<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: evilpie</title><link>https://news.ycombinator.com/user?id=evilpie</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 27 Apr 2026 08:31:12 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=evilpie" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by evilpie in "Firefox Has Integrated Brave's Adblock Engine"]]></title><description><![CDATA[
<p>> The Firefox team is experimenting with ways to improve the built-in Enhanced Tracking Protection feature in Firefox. This is one of the libraries we're going to experiment with.<p>> - We are not, and have no plans to abandon MV2 extensions. This will ensure certain types of add-ons, like ad-blockers, continue to work best in Firefox.<p>> - Firefox supports several ad-blockers as add-ons on Desktop and Android, including uBlock Origin.<p>> - We are not bundling Brave's ad-blocking system, we're testing one of their open source Rust components to improve how Firefox processes tracker lists.<p><a href="https://www.reddit.com/r/firefox/comments/1sttf82/firefox_will_start_bundling_in_braves_adblock/oi1xklx/" rel="nofollow">https://www.reddit.com/r/firefox/comments/1sttf82/firefox_wi...</a><p>This is what the official Firefox account had to say when this came up on reddit.</p>
]]></description><pubDate>Sat, 25 Apr 2026 07:28:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=47899472</link><dc:creator>evilpie</dc:creator><comments>https://news.ycombinator.com/item?id=47899472</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47899472</guid></item><item><title><![CDATA[New comment by evilpie in "Making Firefox's right-click not suck with about:config"]]></title><description><![CDATA[
<p>Yes. It's in about:keyboard.</p>
]]></description><pubDate>Thu, 05 Mar 2026 11:43:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=47260502</link><dc:creator>evilpie</dc:creator><comments>https://news.ycombinator.com/item?id=47260502</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47260502</guid></item><item><title><![CDATA[New comment by evilpie in "Goodbye InnerHTML, Hello SetHTML: Stronger XSS Protection in Firefox 148"]]></title><description><![CDATA[
<p>You aren't reading it right.<p><pre><code>  new Sanitizer({})
</code></pre>
This Sanitizer will allow everything by default, but setHTML will still block elements/attributes that can lead to XSS.<p>You might want something like:<p><pre><code>  new Sanitizer({ replaceWithChildrenElements: ["h1"], elements: [], attributes: [] })
</code></pre>
This will replace <h1> elements with their children (i.e. text in this case), but disallow all other elements and attributes.</p>
]]></description><pubDate>Tue, 24 Feb 2026 17:25:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=47139847</link><dc:creator>evilpie</dc:creator><comments>https://news.ycombinator.com/item?id=47139847</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47139847</guid></item><item><title><![CDATA[New comment by evilpie in "Goodbye InnerHTML, Hello SetHTML: Stronger XSS Protection in Firefox 148"]]></title><description><![CDATA[
<p>Using an allowlist based Sanitizer you are definitely less likely to shoot yourself in the foot, but as long as you use setHTML you can't introduce XSS at least.</p>
]]></description><pubDate>Tue, 24 Feb 2026 14:47:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=47137824</link><dc:creator>evilpie</dc:creator><comments>https://news.ycombinator.com/item?id=47137824</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47137824</guid></item><item><title><![CDATA[New comment by evilpie in "Firefox 148 Launches with AI Kill Switch Feature and More Enhancements"]]></title><description><![CDATA[
<p>We made sure to exclude WebExtensions code from web pages's Trusted Types restrictions enforcement. (Bugs can happen of course)</p>
]]></description><pubDate>Tue, 24 Feb 2026 08:54:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=47134615</link><dc:creator>evilpie</dc:creator><comments>https://news.ycombinator.com/item?id=47134615</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47134615</guid></item><item><title><![CDATA[New comment by evilpie in "Element: setHTML() method"]]></title><description><![CDATA[
<p>If you want to use an XSS-unsafe Sanitizer you have to use setHTMLUnsafe.</p>
]]></description><pubDate>Wed, 22 Oct 2025 21:23:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=45675325</link><dc:creator>evilpie</dc:creator><comments>https://news.ycombinator.com/item?id=45675325</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45675325</guid></item><item><title><![CDATA[New comment by evilpie in "Element: setHTML() method"]]></title><description><![CDATA[
<p>We enabled this by default in Firefox Nightly (only) this week.</p>
]]></description><pubDate>Wed, 22 Oct 2025 20:51:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=45674985</link><dc:creator>evilpie</dc:creator><comments>https://news.ycombinator.com/item?id=45674985</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45674985</guid></item><item><title><![CDATA[Firefox Security and Privacy newsletter 2025 Q2]]></title><description><![CDATA[
<p>Article URL: <a href="https://attackanddefense.dev/2025/07/17/firefox-security-privacy-newsletter-2025-q2.html">https://attackanddefense.dev/2025/07/17/firefox-security-privacy-newsletter-2025-q2.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44592338">https://news.ycombinator.com/item?id=44592338</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 17 Jul 2025 12:00:07 +0000</pubDate><link>https://attackanddefense.dev/2025/07/17/firefox-security-privacy-newsletter-2025-q2.html</link><dc:creator>evilpie</dc:creator><comments>https://news.ycombinator.com/item?id=44592338</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44592338</guid></item><item><title><![CDATA[New comment by evilpie in "Firefox tab groups are here"]]></title><description><![CDATA[
<p>Make sure you have Firefox 138!
