With Google's new API, all ads can still be blocked. There will be a limit for network request blocking rules, but it's very high so that normal users don't reach it. And for those that reach it, only network requests are affected, so adblockers can still use other APIs to hide the ads.
> Hey all, I'm Simeon, the developer advocate for Chrome extensions. This morning I heard from the review team; they've approved the current draft so next publish should go through. Unfortunately it's the weekend, so most folks are out, but I'm planning to follow up with u/gorhill4 with more details once I have them.
Tavis Ormandy, who discovered the latest and several other Lastpass bugs, has these password manager recommendations:
"KeePass and KeePassX are both good choices. If you really must use an online one, at least LastPass are responsive to researchers and have a competent security team, I would use them."
Asked about the experience he had reporting a 1Password vulnerability, he says:
Password manager recommendations from Tavis Ormandy, who found the bug:
"KeePass and KeePassX are both good choices. If you really must use an online one, at least LastPass are responsive to researchers and have a competent security team, I would use them."
He adds about Lastpass:
"I consider them competent, I've reported some pretty complex issues and found they handle them well. Attack surface is definitely massive, I always recommend KeePass or just use a book if that's too complicated"
Google Chrome will now detect, if you have sync turned on, if your account is enrolled in Google's Advanced Protection Program (https://landing.google.com/advancedprotection/), and in case you are, give you stronger protection from malicious downloads.
The ZDNet article adds a lot of fluff around this, and weirdly calls the Advanced Protection Program "Gmail Advanced Protection Program".
Prediction: In a year, adblocking extensions on Chrome will still block the same percentage of ads from Google's networks as they do on Firefox. Care to make a bet?
Chrome security lead Justin Schuh says he is responsible:
"The sole motivation here is correcting major privacy and security deficiencies in the current system. I know, because I set that focus, and the team reports up through me."
"We are planning to raise these values but we won't have updated numbers until we can run performance tests to find a good upper bound that will work across all supported devices."