Guest wrote:I wanted to add Lavabit to NoScript's list of sites to force cookies to use encryption to be sure.
If the site works fine in full HTTPS mode, all you need to protect it is adding it to your
NoScript Options|Advanced|HTTPS|Behavior|Force the following sites to use HTTPS connections lists.
This way your cookies can't leak over plain HTTP even if they are not secure.
Forcing secure cookies, on the other hand, can sometimes cause non-obvious compatibility issues because cookies are rewritten on the fly, hence it should be used sparely only if a site actually forces you in mixed HTTP/HTTPS mode (i.e. some URLs do not work over HTTPS, like Google search for instance).
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10 (.NET CLR 3.5.30729)