Need a Reason to Drop Google Chrome?

Google is planning to restrict modern ad blocking Chrome extensions to enterprise users only. This is despite a backlash to an announcement by Google in January proposing changes that will stop certain ad blockers from working efficiently.

The proposal–dubbed Manifest V3–will see a major transformation to Chrome extensions that includes a revamp of the permissions system. It will mean modern ad blockers such as uBlock Origin—which uses Chrome’s webRequest API to block ads before they’re downloaded–won’t work. This is because Manifest V3 sees Google halt the webRequest API’s ability to block a particular request before it’s loaded.

A single sentence buried in the text of Google’s response to the complaints, which clarified the changes: “Chrome is deprecating the blocking capabilities of the webRequest API in Manifest V3, not the entire webRequest API (though blocking will still be available to enterprise deployments).”

In other words, paid enterprise-only users will still have the ability to block unwanted content. It probably means enterprise customers can develop in-house Chrome extensions, not for ad blocking use. For everyone else, the changes announced in January will remain the same.

It’s annoying, to say the least, but the reason for these changes is obvious: Ads are at the heart of Google’s business model.

There are many users who won’t use Chrome without an ad blocker, so it will see some switch to other providers such as Firefox. However, Firefox has had its own issues over recent weeks.

So, now might be the time to switch to another browser, such as Brave. Brave is built upon Chromium so all existing Chrome plugins and even themes work on it and reduces your digital footprint, protecting your privacy.

Another option is using DNS level methods that blacklists adverts as well as malicious URLs.

Safe and Ad Free Browsing

Ever since my bad experience with Facebook and their other products, I have been working on ways to minimize my digital footprint. I moved over to other social media sites that have no ads and don’t ask or use your private information. With the demise of Google Plus in April (2019), I decided that it was the perfect opportunity to research and move to other products that decrease my digital footprint and at least work to safe guard my web browsing. This is a living post, per-se, that I will be maintaining with new and updated information.

Ad Free DNS

AdGuard DNS is a free Domain Name System service provided by the AdGuard company. You can use this DNS service to block advertising and trackers. It works like this: when a website sends a request to an ad network, the DNS sends back a “null” response. For example, when a web page looks up the domain name “ads.facebook.com” the DNS will not find that name. This means all networks request are never loaded — this is the most efficient way to block them. This blocking may even speed up your web browser slightly.

Besides blocking advertising, AdGuard DNS will also blocks trackers and malware phishing sites.

Default Ad-Blocking DNS

Use these servers to block ads, tracking and phishing:

  • 176.103.130.130
  • 176.103.130.131

Or use IPv6 addresses:

  • 2a00:5a60::ad1:0ff
  • 2a00:5a60::ad2:0ff

Family Protection DNS

Default + blocking adult (porn) websites + safe search:

  • 176.103.130.132
  • 176.103.130.134

Or use IPv6 addresses

  • 2a00:5a60::bad1:0ff
  • 2a00:5a60::bad2:0ff

For more information on AdGuard DNS, click here.

Web Browsers

Your web browser knows a lot about you, and tells the sites you visit a lot about you as well—if you let it. I have been testing out a number of browsers that specifically caters to those that want safer browsing experience and free of most ads.

Brave Browser

Here is one that I have been using for a while and it works pretty well, when used with the AdGuard DNS protection.

Brave is the latest unique browser to join the ever-expanding market. The open source and free browser from Brave Software Inc. has positioned itself as the browser that loads faster with better privacy protection. The firm was co-founded by Brendan Eich, the creator of JavaScript and a co-founder of Mozilla. Brave keeps data safe and provides users with the power to save or delete it. It features a built-in ad tracker and blocker. Unlike most common browsers, Brave also helps to fight phishing and malware.

Brave blocks ads automatically. Users are no longer required to search the web for a perfect ad blocker. The auto-blocking protects your device from malware and extensive tracking by advertisers. Brave is also working on a plan to replace ads that appear harmful.

