4 ms·
NoScript provides many features that uMatrix does not: * Shift+click on host name, and pull up info on trustability from NoScript.net database * Filters WebGL
by hackuser 10y ago
NoScript provides many features that uMatrix does not:
* Shift+click on host name, and pull up info on trustability from NoScript.net database
* Filters WebGL, XSLT, @font-face
* Sophisticated XSS protection: Look up XSS on these pages:
https://noscript.net/features https://noscript.net/features
https://noscript.net/faq https://noscript.net/faq
* CSRF protection
* Clearclick: Detects invisible elements which cover clicked visible elements
https://hackademix.net/2008/10/08/hello-clearclick-goodbye-clickjacking/ https://hackademix.net/2008/10/08/hello-clearclick-goodbye-c...
* A pretty sophisticated firewall in your browser, Application Boundaries Enforcer (ABE), where you can even write your own policies:
"Living inside the browser, the ABE component can take advantage of its privileged placement for enforcing web application boundaries, because it always knows the real origin of each HTTP request"
"Many of the threats NoScript is currently capable of handling, such as XSS, CSRF or ClickJacking, have one common evil root: lack of proper isolation at the web application level."
"The idea behind the Application Boundaries Enforcer (ABE) module is hardening the web application oriented protections ... by delivering a firewall-like component running inside the browser ... specialized in defining and guarding the boundaries of each sensitive web application"
More here: https://noscript.net/abe/ https://noscript.net/abe/
Also, there's a project to create a GUI for just the ABE component, called SABER
https://forums.informaction.com/viewtopic.php?f=19&t=8059 https://forums.informaction.com/viewtopic.php?f=19&t=8059
- ryuuchin 10y agoSome of these features can be accomplished simply through blocking javascript.
- hackuser 10y agoWhich ones are you thinking about? Sometimes you want to enable JavaScript and still be protected from attacks.
- arviewer 10y agoFor us tech-savvy people that might be an option. But for the average user it's not. Too many things don't work. I use Privacy Badger and install it on every system that I maintain. It's simple and clean, and set up by an organisation that doesn't need shady ads on its website.
- wtallis 10y agoI do find it ironic that people assume that NoScript's only feature is the one that is the most hassle to use. The more passive always-on protections get overlooked, and people recommend as equivalent alternatives extensions that only provide a better UI for the domain-based script blocking, while not providing the defense in depth that NoScript has.
- elementalest 10y agoNot sure if this is considered bad practice, but I have uMatrix installed with noscript. I use uMatrix for script blocking and have noscript set to globally allow scripts, with ABE, XSS, clickjacking, etc protection enabled to cover the weak points of uMatrix.
- hackuser 10y agoWhy would it be bad practice?
- elementalest 10y agoPerhaps bad practice was the wrong word. Unnecessary might have been a better word.
- lightedman 10y ago"Shift+click on host name, and pull up info on trustability from NoScript.net database" The irony of that is staggering given NoScript being busted for spreading malware in this story.
- wtallis 10y agoThe report includes only links to third-party information, eg.: https://noscript.net/about/news.ycombinator.com;news.ycombinator.com https://noscript.net/about/news.ycombinator.com;news.ycombin...