4 ms·
As I mentioned on /r/netsec it's valid to point out the author does shady shit, but the title is clickbaity at best - the NoScript website advertises malware, t
by necessity 10y ago
As I mentioned on /r/netsec it's valid to point out the author does shady shit, but the title is clickbaity at best - the NoScript website advertises malware, there is no evidence that NoScript itself is harmful to the user. And btw you shouldn't let your extensions auto-update on Firefox anyway, specially if you use Tor, as it's vulnerable to MITM as someone posted here a few days ago. I might switch to uMatrix, but I don't really have the time right now to learn it.
- corndoge 10y agoTakes about five minutes to learn. For NoScript equivalence, click the matrix and deselect the JavaScript column.
- vesinisa 10y agoI can second this. Recently migrated from NoScript to uMatrix. I was finally confident enough to put NoScript to "globally allow all" mode this week and use uMatrix alone for controlling scripting permissions. (After reading this disabled NoScript altogether.) uMatrix allows more fine-grained control than NoScript. It's basically based on three contexts (scopes): host, domain and global, but my experience is I only ever use the global and domain scopes. I would recommend starting by globally white-listing the popular CDNs (so scripts on all sites delivered e.g. through Google's CDN are always executed and <script> snippets to integrate Google widgets work). Then, for a majority of trusted sites it's enough to just white-list the local domain (allow executing scripts from example.com when you are visiting example.com sites). Scripts included on foobar.org from example.com still remain blocked – this is the crucial difference between global and local scopes that NoScript doesn't lend to. I would recommend always allowing XHR and iframes in the site-local scope. IIRC this is not in the default config but since XHR anyway requires scripting you can then easily control both XHR / scripting by just white-listing the site for scripting. So this is my uMatrix base configuration currently and a good starting point for migrating from NoScript: * * * block * * css allow * * image allow * 1st-party cookie allow * 1st-party frame allow * 1st-party xhr allow I.e. CSS / images allowed from all sources (except those blocked explicitly). Cookies, frames and XHR allowed from the same site you are currently visiting. Only scripting must be allowed per-site, just like with NoScript.
- shapov 10y ago> there is no evidence that NoScript itself is harmful The article states that every time the plugin updates, it automatically opens up a webpage that serves malware. So technically the article is not wrong. NoScript forces your browser to open a malicious page, therefore it can be considered itself harmful.
- steanne 10y agothe release notes page? there's a checkbox for "display the release notes on updates".
- qbrass 10y agoWhen you first install it, you have to restart Firefox to complete the install and access the config menu. When you restart Firefox, it automatically loads the Noscript website to display. You have to disconnect from the internet, restart Firefox, let it fail to load the page, then go to the settings menu and uncheck the box.
- deleted 10y ago[deleted]
- Dylan16807 10y agoIt opens a webpage that has an ad link to malware that must be manually installed. That's not a malicious page.
- carterehsmith 10y agoSure. Now, the question is, do I trust a plugin that serves ads for malware? BTW any info on when did they start doing that?
- revanx_ 10y agoSource code for NoScript is available, if you manually update and compare the code you should be safe.
- PeCaN 10y agouMatrix is one of the most brilliantly designed UIs I've used in a while. There's hardly any learning involved, it's simply a very usable thing.
- lolc 10y agoNoScript is harmful because it keeps displaying the site in question to its users. The title is justified in my opinion.
- pfg 10y ago> And btw you shouldn't let your extensions auto-update on Firefox anyway, specially if you use Tor, as it's vulnerable to MITM as someone posted here a few days ago. This was fixed in Tor Browser 6.0.5[1] and Firefox 49[2]. Worth noting that the attack required a publicly-trusted certificate for addons.mozilla.org, which makes this a bit harder than just a run-of-the-mill MitM attack, though certainly possible for nation-state actors and the likes. [1]: https://blog.torproject.org/blog/tor-browser-605-released https://blog.torproject.org/blog/tor-browser-605-released [2]: https://www.mozilla.org/en-US/security/advisories/mfsa2016-85/ https://www.mozilla.org/en-US/security/advisories/mfsa2016-8...
- RaleyField 10y ago> there is no evidence that NoScript itself is harmful to the user In the most narrow sense. Since I can't in good conscience recommend it to normal people I am considering it harmful.
- wtallis 10y ago> Since I can't in good conscience recommend it to normal people I am considering it harmful. You can't really recommend it to normal people even without considering the author's advertising practices. NoScript is a tool for power users who understand a few things about how the web works.
- hasenj 10y agoSecurity is based on trust ..