Tracking ads by Brave is accurate. Users are served with the right ads because Brave does the tracking using local data. If an ad is irrelevant to the user, it is pulled down. You get the appropriate ads based on this model. A user’s data stays within the device since they have no third parties involved.

While Brave blocks third-party cookies, the first party cookies are not blocked by default. Users have the option to prevent or enable cookies on a given website.

However, Brave does not block ads displayed in search results. You will be able to see AdWords advertisements within Google’s results. This is because Ad blocking extensions don’t stymie search ads either.

Blocking of malicious ads automatically allows safe browsing. Brave does not have access to identifiable user data. The anonymity aggregated ad campaign related data is used for accounting. However, this data cannot be traced back to a user’s device.

Brave also comes with additional tactics to boost privacy while browsing. The incorporation of HTTPS everywhere allows usage of web encryption whenever available.

The fingerprinting feature bars third parties from tracking your activity. This feature can be activated in the settings tab.

Brave offers a clean and crisp interface that is intuitive to use. It has all the elements you would expect in your ideal browser. Furthermore, Brave’s individual tabs sport icons for quick identification, and hovering the cursor over a tab offers details on the page in that tab without having to click on the tab and activate it.

The browser also displays statistics about the content the browser has blocked. These statistics are very useful. Furthermore, it displays photos, the current time and shortcuts to your favorite sites. Like other websites, one would expect these features to have an effect on speed. However, this is not the case. Brave is very easy to use, with a streamlined design and the useful option to preview the content of tabs.

Brave’s load speeds emerge on top. The fast browsing is supported by Brave’s lack of thirds party ads. You, therefore, have less content to download before accessing your favorite website. However, Brave’s rendering speeds come a bit after Google Chrome and Mozilla.

Brave is set up on the Chromium platform. Chromium is an open-source system that also powers popular browsers like Google Chrome and soon Microsoft Edge. Based on the Chromium capability, you can almost use all Chrome extensions on Brave. The extensions on Chrome can be added to Brave through the Chrome Web Store.

For more information and downloads, click here.

No More Ads

I have disabled the ads on VA3DBJ.ca, as they were not beneficial at all and I have started to push for an ad free environment. I have also decreased the amount of personal tracing as well, to only those that would benefit you and the operation of the site.

I have also limited some tracking, with the exception of the Google reCAPTCHA function for the Contact Us section and twitter tracking for the tweeting of the VA3DBJ hourly weather reports and warnings.

I have limited the amount of SEO tracking as well, allowing just enough tracking so that pages can be re-posted to social media accounts.

I have also enabled GDPR to meet the new European Union requirements.

A Powerful Spyware App Now Targets iPhone Owners

Security researchers have discovered a powerful surveillance app first designed for Android devices can now target victims with iPhones.

The spy app, found by researchers at mobile security firm Lookout, said its developer abused their Apple-issued enterprise certificates to bypass the tech giant’s app store to infect unsuspecting victims.

The disguised carrier assistance app once installed can silently grab a victim’s contacts, audio recordings, photos, videos and other device information — including their real-time location data. It can be remotely triggered to listen in on people’s conversations, the researchers found. Although there was no data to show who might have been targeted, the researchers noted that the malicious app was served from fake sites purporting to be cell carriers in Italy and Turkmenistan.

Researchers linked the app to the makers of a previously discovered Android app, developed by the same Italian surveillance app maker Connexxa, known to be in use by the Italian authorities.

The Android app, dubbed Exodus, ensnared hundreds of victims — either by installing it or having it installed. Exodus had a larger feature set and expanded spying capabilities by downloading an additional exploit designed to gain root access to the device, giving the app near complete access to a device’s data, including emails, cellular data, Wi-Fi passwords and more, according to Security Without Borders.

For more information, click here.

