3 ms·
On Firefox, I use the RequestPolicy plugin: by default, it only allows requests to the current domain, so nytimes.com can't access connect.facebook.com. You can
by fdb 15y ago
On Firefox, I use the RequestPolicy plugin: by default, it only allows requests to the current domain, so nytimes.com can't access connect.facebook.com. You can enable requests to go through, so that reddit.com can access redditstatic.com.
I think it strikes a good balance between blocking everything (a la NoScript) and total openness.
https://addons.mozilla.org/en-US/firefox/addon/requestpolicy/ https://addons.mozilla.org/en-US/firefox/addon/requestpolicy...
- jerf 15y ago"blocking everything (a la NoScript)" This seems to be a really popular misconception (presumably the name), but NoScript works pretty much as you describe, too. You do not need a plugin to turn "everything" off, the browsers all ship with that capability and have for over 15 years.
- deleted 15y ago[deleted]
- Zirro 15y agoNoScript and RequestPolicy are best used together (as recommended by the creator of the latter) as they serve different purposes. This, plus a few other add-ons in these areas are my set-up and that works well.
- fdb 15y agoYou often have to trade off security for convenience – for me, NoScript is too inconvenient to be worth it, because so many sites silently break when JavaScript is not available. I sometimes dream of a browser that would just fetch the page content and no extra other resources, showing it like Instapaper. The reality is more complex: images, css, CDN's, dynamic content, ... RequestPolicy realizes the most important part of that dream: not telling Google, Facebook and a host of obscure tracking companies about every website I visit.