[Bug] Default NS settings make some sites unusable

Bug reports and enhancement requests

[Bug] Default NS settings make some sites unusable

Postby iDrugoy » Fri Feb 10, 2012 11:54 pm

Read this.
Last edited by iDrugoy on Sat Feb 11, 2012 1:13 pm, edited 2 times in total.
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:13.0a1) Gecko/20120210 Firefox/13.0a1
iDrugoy
Senior Member
 
Posts: 80
Joined: Sun Feb 21, 2010 2:16 pm

Re: [Bug] NoScript (with any settings) makes 2 sites malfunc

Postby Giorgio Maone » Fri Feb 10, 2012 11:56 pm

URLs?
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0) Gecko/20100101 Firefox/10.0
User avatar
Giorgio Maone
Site Admin
 
Posts: 6832
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy

Re: [Bug] NoScript (with any settings) makes 2 sites malfunc

Postby iDrugoy » Fri Feb 10, 2012 11:58 pm

Another site that gets pwned by NoScript (even on a clean profile) is chat.nekto.me
1. you have to click this button:
Image
2. if you see there the following text:
Code: Select all
<p>Ошибка: </p>

then the site is not working.
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:13.0a1) Gecko/20120210 Firefox/13.0a1
iDrugoy
Senior Member
 
Posts: 80
Joined: Sun Feb 21, 2010 2:16 pm

Re: [Bug] NoScript (with any settings) makes 2 sites malfunc

Postby Giorgio Maone » Sat Feb 11, 2012 12:40 am

That's very strange, the problem goes away as soon as ABE is disabled (NoScript Options|Advanced|ABE), but no rule is triggered.
Investigating, thanks.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0) Gecko/20100101 Firefox/10.0
User avatar
Giorgio Maone
Site Admin
 
Posts: 6832
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy

Re: [Bug] NoScript (with any settings) makes 2 sites malfunc

Postby iDrugoy » Sat Feb 11, 2012 12:46 am

which one of 2 sites are you talking about?
actually that didn't resolve the issue for me for neither of them.
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:13.0a1) Gecko/20120210 Firefox/13.0a1
iDrugoy
Senior Member
 
Posts: 80
Joined: Sun Feb 21, 2010 2:16 pm

Re: [Bug] NoScript (with any settings) makes 2 sites malfunc

Postby iDrugoy » Sat Feb 11, 2012 12:56 am

this might help: site "chat.nekto.me" doesn't work if "donottrack" header is enabled.

edit: found NoScript's hidden pref "noscript.doNotTrack.enabled". Setting it to false makes this site work again.
Last edited by iDrugoy on Sat Feb 11, 2012 1:02 pm, edited 1 time in total.
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:13.0a1) Gecko/20120210 Firefox/13.0a1
iDrugoy
Senior Member
 
Posts: 80
Joined: Sun Feb 21, 2010 2:16 pm

Re: [Bug] NoScript (with any settings) makes 2 sites malfunc

Postby iDrugoy » Sat Feb 11, 2012 1:02 am

site http://thisissand.com/ also stops working, if http://www.google-analytics.com/ga.js gets blocked. By AdBlock+, for example.
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:13.0a1) Gecko/20120210 Firefox/13.0a1
iDrugoy
Senior Member
 
Posts: 80
Joined: Sun Feb 21, 2010 2:16 pm

Re: [Bug] NoScript (with any settings) makes 2 sites malfunc

Postby iDrugoy » Sat Feb 11, 2012 1:12 pm

To sum it up: both issues with each of the mentioned site got solved.
1. To make chat.nekto.me work - I had to turn a hidden NS "noscript.doNotTrack.enabled" pref to false. Actually, it shouldn't be true by default or should have an option somewhere in menu: not many users know of about:config page at all.

2. To make thisissand.com work for me - I just clicked "reset" button in NS. Now it works for me.

Thank you and I hope you either change default value for the mentioned pref to false, or add an option for it into the setting.
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:13.0a1) Gecko/20120210 Firefox/13.0a1
iDrugoy
Senior Member
 
Posts: 80
Joined: Sun Feb 21, 2010 2:16 pm

Re: [Bug] NoScript (with any settings) makes 2 sites malfunc

Postby Giorgio Maone » Sat Feb 11, 2012 9:18 pm

iDrugoy wrote:To sum it up: both issues with each of the mentioned site got solved.
1. To make chat.nekto.me work - I had to turn a hidden NS "noscript.doNotTrack.enabled" pref to false. Actually, it shouldn't be true by default or should have an option somewhere in menu: not many users know of about:config page at all.

