5 ms·
https://en.wikipedia.org/wiki/NoScript https://en.wikipedia.org/wiki/NoScript
by n0nc3 6y ago
https://en.wikipedia.org/wiki/NoScript https://en.wikipedia.org/wiki/NoScript
- alquemist 6y agoChristmas came early this year :) Thanks!
- eindiran 6y agoFor anyone considering taking the dive: NoScript takes a bit of time to get used to, but stick with it. You'll build up some things you are happy to whitelist, plus always have the backup option of disabling temporarily within a tab. In a week or two, your new workflow will feel completely natural.
- rakoo 6y agoAnother user here, and things weren't so smooth. Everytime you reach a new website you'll need to change rules and reload it. It's ok if you're always going to the same sites, but if you always discover new places (and I believe HN participates in that) it's a constant weight to lift. Always useful, but still not natural IME.
- dylan604 6y agoIt gets a lot easier if you only allow self-hosted JS. Block any JS loaded from a domain other than the one you are actually visiting. If the site I am visiting cannot function properly from self-hosted JS, then I move right along. It has to be a webiste I'm really interested in for me to even consider allowing 3rd party JS.
- smittywerben 6y agoI've been whitelisting JavaScript since No-Script was new. I've used uMatrix recently but with it's end-of-development[0] I am considering switching back. I grew tired of having some shitty virus dropped to %appdata% for the N-th time loading a web page, exempli gratia [1] It's gotten a lot more annoying the last several years with 5mb webpages. Backing up the whitelist saves a lot of time. For perspective, I use 4 separate profiles (--user-data-dir) listed in descending order of how annoying they are for me to use. 1). School browser: Chrome + uBlock origin 2). Shopping/low security (when the payment processor is an iFrame and I don't want to refresh...): Firefox + uBlock origin + CanvasBlocker 3). General browsing like browsing Google or YouTube: Chrome + uBlock Origin + uMatrix 4). VPN browser: Chrome + uBlock origin + uMatrix + CookieAutoDelete + VPN extension I've gone from 2 browsers (Firefox + IE6) to 4 browsers (Firefox, Chrome1, Chrome2, Chrome3). By 2030 I'll be running 16 browsers in a virtual machine on a remote server that I connect to with my browser browser. [0] https://www.ghacks.net/2020/09/20/umatrix-development-has-ended/ https://www.ghacks.net/2020/09/20/umatrix-development-has-en... [1] http://forums.mozillazine.org/viewtopic.php?f=38&t=368230 http://forums.mozillazine.org/viewtopic.php?f=38&t=368230 (2006)
- marcthe12 6y agoI wish these extensions could integrate with Firefox containers. Work and schools can easily ask people to use new sites which can not avoid and in that case it's best to defer to later day or just not fight with extensions.
- fuzxi 6y agoI'd recommend uMatrix instead. It largely (completely?) supersedes NoScript, and I find the UI to be much easier to work with. It also has better granularity of exactly what you want blocked/allowed.
- rakwoelq 6y agouMatrix development has ended though, no more updates will arrive.
- fuzxi 6y agoIt hadn't had a stable release for a year at the point when the repo was archived, because it's more-or-less feature-complete and has no major bugs. 90% of the open github issues [1] were enhancement or documentation requests. No updates is not necessarily a bad thing. Sometimes things work well enough to leave alone. [1]: https://github.com/uBlockOrigin/uMatrix-issues/issues https://github.com/uBlockOrigin/uMatrix-issues/issues
- dehrmann 6y agoEvery once in a while there's a site that will refuse to work with uMatrix enabled, even if I manually allow everything and disable spoofing.
- fuzxi 6y agoI've noticed this too. Every time, it was solved by disabling uBlock.
- l33tman 6y agoI use umatrix all the time and there are multiple sites where it doesn't work. I think part of the problem is that not all requests are actually shown in the drop-down for you to enable them. Maybe a popup or frame causes umatrix to miss it etc. For a blocker where the default mode is "block everything", it makes sense that this failure mode would be the dominant..