Sun Sets on Google Plus

On February 1st, I received the official email from Google, that Google Plus will be turned off on April 2nd. I have been messing around with a couple of replacements, of sorts, and have been hanging out at the MeWe and Pluspora sites.

They have pretty much replace both Google+ and Facebook. MeWe has been my tech related replacement and Pluspora, for my photography. Below are my links and a short copy of the Google notice on Google+.

https://www.mewe.com/i/va3dbj
https://pluspora.com/people/c67b3320b1310136206800505608f9fe

In December 2018, we announced our decision to shut down Google+ for consumers in April 2019 due to low usage and challenges involved in maintaining a successful product that meets consumers’ expectations. We want to thank you for being part of Google+ and provide next steps, including how to download your photos and other content.

On April 2nd, your Google+ account and any Google+ pages you created will be shut down and we will begin deleting content from consumer Google+ accounts. Photos and videos from Google+ in your Album Archive and your Google+ pages will also be deleted. You can download and save your content, just make sure to do so before April. Note that photos and videos backed up in Google Photos will not be deleted.

The process of deleting content from consumer Google+ accounts, Google+ Pages, and Album Archive will take a few months, and content may remain through this time. For example, users may still see parts of their Google+ account via activity log and some consumer Google+ content may remain visible to G Suite users until consumer Google+ is deleted.

As early as February 4th, you will no longer be able to create new Google+ profiles, pages, communities or events.

See the full FAQ for more details and updates leading up to the shutdown.


Huge CenturyLink Outage Caused by Bad Networking Card in Colorado

A widespread outage on CenturyLink’s cloud network that lasted almost two days and hampered emergency phone service in Washington and other states was caused by a faulty network management card, according to a customer notice.

Brian Krebs, a veteran security journalist, posted a copy of a notice sent to CenturyLink’s “core customers” to his Twitter feed Saturday that blamed a card at its data center in Colorado for “propagating invalid frame packets across devices,” causing a series of issues that forced the company to reboot much of its networking equipment. It took CenturyLink more than two days from when it first identified the issues to sound the all-clear on Saturday morning, a period during which 911 services in several states including Washington were down or spotty.

For full article, click here.

November 28, 2018 Public Awareness Test

On November 28th at 1:55 PM local time (2:55 PM local time in Quebec), a test of the Alert Ready system will be conducted. The test will be distributed on TV, radio and compatible wireless devices. Please note, not all mobile devices will receive the test message. For general device compatibility, you can refer to the Alert Ready website here. We recommend that you contact your wireless service provider with specific inquiries regarding public alerting services and device compatibility. Your provider will be best able to answer specific compatibility questions.

A Day of Remembrance

The Ode of Remembrance

They went with songs to the battle, they were young. 
Straight of limb, true of eyes, steady and aglow. 
They were staunch to the end against odds uncounted, 
They fell with their faces to the foe. 
They shall grow not old, as we that are left grow old: 
Age shall not weary them, nor the years condemn. 
At the going down of the sun and in the morning, 
We will remember them.


Lest we Forget

Facebook – I Quit

Well after some thought, I shutdown my Facebook page.  There were a few reasons why I did, but the main reason was the invasion of privacy.  It wasn’t the increased BS, the fake news and the political crap, it ended up being that Facebook was monitoring my private text messages with my family and friends.

When I first joined, the conditions you had to agree too to install the app was very basic, kind’a, but it didn’t monitor your private messages. But along the way, they added the ability to monitor private messages, but did not notify you as such.  Only if you deleted the app and reinstalled, or re-read the conditions, would you have known.

Either way, I felt, that not having the option to turn off specific access to a service or app on my phone, was a little too much, after all these years.

Taking a few weeks and actually paid attention to what I was reading and seeing what interaction I was having with my family and friends, I decided that it was time.

I had investigated other social platforms that allowed me to carry on my photography, communications and computing hobbies and found a couple of new ones that focused on security and minimal amount of personal information that is handed over.

