Page 1 of 1

Google Fonts should not be blocked

Posted: Sat Nov 24, 2012 11:22 pm
by chuffmunky
Google fonts will not display with Noscript active, and it's not apparent from the main popup list that they are being blocked; it only becomes apparent if the user looks in the submenu. It's confused a lot of people - i read many forum threads trying to find an answer and almost none of them were ever resolved! Can you please allow the googleusercontent fonts by default or at least make it apparent in the man popup window somehow?As noscript becomes more and more popular, it becomes more of a problem!

Re: Google Fonts should not be blocked

Posted: Thu Nov 29, 2012 2:24 am
by Tom T.
There is a good reason why NoScript blocks font downloads: Because there have been attacks using malicious fonts.
Search Microsoft Support for the terms: font vulnerability, and you'll get many results consisting of updates to address these vulnerabilities in the operating system.

Here's an example: http://support.microsoft.com/kb/2639658. There are many more.

A font download is in effect an object download, so yes, it will appear in the "blocked objects" sub-menu.
Any time that something doesn't seem right, even with the necessary scripts allowed, always look in this sub-menu.

If you would like to make it readily apparent that objects are being blocked, go to
NoScript Options > Notifications
and check "Show message about blocked scripts". It's your choice whether to have this at the top or bottom, and if'/when it should auto-disappear.

Once this is done and click OK, then you should receive a notification showing the number of scripts blocked and the number of objects blocked.

Possible solutions: Uncheck "Apply to whitelisted sites", assuming that the site you're on is whitelisted; uncheck "Forbid font", but not recommended.
If you post the specific sites where you want to allow this, we can help you write rules to automate the permission.
As noscript becomes more and more popular, it becomes more of a problem!
It's not NoScript becoming more popular; it's that the Web continues to become more complex, with new "features". Increased complexity and features always increase the possible points of attack. NoScript is defending you from those.

Re: Google Fonts should not be blocked

Posted: Thu Nov 29, 2012 11:32 am
by Thrawn
@chuffmunky: When objects are being blocked, there should be a cog on the NoScript icon; does that not appear for you?