DPG media (Nu.nl, Volkskrant.nl, AD.nl etc)
- checked OLD CMP decline handler for MediaHous (NRC Telegraag etc),
@Jan Willy whn I enter the commands in the console (dev tools) it works, so can't reproduce or find it


At the moment applying 45 Cookie Management Platform decline handlers




1787856611292.png
 
Last edited:
Everyone, thank you for the likes, but I spoke too soon. Got another e-mail, and again I had to temporarily disable uBlock-Stripped. :(
You could disable the Security & Privacy protections on the tab, but enable them in Worry-free mode. Stop worry-free mode when you check your emails.


Wow now over 300 users :-) of uBlock Stripped.
 
Last edited:
Version 8.6.6 is available at the Chrome Web Store

@Jan Willy after some days of testing with worry enabled on startup
I already had collected list of websites where I disabled my adblocker (60 domains) over the years, combined with the automated login using Cookie-consen-clicker, I could do all normal work related stuff from home. So I suppose my allow list and the internal whitelist copied from 3P-Matrix-lite for critical resources works well enough together to use worry-free-safe-surfing all the time. Good instinct to keep pushing for always on option, I was probably to conservative in regard to the fear of website breakage,

There is one situation I have not tried (one student did a re-examine which I reviewed on-line) I did not dare try yet (because it is so much work when it goes wrong), where one one-line application passes the results and my credentials to another web application. Off course this pass hand-over should have been build using an API, but many educational software is written using bad principles (e,g passing credentials through cookies what nobody in his right mind would do today anymore).

@Gandalf_The_Grey I remember you asked for an Edge version, I will have a look at the developer requirements when I am commuting in the train again on the way back from university to home. Question I remember (but not sure about it), you used I-don´t-care-about-cookies. Have your tried the new worry-free mode when you are still using uBlock-stripped?
 
It's hard to keep up, but I'll try my best. Wait, why did that sound dirty? Any hoozle, 8.6.6 seems to run fine on Vivaldi stable. All I need to do now is find out what's preventing ESPNs gamecast from auto-refreshing.
 
  • Like
Reactions: simmerskool
When we're talking about easy medium mode, we shouldn't forget the initiator who started these two threads:
Guess who he is. All credits to him.
 
Last edited:
Version 8.6.6: cookie consent banner didn't show up on nrc.nl, but again on volkskrant.nl (after closing tabs, restarting Brave and opening pages).
At the moment there are tseveral ways of bypassing CMP's
  1. using CMP's own API's = 100% succes and generic applicable
  2. using user click emulation = works well for single clicks on websites which don´t combine with anti-adblock counter measures, for anti-adblock counter measures using generic heuristics in combination with scriptlets, also generic applicable with a succesrate of 60%
  3. website specific trusted-cookie, trusted-click scriptlets which have a high succesrate, only websites change underlying identifiers regularly (uBo has a rule for DPG media websites, but it only works half of the time)
  4. website specific combination of blocking and hiding using a combo of netwerk rules, procedural and cosmetic hiding rules, succesrate depends on the time and dedication a rule writer is willing to invest in a single website. These rules also have some aging, but on average less lower change rate than teh websites needing trusted scriptlets, because (as a general rule) when the bypass requires less sophisticated tricks, the counter measures of these websites is usually are (as a rule of thumb) also of less complexity/sophistication.
I like to target the infrastructure behind annoyances in stead of chasing individual websites, so I decided to add an option in Worry-free safe surfing mode (in Filter blocklist panel) which states "Fall back to accept cookies simulation for troublesome Cookie Management Platforms". When the user enables this, the worry-free mode will click allow instead of decline cookies in worry-free mode, so I leave it up to the user to either accept annoyance for a website or accept cookies being allowed automatically.

When is a CMP troublesome? Answer is four unsuccessful heuristics applications gets the CMP a free run. DPG media is the first which will get the new (allow or ignore) treatment.
 
Last edited:
My problem with Gmail at the moment may not be linked to uBlock-Stripped or just Vivaldi. I just tried it in Firefox 3 times. And the first two times the e-mails I got came back again, and only on the third time did they stay deleted. And I am using uBlock Origin in Firefox, so that makes it even more weird. :unsure:
 
Before I tell you about V 9.0 and before you start complaining about less is more, I have to provide some info on uBO-Lite first (hoping you won´t start critiquing me for adding some 50 cheap efficient DNR rules in total).:cool:


What is added with the block popup feature of uBO-lite?
When you install uBO-lite and enable development and open the development tab and select session rules, you will notice that it shows 790 rules
1787928086674.png

Those 790 rules are expensive (in terms of CPU load) regexSubstitions for a redirect (that hurts double)!!!