From the release notes:
> You can also now reposition a tab group on the tab bar by dragging it.</p>
]]></description><pubDate>Wed, 30 Apr 2025 07:41:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=43842284</link><dc:creator>evilpie</dc:creator><comments>https://news.ycombinator.com/item?id=43842284</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43842284</guid></item><item><title><![CDATA[New comment by evilpie in "Hardening the Firefox Front End with Content Security Policies"]]></title><description><![CDATA[
<p>Removing security headers like Content-Security-Policy is forbidden by the addons.mozilla.org policy.<p><a href="https://extensionworkshop.com/documentation/publish/add-on-policies/#development-practices" rel="nofollow">https://extensionworkshop.com/documentation/publish/add-on-p...</a></p>
]]></description><pubDate>Wed, 09 Apr 2025 11:31:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=43630991</link><dc:creator>evilpie</dc:creator><comments>https://news.ycombinator.com/item?id=43630991</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43630991</guid></item><item><title><![CDATA[New comment by evilpie in "Hardening the Firefox Front End with Content Security Policies"]]></title><description><![CDATA[
<p>While this is definitely annoying, most of the time this can be worked around by the extension without workarounds that themself weaken security.<p>For example I helped uBlock Origin out in 2022 when they ran into this: <a href="https://github.com/uBlockOrigin/uBlock-issues/issues/235#issuecomment-1344313926">https://github.com/uBlockOrigin/uBlock-issues/issues/235#iss...</a></p>
]]></description><pubDate>Wed, 09 Apr 2025 11:30:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=43630984</link><dc:creator>evilpie</dc:creator><comments>https://news.ycombinator.com/item?id=43630984</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43630984</guid></item><item><title><![CDATA[Hardening the Firefox Front End with Content Security Policies]]></title><description><![CDATA[
<p>Article URL: <a href="https://attackanddefense.dev/2025/04/09/hardening-the-firefox-frontend-with-content-security-policies.html">https://attackanddefense.dev/2025/04/09/hardening-the-firefox-frontend-with-content-security-policies.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=43630388">https://news.ycombinator.com/item?id=43630388</a></p>
<p>Points: 185</p>
<p># Comments: 68</p>
]]></description><pubDate>Wed, 09 Apr 2025 09:34:16 +0000</pubDate><link>https://attackanddefense.dev/2025/04/09/hardening-the-firefox-frontend-with-content-security-policies.html</link><dc:creator>evilpie</dc:creator><comments>https://news.ycombinator.com/item?id=43630388</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43630388</guid></item><item><title><![CDATA[New comment by evilpie in "Firefox tracks you with “privacy preserving” feature"]]></title><description><![CDATA[
<p>If it's disabled (greyed-out), then you already have telemetry disabled.</p>
]]></description><pubDate>Wed, 25 Sep 2024 07:46:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=41644817</link><dc:creator>evilpie</dc:creator><comments>https://news.ycombinator.com/item?id=41644817</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41644817</guid></item><item><title><![CDATA[New comment by evilpie in "Show HN: Tiny Chrome extension to disable images to reduce distractions"]]></title><description><![CDATA[
<p>Firefox also has the about:config preference permissions.default.image: 2, which will block most images.</p>
]]></description><pubDate>Sat, 01 Jun 2024 22:24:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=40549602</link><dc:creator>evilpie</dc:creator><comments>https://news.ycombinator.com/item?id=40549602</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40549602</guid></item><item><title><![CDATA[New comment by evilpie in "Cross My Heart – A Frogger Demake in 256 Bytes of HTML/JS"]]></title><description><![CDATA[
<p>The profile actually shows the freeze is not caused by normal JS garbage collection, but by cycle collection. So probably something related to DOM nodes.</p>
]]></description><pubDate>Sun, 11 Feb 2024 21:26:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=39338896</link><dc:creator>evilpie</dc:creator><comments>https://news.ycombinator.com/item?id=39338896</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39338896</guid></item><item><title><![CDATA[New comment by evilpie in "Flashpoint Archive"]]></title><description><![CDATA[
<p>See also <a href="https://ooooooooo.ooo/" rel="nofollow">https://ooooooooo.ooo/</a>.
