Font blocking (mainly)

Ask for help about NoScript, no registration needed to post
Gogg

Font blocking (mainly)

Post by Gogg »

Hey guys,

Just wondering something. Why are fonts blocked by NoScript ? What kind of threats does this mitigate ?


Also, side question while I'm at it, is there any protection gained from blocking URL "javascript:" for technically literate people ? Until now I thought it would only protect common users who would be tricked into copy/pasting a javascript: URL into their address bar, or clicking on a javascript: link. So if I can read the URL before running it I cannot be tricked. But maybe there are concealed ways to have them run that would work even on JS literate people ?
If not I'll just keep the javascript: blocking disabled.


Thanks :)
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:21.0) Gecko/20100101 Firefox/21.0
User avatar
therube
Ambassador
Posts: 7991
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: Font blocking (mainly)

Post by therube »

Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 5.1; rv:22.0) Gecko/20100101 SeaMonkey/2.19a2
Gogg

Re: Font blocking (mainly)

Post by Gogg »

Wow, I didn't expect the custom fonts feature to require so much of a complex machinery. Now that does make sense to block it. Thanks :)
Though the last line of that article links to slides that talk about SVG font abuse among other things. Why doesn't NoScript block SVG ?


Also if anyone knows the reply to my less important question about "javascript:" URLs, I'm all ears :)
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:21.0) Gecko/20100101 Firefox/21.0
User avatar
Giorgio Maone
Site Admin
Posts: 9557
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Font blocking (mainly)

Post by Giorgio Maone »

NoScript does block cross-site SVG.
Gogg wrote:But maybe there are concealed ways to have them run that would work even on JS literate people ?
As soon as you type the JavaScript snippet in first person and don't use copy&paste from a website (which can be easily hijacked) you should be relatively safe.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:21.0) Gecko/20100101 Firefox/21.0
Guest

Re: Font blocking (mainly)

Post by Guest »

Oh ok, only cross site SVG is blocked ! That must be why I didn't notice it. Good to know

And the protection from "javascript:" can stay disabled as well, which I prefer this way. I wanted to make sure there wasn't some way to trick the browser into automatically executing somehow. If it absolutely requires a copy/paste action from the user, it's safe for me even if the copy is hijacked.


Thanks for the answers !
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:21.0) Gecko/20100101 Firefox/21.0
Post Reply