Page 1 of 1

Thoughts on company-wide installation

Posted: Sat Oct 01, 2011 7:03 pm
by orange
Hi there,

I'm using NoScript for quite a while now and I think it's a great security enhancement. As a to-be IT-Security Manager I wondered why not use NoScript company wide on every PC? I read through the FAQ and searched the forum but didn't find what I was looking for. So, if I start making Firefox the default browser and add NoScript to every PC, it would be very useful to deploy a company-wide whitelist. Of course I could import a whitelist after initial installation, but what if I need to add or remove something to/from the whitelist (e.g. if a whitelisted website starts serving malware ... mysql.com ... )?

It would be great if there would be a possibility to import a whitelist from a network-share everytime I start Firefox - and override the existing local whitelist.

As far as I know the NoScript settings can be synchronized via Firefox Sync. So one possible solution could be to set up a Firefox Sync-Server on my local LAN and point every single Firefox to this Sync-Server. But setting up this Sync-Server (Weave) doesn't seem to be that trivial and I'm not that much into configuring webservers: http://docs.services.mozilla.com/howtos/run-sync.html

Has anyone done this before or considered using NoScript company wide?
I think it would be great if NoScript could provide this - syncing preferences/whitelist between multiple Firefoxes in a LAN.

Re: Thoughts on company-wide installation

Posted: Sun Oct 02, 2011 4:39 pm
by therube
> e.g. if a whitelisted website starts serving malware ... mysql.com

You would have been safe in any case (most likely), because the domains hosting the exploit were at falosfax.in & cx.cc & were not Trusted (Allowed, by default).

Re: Thoughts on company-wide installation

Posted: Tue Oct 04, 2011 7:11 pm
by orange
therube wrote:> e.g. if a whitelisted website starts serving malware ... mysql.com

You would have been safe in any case (most likely), because the domains hosting the exploit were at falosfax.in & cx.cc & were not Trusted (Allowed, by default).
I see, thanks for clarification. :)