Page 1 of 1

A new guide to NoScript 10.x

Posted: Fri Dec 22, 2017 10:31 pm
by jeaye
I have published an updated guide which details how to use the latest NoScript. I realize there's a similar guide here, but, when learning the new UI, not all of the existing guide's words and images connected with me. Hopefully this proves helpful for others as well.

https://blog.jeaye.com/2017/11/30/noscript/

Re: A new guide to NoScript 10.x

Posted: Fri Dec 22, 2017 11:08 pm
by bo elam
Hi jeaye, nice and simple. 8-)

Bo

Re: A new guide to NoScript 10.x

Posted: Fri Dec 22, 2017 11:35 pm
by FranL
jeaye wrote:I have published an updated guide which details how to use the latest NoScript. [...]
https://blog.jeaye.com/2017/11/30/noscript/
Thanks, jeaye. Very nice. You say that we should go through the settings migrated from 5.x and change the red locks to green, but if those sites are only available via HTTP, then that will break them, correct?

Re: A new guide to NoScript 10.x

Posted: Fri Dec 22, 2017 11:41 pm
by jeaye
FranL wrote:
jeaye wrote:I have published an updated guide which details how to use the latest NoScript. [...]
https://blog.jeaye.com/2017/11/30/noscript/
Thanks, jeaye. Very nice. You say that we should go through the settings migrated from 5.x and change the red locks to green, but if those sites are only available via HTTP, then that will break them, correct?
That's right. I'd be careful trusting any JS served via HTTP at all though!

Re: A new guide to NoScript 10.x

Posted: Sat Dec 23, 2017 2:06 am
by Pansa
jeaye wrote:
FranL wrote:
jeaye wrote:I have published an updated guide which details how to use the latest NoScript. [...]
https://blog.jeaye.com/2017/11/30/noscript/
Thanks, jeaye. Very nice. You say that we should go through the settings migrated from 5.x and change the red locks to green, but if those sites are only available via HTTP, then that will break them, correct?
That's right. I'd be careful trusting any JS served via HTTP at all though!
It's not really an indicator of the security of the JS. It is "merely" a matter of being intercepted by third parties.
So for any Javascript that isn't a matter of transferring sensitive data, it is demonstrably fine. Or better "as fine as surfing any HTTP content at all".

Re: A new guide to NoScript 10.x

Posted: Sat Dec 23, 2017 3:37 pm
by Giorgio Maone
Pansa wrote: It's not really an indicator of the security of the JS. It is "merely" a matter of being intercepted by third parties.
So for any Javascript that isn't a matter of transferring sensitive data, it is demonstrably fine. Or better "as fine as surfing any HTTP content at all".
Not necessarily true.
The HTTP non-secured content it's not just easy to be read, but also easy to be spoofed by whomever controls the network.
This means that even if you trust the website's owner not to use a zero-day exploit against you, there's no guarantee that your WI-FI network administrator, your TELCO provider (possibly ordered by the police or some other nosy authority), the owner of the proxy you're using if any or an anonymous Tor Exit Node operator does not inject malicious code in your unencrypted traffic. That's why Tor, by default, enables active content only on HTTS sites.

Re: A new guide to NoScript 10.x

Posted: Sat Dec 23, 2017 3:49 pm
by Giorgio Maone
@Jaye:
thank you so much, very needed. I've just tweeted about it.

Re: A new guide to NoScript 10.x

Posted: Sat Dec 23, 2017 6:58 pm
by jeaye
Excellent, Giorgio! Glad to help.

Re: A new guide to NoScript 10.x

Posted: Sat Feb 03, 2018 8:45 pm
by jeaye
Hey folks, I have udpated my guide with new images and explanations for the latest version.

https://blog.jeaye.com/2017/11/30/noscript/

Enjoy!

Re: A new guide to NoScript 10.x

Posted: Mon Feb 05, 2018 10:58 am
by Quest
Clanced it through. Seems to be OK but if it is supposed to be for ordinary users too, then you should explain a bit your foliohat settings.

1. Those current default ticks on Default are not very big security risk but provide for some pages better functionality.

2. This red lock syndrom sure is a problem. But when I have tried to chance those locks green, no page has functionend. This might rise some confusion combined with NoScript strange behavior: when I change a red lock to green, then Trusted page turns to Default and popdown menu and options page show different permission status. And as said the page won't work any more.
I think that if any new/classic user meets this kind of behavior then he/she is no user anymore.

I don't claim that your suggestions are wrong, but I think they are too categoric.

Re: A new guide to NoScript 10.x

Posted: Mon Feb 05, 2018 11:02 pm
by Giorgio Maone
jeaye wrote:Hey folks, I have udpated my guide with new images and explanations for the latest version.

https://blog.jeaye.com/2017/11/30/noscript/

Enjoy!
Thank you.
Should I find the time to restructure the website, have I got your permission to reuse your text and screenshot?

Re: A new guide to NoScript 10.x

Posted: Wed Feb 07, 2018 5:25 pm
by jeaye
Giorgio Maone wrote:
jeaye wrote:Hey folks, I have udpated my guide with new images and explanations for the latest version.

https://blog.jeaye.com/2017/11/30/noscript/

Enjoy!
Thank you.
Should I find the time to restructure the website, have I got your permission to reuse your text and screenshot?
Absolutely, Giorgio. Attribution is appreciated.