![]() |
|
|||||||
| View Poll Results: Do you use noscript to handle Javascript | |||
| Yes |
|
92 | 50.83% |
| No |
|
89 | 49.17% |
| Voters: 181. You may not vote on this poll | |||
|
|
Thread Tools | Search this Thread |
|
#101
|
|||
|
|||
|
Quote:
I pretty much agree. I've gone off and on NoScript for years now, and I just end up tiring of it. Its effectiveness at controlling script security issues is well shown, but if you're an "avid surfer" (notice I said avid, not stupid ), it quickly becomes tiresome. I spend more time answering "Is this safe to allow?" questions from friends and family than I care to keep spending. It may be a fine and dandy tool in the hands of someone who has a single system to his or her self, but add 3 or more people in the mix, and it's soon not worth the most often small benefit of extra security. |
|
#102
|
|||
|
|||
|
Quote:
![]() -ClearClick -Click to Play plugins -XSS protection -ABE and others ![]() |
|
#103
|
|||
|
|||
|
Quote:
None of which I find to be a big deal anyway. In a multiple person environment, it's more hassle than benefit. I find it's more productive and easier to simply use a browser that makes it harder or impossible to pull off such attacks (Chrome), or isolating the browser via Sandboxie or some such method. Allowing scripts globally is all but the same as not having the extension to begin with. And, as I've said before a few times, playing the shell game with scripts isn't going to do a user any good either. |
|
#104
|
|||
|
|||
|
No, I have never used it because I do not use Java.
|
|
#105
|
||||
|
||||
|
Quote:
Java and java scripts are not the same thing. at all. Java is a framework to make other software/apps work, java scripts are little pieces of codes that are used in internet browsers. they are totally different.
__________________
| Xubuntu || NoScript || Image for Linux + BootIt Bare Metal | |
|
#106
|
||||
|
||||
|
Quote:
i think you got something there. i kinda enjoy fiddling with NoScript but there's gotta be something wrong with me.lol anyway, i kind of enjoy the granularity NoScript affords but while you're playing with NoScript you're not surfing the net. which is what a browser should be used for.lol and what if you should allow the wrong script by mistake? since Firefox doesn't have yet a sandbox it means one should use Sandboxie, SRP or some other thing...
__________________
| Xubuntu || NoScript || Image for Linux + BootIt Bare Metal | |
|
#107
|
|||
|
|||
|
I like NoScript not only because it makes browsing safer but also because it cleans websites of a lot of annoying stuff that gets displayed as ads, moving and/or distracting thing's that jump all over the place, pop ups, etc. Browsing gets faster and it makes it easier to focus on what I am doing since most distractions are killed by NoScript. To me, NoScript is a lot more than a security addon but it is also a great tool for security.
A couple of years ago, a Colombian site that I visit almost every day was under attack. That did not stop me from going there and even though NoScript kept displaying the clickjacking warning for almost 2 weeks, I did not get infected. I was still using an AV at the time and it never detected anything, SBIE and NoScript alerts is what kept me clean. Bo |
|
#108
|
||||
|
||||
|
Quote:
the geek in me loves NoScript but the web these days use a lot of javascripts. yes, NS blocks a lot of things. for example, it can also block the comments of bloggers to a news article you are reading. if the site does not warn that the comments are blocked by your js blocker then you might not even know the comments are there. it seems like most web developers these days are not even trying to cater to the less than 1% who block js in their browsers, using NS or some other means. using NoScript means you are probably very safe. it probably also means you are missing a lot of the web...
__________________
| Xubuntu || NoScript || Image for Linux + BootIt Bare Metal | |
|
#109
|
||||
|
||||
|
I don't use it because I sandbox browser and scripts can't do much harm to my system.
Whitelisting the whole Internet is just to tedious for me.
__________________
ESET Nod32 AV • Sandboxie • EMET • OpenDNS My security setup in detail • Always remember you're unique, just like everyone else • |
|
#110
|
||||
|
||||
|
Quote:
Yep, and then 50% faster when you start actually browsing. Without all that junk popping up on the screen, pages load much faster. Same deal with ABP, Ghostery & Request Policy. Pages load much faster with these 4 addons. All the elements blocked far more than offset any resource usage from the addons themselves. And I just don't get the complaints about it being some monumental inconvenience. How difficult is it, really, to click "allow" one time? It's then on your whitelist and you never have to do it again. I guess it depends on your usage. If you're perpetually digging through new sites, then it would become a nuisance. I'm not. There are about a dozen sites I frequent, and I rarely do anything else on the net.
__________________
XP Pro SP3: Comodo FW/D+ 5.10 ▪ Sandboxie 3.76 ▪ VT Hash Check 1.01 ▪ OpenVPN 2.2.1 ▪ VirtualBox 4.2 ▪ TrueCrypt 7.1 Firefox/Ixquick ▪ NoScript - ABP - RequestPolicy - CS Lite - WOT ▪ Macrium Reflect Free 4.2 ▪ PRQ - Mullvad ▪ Comodo Secure DNS ▪ MBAM Free ▪ Hitman Pro |
|
#111
|
||||
|
||||
|
Quote:
Not for me it's not. Rarely, anyhow. And that is the real impasse here. dw pointed it out in his response to you... if you are an avid surfer, "whitelisting the entire internet", as another person put it, would certainly become a nuisance. I'm personally not browsing the entire internet.