"9o3o is an official (but experimental) online version of the Flashpoint Archive."</p>
]]></description><pubDate>Thu, 04 Jan 2024 12:03:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=38865964</link><dc:creator>evilpie</dc:creator><comments>https://news.ycombinator.com/item?id=38865964</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38865964</guid></item><item><title><![CDATA[New comment by evilpie in "Fritzbox: AVM is threatened with a sales ban due to violations of Huawei patents"]]></title><description><![CDATA[
<p><a href="https://www.pcgameshardware.de/Internet-Thema-34041/News/AVM-Fritzbox-Verbot-wegen-Verstoss-gegen-WLAN-Patente-1436400/" rel="nofollow noreferrer">https://www.pcgameshardware.de/Internet-Thema-34041/News/AVM...</a><p>Also one of the headings was mistranslated horribly.<p>In linked the article: "AVM threatens to ban the sale of Fritzbox routers".
The original in German: "AVM droht Verkaufsverbot für Fritzbox-Router".
Right translation is roughly: "AVM is threatened with a ban on the sale of Fritzbox routers".</p>
]]></description><pubDate>Mon, 18 Dec 2023 12:44:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=38681673</link><dc:creator>evilpie</dc:creator><comments>https://news.ycombinator.com/item?id=38681673</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38681673</guid></item><item><title><![CDATA[New comment by evilpie in "Half-Life: 25th Anniversary Documentary [video]"]]></title><description><![CDATA[
<p>See also Dario Casali's Half Life 25yr anniversary playthrough: <a href="https://www.youtube.com/playlist?list=PLk5gaNp4x_AVIJviyHueHizonrIhAAtdj" rel="nofollow noreferrer">https://www.youtube.com/playlist?list=PLk5gaNp4x_AVIJviyHueH...</a></p>
]]></description><pubDate>Tue, 28 Nov 2023 13:21:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=38445400</link><dc:creator>evilpie</dc:creator><comments>https://news.ycombinator.com/item?id=38445400</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38445400</guid></item><item><title><![CDATA[New comment by evilpie in "Firefox desktop extensions coming soon for the upcoming Android release"]]></title><description><![CDATA[
<p>Igalia is regularly contracted to work on new Firefox features, so this is already happening.</p>
]]></description><pubDate>Fri, 11 Aug 2023 09:36:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=37086786</link><dc:creator>evilpie</dc:creator><comments>https://news.ycombinator.com/item?id=37086786</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37086786</guid></item><item><title><![CDATA[New comment by evilpie in "Firefox 115 Now Available with Intel GPU Video Decoding on Linux"]]></title><description><![CDATA[
<p>[deleted because I don't to be accused for ragebaiting]</p>
]]></description><pubDate>Tue, 04 Jul 2023 15:01:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=36587587</link><dc:creator>evilpie</dc:creator><comments>https://news.ycombinator.com/item?id=36587587</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36587587</guid></item></channel></rss>