Does the built-in Firefox DnT feature break this site as well?
[/quote]
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0) Gecko/20100101 Firefox/10.0
User avatar
Giorgio Maone
Site Admin
 
Posts: 6832
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy

Re: [Bug] Default NS settings make some sites unusable

Postby iDrugoy » Sun Feb 12, 2012 12:16 am

Yes.
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:13.0a1) Gecko/20120211 Firefox/13.0a1
iDrugoy
Senior Member
 
Posts: 80
Joined: Sun Feb 21, 2010 2:16 pm

Re: [Bug] Default NS settings make some sites unusable

Postby GµårÐïåñ » Mon Feb 13, 2012 9:59 pm

So this seems like bad coding to me where the site developers are insisting on getting this information or not providing you the services, not really an NS issue. It seems they are just overreaching and not accounting for those who may wish to not provide it. Sort of a take it or leave it kind of thing, so that should be a user choice and not a default allow choice as you suggested. I believe that NS is enforcing the best practice on this matter. After all, it is a security addon and designed to prevent such blatant intrusion, further supported by the fact that the built-in browser function limiting this nosy behavior also breaks the site. The site should either be more flexible or if you can't live without it, then you bend, but I don't believe NS should bend to the will of developers who insist on pushing this intrusion on their users.
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
[ Major's Blog ] .:. [ Security Pack ] .:. [ Productivity ]
Mozilla/5.0 (Windows NT 6.1; rv:10.0.1) Gecko/20100101 Firefox/10.0.1
User avatar
GµårÐïåñ
Lieutenant Colonel
 
Posts: 2820
Joined: Fri Mar 20, 2009 5:19 am
Location: PST - USA

Re: [Bug] Default NS settings make some sites unusable

Postby iDrugoy » Tue Feb 14, 2012 6:20 am

Agreed. Except the statement that DNT header improves security somehow. That's an illusion.
The whole idea of DNT is a mistake. You get zarro guaranties that site will respect your "please do not track me!" please.
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:13.0a1) Gecko/20120212 Firefox/13.0a1
iDrugoy
Senior Member
 
Posts: 80
Joined: Sun Feb 21, 2010 2:16 pm

Re: [Bug] Default NS settings make some sites unusable

Postby GµårÐïåñ » Tue Feb 14, 2012 11:04 pm

iDrugoy wrote:Agreed. Except the statement that DNT header improves security somehow. That's an illusion.
The whole idea of DNT is a mistake. You get zarro guaranties that site will respect your "please do not track me!" please.

I never said it does per se, afterall the fact that its there shows the industry has bent to the will of such providers as Google and other tagging services to provide geolocation.

However, that being said, it obviously had enough effect to render the site that wasn't willing to bend to stop functioning. If the site was able to somehow not respect that setting and force it to submit, it would have, no? So although I agree with you on the fact that the presence of this feature in the browser is asinine and we can only react to the implemented technology the best we can, it does have an effect, no matter how minor it might be.

Now simply saying DNT-me isn't always enough, if you actually disable the browser's Geolocation setting which remains active in Fx despite setting the DNT, THEN you will make whatever they MIGHT grab from you relatively useless. So if you push back ENOUGH, you CAN get improved security and I stand by that. If it was a useless feature, Giorgio wouldn't have wasted time with it. Everything has a reason, even if it is not immediately clear to everyone.
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
[ Major's Blog ] .:. [ Security Pack ] .:. [ Productivity ]
Mozilla/5.0 (Windows NT 6.1; rv:10.0.1) Gecko/20100101 Firefox/10.0.1
User avatar
GµårÐïåñ
Lieutenant Colonel
 
Posts: 2820
Joined: Fri Mar 20, 2009 5:19 am
Location: PST - USA


Return to NoScript Development

Who is online

Users browsing this forum: No registered users and 0 guests