ScriptSafe former ScriptNo: Discussion

Discussion in 'other software & services' started by andryou, Nov 15, 2011.

  1. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Re: ScriptNo: Discussion

    Layers are nice. No one can really say "X feature is better than Y" and be 100% objectively correct. Security features just can't be compared like that especially when you start taking "real-world" security into account with an ever-changing threat landscape.

    The sandbox has its specific purposes and they don't have much to do with XSS. For that Chrome has an XSS filter, which works fine.
     
  2. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    Re: ScriptNo: Discussion

    You're absolutely right when you say that it isn't a solution against everything. But, there's a difference between saying that and saying that's overrated.

    Otherwise, if we look at it from Maoni's perspective, then anyone could say As useful as XSS protection is, it does nothing to minimize the damage that can be done by attacks that exploit browser and plugin vulnerabilities.

    Correct? :) So, I think we agree that all of these mitigation techniques, XSS protection, sandboxing, etc are all very welcome. :)
     
  3. tlu

    tlu Guest

    Re: ScriptNo: Discussion

    We do :thumb:
     
  4. lipsin

    lipsin Registered Member

    Joined:
    Mar 19, 2012
    Posts:
    16
    Re: ScriptNo: Discussion

    Scriptno Bugs? By Design? or just plain broken?

    Scriptno Version: 1.0.6.X (latest) Chrome: 18 beta

    Assume empty whitelist, default everything block in settings.

    1) Visit Google homepage from address bar or from clicking bookmark.

    www.google.com

    Expectation: No script on google homepage should be allow to execute.

    Result: Google homepage black bar drop down menu work. (Script execute)

    Further testing, seem as long as any site load from address bar or bookmark, it would not block majority of the script, script execute like business as usual. Only a 2nd refresh will block all those script.

    While the menu, shown all still blocked.

    2) Confirmed all script for a site is blocked including all 3rd party script.
    Temp Allowed current site domain.

    Result: Almost all script is execute including majority 3rd party reference script.

    Example: http://www.soyacincau.com/2012/03/19/samsung-galaxy-s-iii-to-feature-quad-core-exynos-4412-possible-1-5ghz-clock-speed/

    All kind of 3rd party script also execute, ads, social widget, and the most visible part, the commenting platform also load.

    Seem almost all script including 3rd party is execute.

    While the menu icon only shown current domain is allowed, and all detected 3rd party script/domain blocked.

    3) An extreme simple pages using javascript and jquery host on dropbox.
    https://dl.dropbox.com/u/6589730/test.html

    Contain inline script and reference a Google host jquery code

    Basically it just change text color from red to green.

    it can demo problem 1) and 2)

    Firefox + Noscript = OK work as expected
    Chrome + Notscript (long not updated) = also OK work as expected

    Blocked till allowed both inline script and reference script.

    Chrome + Scriptno is not working as expected at all.
    Either in situation 1 or situation 2.
    The text color keep changing from red to green.
    While the menu icon still shown incorrect feedback.

    Prior version problem is mainly on the unreliable problem 2).

    Latest version with web request api cause the problem 1) and 2) even worst.

    Scriptno is a very nice extension for chrome, but unless i miss somethings it is broken badly for now.
     
  5. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Re: ScriptNo: Discussion

    Make a bug report?
     
  6. moontan

    moontan Registered Member

    Joined:
    Sep 11, 2010
    Posts:
    3,931
    Location:
    Québec
    Re: ScriptNo: Discussion

    @ lipsin:

    welcome to the forum and thanks for the heads up! :thumb:

    i've been using ScriptNo for a few weeks.
    i don't think i could have spotted these issues as i simply don't understand enough about how these things work.

    thanks again for pointing this out! :)
     
  7. lipsin

    lipsin Registered Member

    Joined:
    Mar 19, 2012
    Posts:
    16
  8. lipsin

    lipsin Registered Member

    Joined:
    Mar 19, 2012
    Posts:
    16
    Re: ScriptNo: Discussion

    Scriptno popularity grow day by day.

    Many tech site, show promote this as the noscript alternative for chrome, even aggressive as the www now so sensitive to privacy or security things.

    The UI and control it present, for me is much more nicer than firefox noscript.

    But if this defect is true, it just can't be trusted, too scary.

    The result is not what user expect and maybe even provide false expectation to user.

    for me this is not just yet another bugs like usual, but this almost made the extension useless, the user can't be sure the extension run as what it shown to user.
     
  9. EboO

    EboO Registered Member

    Joined:
    Mar 12, 2011
    Posts:
    287
    Re: ScriptNo: Discussion

    Just wait until this summer and noscript will incoming :)
     
  10. lipsin

    lipsin Registered Member

    Joined:
    Mar 19, 2012
    Posts:
    16
    Re: ScriptNo: Discussion

    Insider news? Firefox NoScript chrome port?:D
     
  11. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Re: ScriptNo: Discussion

    I'm not sure when Maone will port it. If we consider ScriptNo at the very least a successful POC (I would call it more than that as it's actively improved) than NoScript could come at any time.

    That said Maone may not want to bring NoScript to Chrome unless he can bring every feature, including XSS and ABE to Chrome, which won't happen.
     
  12. lipsin

    lipsin Registered Member

    Joined:
    Mar 19, 2012
    Posts:
    16
    Re: ScriptNo: Discussion

    Glad to hear that.

    Hook on the scriptno extreme detail control to user (UI much more better than noscript)
    Too bad the latest version is just a disaster.

    Hopefully Scriptno developer resume working on Scriptno soon.
     
  13. EboO

    EboO Registered Member

    Joined:
    Mar 12, 2011
    Posts:
    287
    Re: ScriptNo: Discussion

    I found it on the official forum, forum the developper himself. I've lost the link sorry but i can search it again.
     
