A new guide to NoScript 10.x

Ask for help about NoScript, no registration needed to post
jeaye

A new guide to NoScript 10.x

Post by jeaye »

I have published an updated guide which details how to use the latest NoScript. I realize there's a similar guide here, but, when learning the new UI, not all of the existing guide's words and images connected with me. Hopefully this proves helpful for others as well.

https://blog.jeaye.com/2017/11/30/noscript/
Mozilla/5.0 (X11; Linux x86_64; rv:57.0) Gecko/20100101 Firefox/57.0
bo elam
Senior Member
Posts: 208
Joined: Sat Oct 14, 2017 2:25 am

Re: A new guide to NoScript 10.x

Post by bo elam »

Hi jeaye, nice and simple. 8-)

Bo
Mozilla/5.0 (Windows NT 10.0; WOW64; rv:57.0) Gecko/20100101 Firefox/57.0
FranL
Senior Member
Posts: 84
Joined: Sun Dec 03, 2017 4:17 pm

Re: A new guide to NoScript 10.x

Post by FranL »

jeaye wrote:I have published an updated guide which details how to use the latest NoScript. [...]
https://blog.jeaye.com/2017/11/30/noscript/
Thanks, jeaye. Very nice. You say that we should go through the settings migrated from 5.x and change the red locks to green, but if those sites are only available via HTTP, then that will break them, correct?
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0
jeaye

Re: A new guide to NoScript 10.x

Post by jeaye »

FranL wrote:
jeaye wrote:I have published an updated guide which details how to use the latest NoScript. [...]
https://blog.jeaye.com/2017/11/30/noscript/
Thanks, jeaye. Very nice. You say that we should go through the settings migrated from 5.x and change the red locks to green, but if those sites are only available via HTTP, then that will break them, correct?
That's right. I'd be careful trusting any JS served via HTTP at all though!
Mozilla/5.0 (X11; Linux x86_64; rv:57.0) Gecko/20100101 Firefox/57.0
Pansa
Senior Member
Posts: 318
Joined: Fri Nov 24, 2017 10:30 pm

Re: A new guide to NoScript 10.x

Post by Pansa »

jeaye wrote:
FranL wrote:
jeaye wrote:I have published an updated guide which details how to use the latest NoScript. [...]
https://blog.jeaye.com/2017/11/30/noscript/
Thanks, jeaye. Very nice. You say that we should go through the settings migrated from 5.x and change the red locks to green, but if those sites are only available via HTTP, then that will break them, correct?
That's right. I'd be careful trusting any JS served via HTTP at all though!
It's not really an indicator of the security of the JS. It is "merely" a matter of being intercepted by third parties.
So for any Javascript that isn't a matter of transferring sensitive data, it is demonstrably fine. Or better "as fine as surfing any HTTP content at all".
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0
User avatar
Giorgio Maone
Site Admin
Posts: 9546
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: A new guide to NoScript 10.x

Post by Giorgio Maone »

Pansa wrote: It's not really an indicator of the security of the JS. It is "merely" a matter of being intercepted by third parties.
So for any Javascript that isn't a matter of transferring sensitive data, it is demonstrably fine. Or better "as fine as surfing any HTTP content at all".
Not necessarily true.
The HTTP non-secured content it's not just easy to be read, but also easy to be spoofed by whomever controls the network.
This means that even if you trust the website's owner not to use a zero-day exploit against you, there's no guarantee that your WI-FI network administrator, your TELCO provider (possibly ordered by the police or some other nosy authority), the owner of the proxy you're using if any or an anonymous Tor Exit Node operator does not inject malicious code in your unencrypted traffic. That's why Tor, by default, enables active content only on HTTS sites.
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0
User avatar
Giorgio Maone
Site Admin
Posts: 9546
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: A new guide to NoScript 10.x

Post by Giorgio Maone »

@Jaye:
thank you so much, very needed. I've just tweeted about it.
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0
jeaye

Re: A new guide to NoScript 10.x

Post by jeaye »

Excellent, Giorgio! Glad to help.
Mozilla/5.0 (X11; Linux x86_64; rv:57.0) Gecko/20100101 Firefox/57.0
jeaye

Re: A new guide to NoScript 10.x

Post by jeaye »

Hey folks, I have udpated my guide with new images and explanations for the latest version.

https://blog.jeaye.com/2017/11/30/noscript/

Enjoy!
Mozilla/5.0 (X11; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0
Quest

Re: A new guide to NoScript 10.x

Post by Quest »

Clanced it through. Seems to be OK but if it is supposed to be for ordinary users too, then you should explain a bit your foliohat settings.

1. Those current default ticks on Default are not very big security risk but provide for some pages better functionality.

2. This red lock syndrom sure is a problem. But when I have tried to chance those locks green, no page has functionend. This might rise some confusion combined with NoScript strange behavior: when I change a red lock to green, then Trusted page turns to Default and popdown menu and options page show different permission status. And as said the page won't work any more.
I think that if any new/classic user meets this kind of behavior then he/she is no user anymore.

I don't claim that your suggestions are wrong, but I think they are too categoric.
Mozilla/5.0 (Windows NT 6.1; rv:58.0) Gecko/20100101 Firefox/58.0
User avatar
Giorgio Maone
Site Admin
Posts: 9546
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: A new guide to NoScript 10.x

Post by Giorgio Maone »

jeaye wrote:Hey folks, I have udpated my guide with new images and explanations for the latest version.

https://blog.jeaye.com/2017/11/30/noscript/

Enjoy!
Thank you.
Should I find the time to restructure the website, have I got your permission to reuse your text and screenshot?
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:58.0) Gecko/20100101 Firefox/58.0
jeaye

Re: A new guide to NoScript 10.x

Post by jeaye »

Giorgio Maone wrote:
jeaye wrote:Hey folks, I have udpated my guide with new images and explanations for the latest version.

https://blog.jeaye.com/2017/11/30/noscript/

Enjoy!
Thank you.
Should I find the time to restructure the website, have I got your permission to reuse your text and screenshot?
Absolutely, Giorgio. Attribution is appreciated.
Mozilla/5.0 (X11; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0
Post Reply