Page 1 of 1

the XSS attack dialog box

Posted: Sun Nov 26, 2017 1:20 pm
by caffeine demon
Hi,

I was wondering if there was anyway of setting noscript to automatically bloack all XSS attacks, as since the firefox & noscript upgrade last week, tripadvisor as well as a lot of shopping sites are bringing up the dialog box every time I click on a new forum topic or item to view and it's just annoying having to block them all?

Many thanks

Re: the XSS attack dialog box

Posted: Sun Nov 26, 2017 4:28 pm
by PersephoneUnderground
I have the same problem, and the answer in the FAQ about how to change my settings:
Yes, you can, just toggle the Noscript Options|Notifications|XSS preference.
...doesn't apply to the new interface in 10.1.2, as that menu doesn't appear to exist. My only choices in the new interface are to either turn the XSS blocking on or off, there are no other options. I want to leave it on, just not have to approve the blocking every time.

(On a larger note, what the heck happened to the interface? I liked the old one, this one seems much less sophisticated and harder to use, also for some reason the drop-down menu is larger and more icon-based, and therefore it's harder to figure out what each option means and what selecting it will do.)

Re: the XSS attack dialog box

Posted: Sun Nov 26, 2017 4:35 pm
by barbaz
PersephoneUnderground wrote:(On a larger note, what the heck happened to the interface? I liked the old one, this one seems much less sophisticated and harder to use, also for some reason the drop-down menu is larger and more icon-based, and therefore it's harder to figure out what each option means and what selecting it will do.)
Giorgio was forced to do a complete UI overhaul - https://hackademix.net/2017/11/21/top-i ... ment-38469

Re: the XSS attack dialog box

Posted: Sun Nov 26, 2017 5:21 pm
by Pansa
PersephoneUnderground wrote:I have the same problem, and the answer in the FAQ about how to change my settings:
Yes, you can, just toggle the Noscript Options|Notifications|XSS preference.
...doesn't apply to the new interface in 10.1.2, as that menu doesn't appear to exist. My only choices in the new interface are to either turn the XSS blocking on or off, there are no other options. I want to leave it on, just not have to approve the blocking every time.

(On a larger note, what the heck happened to the interface? I liked the old one, this one seems much less sophisticated and harder to use, also for some reason the drop-down menu is larger and more icon-based, and therefore it's harder to figure out what each option means and what selecting it will do.)
You have to look at the mouseover text instead of just for the icons. Most of the information is objectively "ok" (except for some buggy behaviour surrounding http/https and untrusted).

It isn't "really" less sophisticated, except for the parts that still aren't included because Mozilla is still working on the APIs and thus can't be replicated yet.
On other fronts it's already more sophisticated allowing for a lot more specific decisions that were never in 5.x

The biggest "misscommunications" happen if you "blindly" apply 5.x logic instead of reading and seeing what is done here.
It changed a lot, and coming from 5.x the logic of "move source to preset and configure the preset anywhere" isn't what you'd expect. It'S more in line with general practices of this kind of software in general though.