A new guide to NoScript 10.x
-
jeaye
A new guide to NoScript 10.x
I have published an updated guide which details how to use the latest NoScript. I realize there's a similar guide here, but, when learning the new UI, not all of the existing guide's words and images connected with me. Hopefully this proves helpful for others as well.
https://blog.jeaye.com/2017/11/30/noscript/
https://blog.jeaye.com/2017/11/30/noscript/
Mozilla/5.0 (X11; Linux x86_64; rv:57.0) Gecko/20100101 Firefox/57.0
Re: A new guide to NoScript 10.x
Hi jeaye, nice and simple.
Bo
Bo
Mozilla/5.0 (Windows NT 10.0; WOW64; rv:57.0) Gecko/20100101 Firefox/57.0
Re: A new guide to NoScript 10.x
Thanks, jeaye. Very nice. You say that we should go through the settings migrated from 5.x and change the red locks to green, but if those sites are only available via HTTP, then that will break them, correct?jeaye wrote:I have published an updated guide which details how to use the latest NoScript. [...]
https://blog.jeaye.com/2017/11/30/noscript/
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0
-
jeaye
Re: A new guide to NoScript 10.x
That's right. I'd be careful trusting any JS served via HTTP at all though!FranL wrote:Thanks, jeaye. Very nice. You say that we should go through the settings migrated from 5.x and change the red locks to green, but if those sites are only available via HTTP, then that will break them, correct?jeaye wrote:I have published an updated guide which details how to use the latest NoScript. [...]
https://blog.jeaye.com/2017/11/30/noscript/
Mozilla/5.0 (X11; Linux x86_64; rv:57.0) Gecko/20100101 Firefox/57.0
Re: A new guide to NoScript 10.x
It's not really an indicator of the security of the JS. It is "merely" a matter of being intercepted by third parties.jeaye wrote:That's right. I'd be careful trusting any JS served via HTTP at all though!FranL wrote:Thanks, jeaye. Very nice. You say that we should go through the settings migrated from 5.x and change the red locks to green, but if those sites are only available via HTTP, then that will break them, correct?jeaye wrote:I have published an updated guide which details how to use the latest NoScript. [...]
https://blog.jeaye.com/2017/11/30/noscript/
So for any Javascript that isn't a matter of transferring sensitive data, it is demonstrably fine. Or better "as fine as surfing any HTTP content at all".
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0
- Giorgio Maone
- Site Admin
- Posts: 9546
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: A new guide to NoScript 10.x
Not necessarily true.Pansa wrote: It's not really an indicator of the security of the JS. It is "merely" a matter of being intercepted by third parties.
So for any Javascript that isn't a matter of transferring sensitive data, it is demonstrably fine. Or better "as fine as surfing any HTTP content at all".
The HTTP non-secured content it's not just easy to be read, but also easy to be spoofed by whomever controls the network.
This means that even if you trust the website's owner not to use a zero-day exploit against you, there's no guarantee that your WI-FI network administrator, your TELCO provider (possibly ordered by the police or some other nosy authority), the owner of the proxy you're using if any or an anonymous Tor Exit Node operator does not inject malicious code in your unencrypted traffic. That's why Tor, by default, enables active content only on HTTS sites.
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0
- Giorgio Maone
- Site Admin
- Posts: 9546
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: A new guide to NoScript 10.x
@Jaye:
thank you so much, very needed. I've just tweeted about it.
thank you so much, very needed. I've just tweeted about it.
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0
-
jeaye
Re: A new guide to NoScript 10.x
Excellent, Giorgio! Glad to help.
Mozilla/5.0 (X11; Linux x86_64; rv:57.0) Gecko/20100101 Firefox/57.0
-
jeaye
Re: A new guide to NoScript 10.x
Hey folks, I have udpated my guide with new images and explanations for the latest version.
https://blog.jeaye.com/2017/11/30/noscript/
Enjoy!
https://blog.jeaye.com/2017/11/30/noscript/
Enjoy!
Mozilla/5.0 (X11; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0
-
Quest
Re: A new guide to NoScript 10.x
Clanced it through. Seems to be OK but if it is supposed to be for ordinary users too, then you should explain a bit your foliohat settings.
1. Those current default ticks on Default are not very big security risk but provide for some pages better functionality.
2. This red lock syndrom sure is a problem. But when I have tried to chance those locks green, no page has functionend. This might rise some confusion combined with NoScript strange behavior: when I change a red lock to green, then Trusted page turns to Default and popdown menu and options page show different permission status. And as said the page won't work any more.
I think that if any new/classic user meets this kind of behavior then he/she is no user anymore.
I don't claim that your suggestions are wrong, but I think they are too categoric.
1. Those current default ticks on Default are not very big security risk but provide for some pages better functionality.
2. This red lock syndrom sure is a problem. But when I have tried to chance those locks green, no page has functionend. This might rise some confusion combined with NoScript strange behavior: when I change a red lock to green, then Trusted page turns to Default and popdown menu and options page show different permission status. And as said the page won't work any more.
I think that if any new/classic user meets this kind of behavior then he/she is no user anymore.
I don't claim that your suggestions are wrong, but I think they are too categoric.
Mozilla/5.0 (Windows NT 6.1; rv:58.0) Gecko/20100101 Firefox/58.0
- Giorgio Maone
- Site Admin
- Posts: 9546
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: A new guide to NoScript 10.x
Thank you.jeaye wrote:Hey folks, I have udpated my guide with new images and explanations for the latest version.
https://blog.jeaye.com/2017/11/30/noscript/
Enjoy!
Should I find the time to restructure the website, have I got your permission to reuse your text and screenshot?
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:58.0) Gecko/20100101 Firefox/58.0
-
jeaye
Re: A new guide to NoScript 10.x
Absolutely, Giorgio. Attribution is appreciated.Giorgio Maone wrote:Thank you.jeaye wrote:Hey folks, I have udpated my guide with new images and explanations for the latest version.
https://blog.jeaye.com/2017/11/30/noscript/
Enjoy!
Should I find the time to restructure the website, have I got your permission to reuse your text and screenshot?
Mozilla/5.0 (X11; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0