+ Built-in force HTTPS list, seeded with www.youtube.com

Ask for help about NoScript, no registration needed to post
Thencent
Posts: 3
Joined: Sat Dec 06, 2014 3:44 pm

+ Built-in force HTTPS list, seeded with www.youtube.com

Post by Thencent »

v 2.6.9.6 introduces:
+ Built-in force HTTPS list, seeded with www.youtube.com

I found this item interesting and have a few questions ...

- do you plan to expand upon the built-in list such that NoScript would be closer to covering the functionality of HTTPS Everywhere?
- why is youtube.com the first domain added to this list?
- is there a way for users to disable the built-in list, if it's functionality is redundant to addons like HTTPS Everywhere?
Mozilla/5.0 (X11; Linux x86_64; rv:34.0) Gecko/20100101 Firefox/34.0
User avatar
Giorgio Maone
Site Admin
Posts: 9454
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: + Built-in force HTTPS list, seeded with www.youtube.com

Post by Giorgio Maone »

Thencent wrote: - do you plan to expand upon the built-in list such that NoScript would be closer to covering the functionality of HTTPS Everywhere?
No, I don't. I'm gonna use it to fix blatant incompatibilities.
Even more so since the major websites are pushing HSTS, which makes client-side forcing for security reasons progressively redundant.
Thencent wrote: - why is youtube.com the first domain added to this list?
Because doing so fixed an embedding activation compatibility problem.
Thencent wrote: - is there a way for users to disable the built-in list, if it's functionality is redundant to addons like HTTPS Everywhere?
You can just edit it like any other about:config preference: once you set it to a value different than its default (e.g. an empty string), NoScript updates won't change it (until you eventually reset it).
Mozilla/5.0 (Windows NT 6.3; WOW64; rv:34.0) Gecko/20100101 Firefox/34.0
Post Reply