3 ms·
Disabling javascript would have prevented the exploit. The Tor browser bundle contains NoScript, but has it set to allow javascript by default. I think this is
by computer 13y ago
Disabling javascript would have prevented the exploit. The Tor browser bundle contains NoScript, but has it set to allow javascript by default. I think this is because it makes it more accessible to non-technical users.
Before this issue they even advised _not_ to disable javascript, since that would make you stand out more amongst Tor users.
- mseidl 13y agoNoscript blocks by default in the browser bundle...
- jlgaddis 13y agoNot in recent versions (the idea being that users w/ JavaScript disabled "stand out" more from typical users).
- mseidl 13y agoMy noscript is on by default on the linux version. I _never_ touched it.
- jlgaddis 13y ago"Why is NoScript configured to allow JavaScript by default in the Tor Browser Bundle? Isn't that unsafe?" https://www.torproject.org/docs/faq.html.en#TBBJavaScriptEnabled https://www.torproject.org/docs/faq.html.en#TBBJavaScriptEna...