I don't understand force https option

Ask for help about NoScript, no registration needed to post
anthoy
Posts: 9
Joined: Sun Apr 05, 2009 3:01 pm

I don't understand force https option

Post by anthoy »

Source NoScript Faq:

"...In order to mitigate these issues, NoScript can be configured to honor your whitelist only if the current page is served through HTTPS, and therefore cannot be spoofed...."

Where is this whitelist?
Q: How can I tell NoScript to allow only the sites of my whitelist which are served through HTTPS?
A: Open NoScript Options|Advanced|HTTPS|Behavior, click under Forbid active web content unless it comes from a secure (HTTPS) connection and choose one among:

1. Never - every site matching your whitelist gets allowed to run active content.
2. When using a proxy (recommended with Tor) - only whitelisted sites which are being served through HTTPS are allowed when coming through a proxy. This way, even if an evil node in your proxy chain manages to spoof a site in your whitelist, it won't be allowed to run active content anyway.
3. Always - no page loaded by a plain HTTP or FTP connection is allowed.
If I set Always and then I go to this site firefox warn me about unencrypted information. But Should NoScript block the unencrypted content?

Can someone explain me this option?

Thanks
Last edited by anthoy on Thu Jul 09, 2009 5:11 pm, edited 1 time in total.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.16) Gecko/20080702 Firefox/2.0.0.16
User avatar
therube
Ambassador
Posts: 7969
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: I don't understand force https option

Post by therube »

I get a broken https: icon without forcing anything, so guessing something is broken in general with that site?
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1pre) Gecko/20090601 SeaMonkey/2.0b1pre
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: I don't understand force https option

Post by Giorgio Maone »

The option you're talking about says "Forbid active content unless it comes from a HTTP connection".
It means that your usual NoScript whitelist (the one in NoScript Options|Whitelist) is filtered on the fly, letting scripts, flash and other active content (according to your NoScript Options|Plugins) run only if coming from a secure connection.

"Force HTTPS" is a different option: you've got two boxes where you can put the sites you want to be automatically redirected on HTTPS if Firefox tries to connect via plain HTTP, and exceptions to this rule.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11 (.NET CLR 3.5.30729)
Post Reply