Help with ABE rule

Discussions about the Application Boundaries Enforcer (ABE) module
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: Help with ABE rule

Post by Thrawn »

Tom T. wrote:
Thrawn wrote:In plain English: every site is allowed to send requests only to itself and other subdomains of the same parent domain.....
Regardless of whether this is done with ABE or with RequestPolicy, it still doesn't address the increasing use of secondary servers for more-or-less static content, as in my previous post.
fbcdn.net is not a sub-domain of Facebook.com. ;)
Indeed. I believe Yahoo actually recommends this to improve multithreading when browsers limit simultaneous connections per site.

Anyone want to make an addon that looks up domain ownership for visited sites and automatically writes ABE rules when sites have the same owner?
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (Linux; U; Android 2.2.1; en-gb; GT-S5570 Build/FROYO) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1
Tom T.
Field Marshal
Posts: 3620
Joined: Fri Mar 20, 2009 6:58 am

Re: Help with ABE rule

Post by Tom T. »

Thrawn wrote:Anyone want to make an addon that looks up domain ownership for visited sites and automatically writes ABE rules when sites have the same owner?
Sounds terribly complex; ownership may not be accurate or up-to-date; and this would tempt someone to make a legit site that calls third-party script from his evil site -- both being under his ownership.

The part of NoScript Quick Start Guide that discusses secondary content servers is hoped to help users know to look for "cdn", "static", or "img", and some resemblance to the original site.
If you have a moment, perhaps check it out? :)
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.28) Gecko/20120306 Firefox/12.0
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: Help with ABE rule

Post by Thrawn »

Tom T. wrote:
Thrawn wrote:Anyone want to make an addon that looks up domain ownership for visited sites and automatically writes ABE rules when sites have the same owner?
Sounds terribly complex; ownership may not be accurate or up-to-date; and this would tempt someone to make a legit site that calls third-party script from his evil site -- both being under his ownership.
Umm...I'd only be talking about ABE rules that would allow requests from the owner's legit site to his evil site, so I'm not sure what advantage he gains by this method, rather than just serving malicious scripts from his legit site. The evil site will still have scripts blocked by default. If he can persuade the user to unblock it, he could probably do that anyway, regardless of ABE.

But I agree about the complexity. I was mostly joking when I suggested it :D.
Tom T. wrote: The part of NoScript Quick Start Guide that discusses secondary content servers is hoped to help users know to look for "cdn", "static", or "img", and some resemblance to the original site.
If you have a moment, perhaps check it out? :)
Believe it or not, I hadn't read the guide before :?...but I was already familiar with everything it was saying. It's well-written, though; I might point some friends/family to it.
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:12.0) Gecko/20100101 Firefox/12.0
Tom T.
Field Marshal
Posts: 3620
Joined: Fri Mar 20, 2009 6:58 am

Re: Help with ABE rule

Post by Tom T. »

Thrawn wrote:Umm...I'd only be talking about ABE rules that would allow requests from the owner's legit site to his evil site, so I'm not sure what advantage he gains by this method, rather than just serving malicious scripts from his legit site. The evil site will still have scripts blocked by default. If he can persuade the user to unblock it, he could probably do that anyway, regardless of ABE.
Under your "ownership rule", users visiting goodsite will see evilsite in the nenu (not under that name, of course ;) ), discover that the ownership is the same, and rely on that in making the trust decision.
But I agree about the complexity. I was mostly joking when I suggested it :D.
You could have saved me a lot of keystrokes... :lol:
Thrawn wrote:
Tom T. wrote:The part of NoScript Quick Start Guide that discusses secondary content servers is hoped to help users know to look for "cdn", "static", or "img", and some resemblance to the original site.
If you have a moment, perhaps check it out? :)
Believe it or not, I hadn't read the guide before :?...but I was already familiar with everything it was saying. It's well-written, though; I might point some friends/family to it.
TUVM. :)

The goal is to get NS to the non-tech majority, rather than have them think it's "too tech" for them. Glad you think it might accomplish that in your case, and of course I'd be eager to hear how the reception was from your (presumably) lesser-tech friends/family.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.28) Gecko/20120306 Firefox/12.0
Post Reply