What is new in uBlock Stripped V9.0 ?
I already explained you that Peter Lowś 3500+ oldschool hostfile rules translate into 1 DNR rule (using block requestDomains). The impact of the in v 8 introduced extra filterblocklists is minimal (39000 3P and host blockrules, translate into 40 DNR rules).

So I did a simple test and added (yes) the advertising and tracking categories of both Disconnect and Ghostery (mentioning them as 3P in my license). And because this added some simple DNR rules, I optimized the rule organisation futher (that is why they can't be excluded) and did a test, Then i repeated the test. Then I did some research asking myself am I doing something wrong? After another test with other than expected outcome, I installed uBO-lite and found above explanation.

A you can see, I still mention that uBlock Stripped offers almost all AdGuard Mv3 functionality (e.g. no popup or popunder and no scriptlets requiring trust), but it now state that yBlock stripped does this extra's with the uBO-lite speed (yes I dropped the NEAR and the with uBO-speed might even be a bit to humble :-) )

1787929265899.png


The apply accept is a works in progress, it does not work correctly yet!
 
Last edited:
Version 9.0.0: First impression: You solved the cookie consent banner problem on volkskrant.nl. Nevertheless when visiting bol.com and ah.nl those banners showed up, on telegraaf.nl, lc.nl and meppelercourant.nl the banner only flashed (didn't try it before on those sites). As usual, I tested in separate Brave-profile with disabled Shields and no further extensions.

Edited 1: In Filter (block) lists you make clear that 'Worry-free safe surfing tries to dismiss cookie-consent prompts ...' So we should not expect it's always successful. I doubt if ever a 100% score could be reached. The lifesaver is of course Cookie consent klicker.

Edited 2: I consider to stop testing cookie consent notices blocking.
 
Last edited:
Version 8.6.6 is available at the Chrome Web Store

@Gandalf_The_Grey I remember you asked for an Edge version, I will have a look at the developer requirements when I am commuting in the train again on the way back from university to home. Question I remember (but not sure about it), you used I-don´t-care-about-cookies. Have your tried the new worry-free mode when you are still using uBlock-stripped?
I-don´t-care-about-cookies was a very long time ago, recently I did use consent-o-matic.
Unfortunately, I did not have the time yet to play around with the worry-free mode.
I did not like the first versions of uBlock-stripped because of the lack of cosmetic filtering.
Will try again this weekend (y)
 
@Jan Willy thanks for all your work, I am looking further into DPG Media, for some reason it is very stubborn. The cookie consent is matured enough. There is only one use case (DPG Media) I have to work out.

@Gandalf_The_Grey it now processes everything of AdGuardMv3 or uBoMv2, except scriptlets requiring trust (are not needed anyway because of alternative cookie consent apprpach with worry-free and cookie-consent-clicker) amd popup/popunder. I recently researched popup-popunder and in the cleaned up AdGuard Base (so dropping rules not for 5eyes and EU+ and not in top 1 MIO websites) there were only 3 rules in AdGuard Base optimized of August 27 version. Two of them were badfilter rules (so removing them) of websites I dropped!!! Also because the extra Security & Privacy rules, the 'block alert spam' and 'block confirm prompt and dialog spam' would tackle the security related occurance of blocking $popup and $popunder, so I decided those were not nessecary either.

As you can see through all optimizations, the size of uBlock Stripped shrank from 2/3 of uBOL to just over 1/3 of uBOL
1787992399461.png
 
That's not quite right.
It's not just scriptlets that require reliability that are rejected.

Some are rejected due to unknown parameters.:unsure:
Others are likely rejected due to incorrect syntax or syntax not present in AG/uBoL.:unsure:
Still others are rejected due to functionality issues,for example, the AELD function isn’t available in AG.


So for users like me, it would be quite complicated to copy and paste all my rules (103) from uBo and transfer them seamlessly to other ad-blockers.
In uBo, I use only 1 rule that requires reliability.

But I’m an “anomaly”........for “normal” users, there won’t be any problems.(y);)
 
  • Like
Reactions: Jan Willy