__________________
XP Pro SP3: Comodo FW/D+ 5.10 ▪ Sandboxie 3.76 ▪ VT Hash Check 1.01 ▪ OpenVPN 2.2.1 ▪ VirtualBox 4.2 ▪ TrueCrypt 7.1 Firefox/Ixquick ▪ NoScript - ABP - RequestPolicy - CS Lite - WOT ▪ Macrium Reflect Free 4.2 ▪ PRQ - Mullvad ▪ Comodo Secure DNS ▪ MBAM Free ▪ Hitman Pro Last edited by luciddream : June 26th, 2012 at 08:49 PM. |
|
#112
|
|||
|
|||
|
It slowed actual browsing last time I used it. I might consider it again in the future, but for now I'm just enjoying simplicity.
My security setup has remained static for longer than a year, other than minor rule changes in Sandboxie and getting rid of HOSTS & Flashblock. |
|
#113
|
|||
|
|||
|
Quote:
When I am in a new site and I want to allow something, I just click on allow temporarily or allow the page. It doesn't really matter if I remember to revoke temporary permissions since the scripts that were allowed temporarily will be gone when I close the browser and the ones that I allowed for good, will also be gone because they were allowed running sandboxed. Thats pretty much how I use NoScript. Simple and easy. Personally, I feel I get a lot of benefits out NoScript. I mentioned those on my previous post, most of them have nothing to do with security but I feel that SBIE and NoScript as a team, is what keeps me safe. I have been using both programs for about the same amount of time, SBIE came a little earlier but since I started using them, I have never seen anything that looks like malware popping around while browsing. Not once in over 3 years. In my opinion, NoScript is blocking a lot of bad stuff for me. I remember once, someone told me, "Why miss the fun?", the fun being watching malware doing its thing while running sandboxed. Myself, I rather let NoScript block potential malware even if I miss the fun. If any gets through NoScrip, it ll be contained by SBIE. Can not be any better. Bo |
|
#114
|
||||
|
||||
|
Those who're 'tired' of NoScript can still choose to 'Allow scripts globally' therefore not being prompted with scripts to allow (which is what makes most annoyed) - and yet being able to take advantage of some security benefits, compared to running vanilla firefox or even a sandboxed firefox.
If you want, you can 'blacklist' certain scripts, even in the 'Allow scripts globally' mode. There's little hassle in this mode, and it's suitable for 'family and friends' context. However for those who can go through an initial phase of whitelisting sites that are frequently visited, they'd find the pain worth the gain in the long run. Maybe i'll share my settings to make NoScript less 'interactive' in the hope that it might be useful for those who wish to run NoScript but on the verge of slamming his/her head on the wall. Yeah, I know coz i've been there...thankfully haven't reached the point of doing it just yet.
__________________
Uncertainty is the only certainty there is, and knowing how to live with insecurity is the only security... |
|
#115
|
||||
|
||||
|
no, you do not need to whitelist the whole internet but the way things are these days it's getting there.
i've been surfing some forums for website developers to learn more about how scripts are integrated these days and the common wisdom seems to be to not bother with the 0.5% of us unwashed peasants who block javascripts. ![]() thus the ever growing reliance for developers on using js... i barely used any whitelist when i used NoScript, wanting to use it as a 'script HIPS'. this way of using NS worked fine in the past but it's become a bloody headaches lately. and getting worse i'm afraid.
__________________
| Xubuntu || NoScript || Image for Linux + BootIt Bare Metal | |
|
#116
|
||||
|
||||
|
Quote:
LOL. No wonder you got headaches. The whitelist is there for a good reason and despite what some NoScript advocates say about not populating it with too many entries (which is a good reminder); i'd say that one is still better of having 50 (heck, even 100) entries there than to go with the route you took and end up giving up due to being 'tired' of it.
__________________
Uncertainty is the only certainty there is, and knowing how to live with insecurity is the only security... |
|
#117
|
|||
|
|||
|
Quote:
Quote:
Bo |
|
#118
|
||||
|
||||
|
NoScript is the primary layer of my setup and it's very strong against malware.
![]()
__________________
✓The first principle is that you must not fool yourself, and you are the easiest person to fool. ✓Science is the belief in the ignorance of experts. ✓I don't know anything, but I do know that everything is interesting if you go into it deeply enough. -------Richard P. Feynman--------- |
|
#119
|
||||
|
||||
|
back to NS, on Mint this time.
i've added a few sites to my whitelist, mainly Youtube and Google, my webmail and a few of their 'dependencies'. i'll try to keep this to a bare minimum. ![]()
__________________
| Xubuntu || NoScript || Image for Linux + BootIt Bare Metal | |
|
#120
|
|||
|
|||
|
retina ipad. I use a third party app that converts on the fly as you watch your content. Great for HD movies in bed.
|
|
#121
|
||||
|
||||
|
Wasn't using NoScript until Bo convinced me again to use it. lol. Damn, he even convinced me to use Sandboxie so I didn't or can't go wrong with either. ![]()
__________________
System: Windows 7 64bit Sandboxie Pd., MBAM Pro, MSE, UAC, Macrium Reflect Wolfstr |
|
#122
|
|||
|
|||
|
Hey Wolfstr, enthusiasm is contagious.
Greetings Bo |
|
#123
|
||||
|
||||
|
Quote:
Yes, using Sandboxie and NoScript in FF ='s "less stress" >> Wolfstr
__________________
System: Windows 7 64bit Sandboxie Pd., MBAM Pro, MSE, UAC, Macrium Reflect Wolfstr |
|
#124
|
|||
|
|||
|
Quote:
Bo |
|
#125
|
||||
|
||||
|
Here's my special service for you
![]() If you want to unclutter the Noscript menu on many sites, just add my blacklist to Noscript. First, export your settings to, say, Noscript.txt (a copy of which you might want to save under a new name - just in case something goes wrong). Second, copy the content of the attached file and replace (or add to) what is shown behind "untrusted" in above txt-file. Third, re-import that file to Noscript. Ready. Makes life easier. Noscript-backup_blacklist.txt |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|