by libove » Wed Feb 24, 2016 6:16 am
barbaz wrote:I'm guessing you might end to see some messages from NoScript XSS in the Browser Console (Ctrl-Shift-J) when the hang occurs. Or that it doesn't happen if you disable the XSS filter.
If I'm right it's all the more reason that you're doing the right thing by contacting them how you are, because that crosses the line from a privacy issue to a security issue.
I reproduced the hang, with the Browser Console open. Nothing about NoScript XSS at all. In fact, the messages in the Console are the same with and without the hang (except of course that, with www.bancsabadell.com allowed in NoScript, bancsabadell.com and datalog.bancsabadell.com not allowed, Firefox doesn't hang and more messages appear in the Console as I navigate farther through the site).
So, maybe this is completely different than the other/XSS related issue.
[quote="barbaz"]I'm guessing you might end to see some messages from NoScript XSS in the Browser Console (Ctrl-Shift-J) when the hang occurs. Or that it doesn't happen if you disable the XSS filter.
If I'm right it's all the more reason that you're doing the right thing by contacting them how you are, because that crosses the line from a privacy issue to a security issue.[/quote]
I reproduced the hang, with the Browser Console open. Nothing about NoScript XSS at all. In fact, the messages in the Console are the same with and without the hang (except of course that, with www.bancsabadell.com allowed in NoScript, bancsabadell.com and datalog.bancsabadell.com not allowed, Firefox doesn't hang and more messages appear in the Console as I navigate farther through the site).
So, maybe this is completely different than the other/XSS related issue.