Pluspora, a side group, or pod, of diaspora* software. A group that focus’s on 3 main ideas. Decentralised servers, the freedom to post what you want and how much of you you want to release and privacy.  You own your data.

Another platform that has a mantra of “No Ads. No Spyware. No BS.” is MeWe.  MeWe has the Google+ feel to it, and that is why a lot of people have been migrating to it, since the Google+ shutdown was announced.

Both platforms are working hard on getting the former Google Plusers and attracting Facebook users to convert over.  I am now using Pluspora and Twitter as my main platforms, with MeWe and Tumblr as my home away from home sites. You can follow me at:

Google to shut down Google+

The Guardian – Google to shut down Google+ after failing to disclose user data leak.

Company didn’t disclose leak for months to avoid a public relations headache and potential regulatory enforcement.

This March, as Facebook was coming under global scrutiny over the harvesting of personal data for Cambridge Analytica, Google discovered a skeleton in its own closet: a bug in the API for Google+ had been allowing third-party app developers to access the data not just of users who had granted permission, but of their friends.

If that sounds familiar, it’s because it’s almost exactly the scenario that got Mark Zuckerberg dragged in front of the US Congress. The parallel was not lost on Google, and the company chose not to disclose the data leak, the Wall Street Journal revealed Monday, in order to avoid the public relations headache and potential regulatory enforcement.

Disclosure will likely result “in us coming into the spotlight alongside or even instead of Facebook despite having stayed under the radar throughout the Cambridge Analytica scandal”, Google policy and legal officials wrote in a memo obtained by the Journal. It “almost guarantees Sundar will testify before Congress”, the memo said, referring to the company’s CEO, Sundar Pichai. The disclosure would also invite “immediate regulatory interest”.

Shortly after the story was published, Google announced that it will shut down consumer access to Google+ and improve privacy protections for third-party applications.

In a blog post about the shutdown, Google disclosed the data leak, which it said potentially affected up to 500,000 accounts. Up to 438 different third-party applications may have had access to private information due to the bug, but Google apparently has no way of knowing whether they did because it only maintains logs of API use for two weeks.

“We found no evidence that any developer was aware of this bug, or abusing the API, and we found no evidence that any profile data was misused,” Ben Smith, the vice-president of engineering, wrote in the blogpost.

Smith defended the decision not to disclose the leak, writing: “Whenever user data may have been affected, we go beyond our legal requirements and apply several criteria focused on our users in determining whether to provide notice.”

None of the thresholds for public disclosure were met, Smith said. 

There is no federal law that obliges Google to disclose data leaks, but there are laws at a state level. In California, where Google is headquartered, companies are only required to disclose a data leak if it includes both an individual’s name and their Social Security number, ID card or driver’s license number, license plate, medical information or health insurance information.

Google also announced a series of reforms to its privacy policies designed to give users more control on the amount of data they share with third-party app developers.

Users will now be able to have more “fine grained” control over the various aspects of their Google accounts that they grant to third-parties (ie calendar entries v Gmail), and Google will further limit third-parties’ access to email, SMS, contacts and phone logs.

David Carroll is a US professor who sued Cambridge Analytica earlier this year to find out what data the company had stored about him. He said that given the legal issues Facebook faces over its Cambridge Analytica cover-up, it’s not surprising Google tried to keep the leak out of the public eye.

“Google is right to be concerned and the shutdown of Google+ shows how disposable things really are in the face of accountability,” he said.

For others, the leak was further evidence that the large technology platforms need more regulatory oversight.

“Monopolistic internet platforms like Google and Facebook are probably ‘too big to secure’ and are certainly ‘too big to trust’ blindly,” said Jeff Hauser, from the Centre for Economic and Policy Research.

He argued that the US Federal Trade Commission should move toward “breaking these platforms up”.

“In the interim, since we cannot trust that we know much or even most of what ought to concern the public, the FTC should install public-minded privacy monitors into the firms as an element of accountability.”