  14. moontan

    moontan Registered Member

    Joined:
    Sep 11, 2010
    Posts:
    3,931
    Location:
    Québec
    Re: ScriptNo: Discussion

    the dev is a student at the U of Toronto.

    he might be a little busy ;)
     
  15. EboO

    EboO Registered Member

    Joined:
    Mar 12, 2011
    Posts:
    287
  16. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Re: ScriptNo: Discussion

    I wonder what's taken so long. And I'm interested to see what he manages to implement.
     
  17. lipsin

    lipsin Registered Member

    Joined:
    Mar 19, 2012
    Posts:
    16
    Re: ScriptNo: Discussion

    Recently chrome just enable the webrequest api.

    httpseverywhere also surface because of this.

    adblock and ghostery also only recently adopt the api。

    maybe he just wait the dust settle to start working on it.

    beside that his chrome comment usually not that good when compare to firefox. maybe also need to overcome some personal preferences.
     
  18. lipsin

    lipsin Registered Member

    Joined:
    Mar 19, 2012
    Posts:
    16
    Re: ScriptNo: Discussion

    from his twitter maybe he working now.

    he said he would look into it, but seem that is few week ago.

    my own opinion. he should take down the latest version for now and push the old version as stop gap measure.

    at least the old version still working although not perfect.

    while the latest version defect, some time made it function like chrome default javascript blocking feature.

    the sad part now is it give false privacy/security expectation to user.
     
  19. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Re: ScriptNo: Discussion

    I'm not really experiencing any issues, honestly. I can see what scripts are loading on the page and when I block them, they're blocked.
     
  20. lipsin

    lipsin Registered Member

    Joined:
    Mar 19, 2012
    Posts:
    16
    Re: ScriptNo: Discussion

    Just test with a clean profile. Most of the time other extensions like adblock or ghostery do the jobs of blocking and cloak the situation.

    Install scriptno only.

    just enter 2 site:
    www.google.com
    or
    http://optimalcycling.com/other-projects/notscripts/

    enter those site from address bar.

    cannot miss the effect, google black bar drown down menu should not work, and the notscript site test area should not pop up multiple windows when click

    and you will see the initial load never block anythings, even you explicit deny or distrust google domain.

    only a 2nd refresh will start to block.

    scriptno old version does not have this problem.

    latest version with webrequest api got this problem and also the old experimental version with webrequest api turn on.

    this is just defect 1.

    defect 2 describe on above post is even scary.

    just test the link in clean profile.

    even an explicit distrust of the "IntenseDebate" commenting platform also load the script.

    all test in chrome 18 beta in windows, linux and mac platform.
     
  21. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Re: ScriptNo: Discussion

    The black bar isn't loaded with Javascript. Try clicking any of the linkns - you'll realize that it's just html hyperlinks.

    It blocked it fine here.

    It may be having some issues, I'll have to look further on a clean profile. But it seems plain that it's blocking scripts on many sites if only because those sites outright break.
     
  22. lipsin

    lipsin Registered Member

    Joined:
    Mar 19, 2012
    Posts:
    16
    Re: ScriptNo: Discussion

    Google Black Bar Drop Down Menu (on the far right)

    Yes Google Home Pages is scripted. If we disable javascript in Chrome itself everything does not work.

    Clean Chrome 18 with new profile + Scriptno

    Several screenshot attach below with RED region which not suppose to appear if script does not execute or not allowed.

    Note:

    Applicable to default option (everything blocked by default), but this time i explicit deny/distrust those site to show, it does not honor the settings.

    Applicable to new tab, manual input url from address bar or click from bookmarkbar or some weird button or link click.

    Not applicable to right click open link, or control - click / command - click on link.

    And everything blocked after we refresh the page.
     

    Attached Files:

    • 1.png
      1.png
      File size:
      119.3 KB
      Views:
      3
    • 2.png
      2.png
      File size:
      234.6 KB
      Views:
      5
    • 4.png
      4.png
      File size:
      174 KB
      Views:
      4
    • 3 2.jpg
      3 2.jpg
      File size:
      36.2 KB
      Views:
      4
    Last edited: Mar 22, 2012
  23. lipsin

    lipsin Registered Member

    Joined:
    Mar 19, 2012
    Posts:
    16
    Re: ScriptNo: Discussion

    This is what NoScript or Scriptno (Old version) result.

    Using Firefox noscript as example.
     

    Attached Files:

    • 11.png
      11.png
      File size:
      79.8 KB
      Views:
      5
    • 22.png
      22.png
      File size:
      187.1 KB
      Views:
      1
    • 33.png
      33.png
      File size:
      54 KB
      Views:
      1
    • 44.png
      44.png
      File size:
      125.4 KB
      Views:
      1
  24. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Re: ScriptNo: Discussion

    See, that's strange because when I go to youtube and ytimg isn't whitelisted it really does block all of those images.
     
  25. lipsin

    lipsin Registered Member

    Joined:
    Mar 19, 2012
    Posts:
    16
    Re: ScriptNo: Discussion

    Discover new weird behaviour thanks to you.

    Setup: Ubuntu 12.04 beta + Chrome 17 stable + Scriptno 1.0.6.2

    Usual step:

    1) Open Chrome.
    2) Manual enter "youtube.com"
    3) Observe the result.

    Part 1:

    Fresh Chrome browser no cache data.

    Perform the step.

    Indeed no image display.

    Close and exit browser.

    Part 2:

    Reopen Chrome.

    Perform the step.

    Now it got image display.

    and reproduce everytime.
     

    Attached Files:

    • 011.jpg
      011.jpg
      File size:
      79 KB
      Views:
      3
    • 022.jpg
      022.jpg
      File size:
      75.2 KB
      Views:
      2
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.