ScriptSafe former ScriptNo: Discussion

Discussion in 'other software & services' started by andryou, Nov 15, 2011.

  1. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,066
    Location:
    Canada
    Re: ScriptNo to ScriptSafe

    This could be awesome! :thumb: I thought it was left for dead. Looking forward to checking it out later.
     
  2. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Re: ScriptNo to ScriptSafe

    I prefer the name change. And I'm glad he's using manifest 2.
     
  3. andryou

    andryou Registered Member

    Joined:
    Nov 15, 2011
    Posts:
    21
    Re: ScriptNo: Discussion

    Sorry for not being around folks, I've been busy with life (I'm at the stage where a person needs to make major decisions regarding family, schooling, work, and juggling the three while having some sort of social life alongside a full-time job).

    v1.0.6.4 has just been released, where I've beefed up the cross-device auto-syncing of settings and whitelists/blacklists (introduced in v1.0.6.3). It also seems that with the update to Manifest version 2, inline script blocking is somewhat more reliable (e.g. http://www.isjavascriptenabled.com/), and some past-reported bugs are now magically fixed.

    Again, the seemingly intermittent inline script blocking is something that is currently out of my control; I've tried to make do with what APIs and data are available upon page load to have inline scripts blocked as quickly as possible (using onBeforeSendHeaders).

    I just want to re-iterate: ScriptSafe (formerly ScriptNo) DOES NOT have the functionality as NoScript; my desire is to give you as much control over what pages are allowed/disallowed to load.

    Happy holidays everyone, and again, my apologies for not being around.

    EDIT: here are the changelogs for v1.0.6.3 and v1.0.6.4:

    v1.0.6.4 - Saturday, December 29, 2012
    - Implemented webbugs patch from martin.b
    - Fixed issue where the close button in the ScriptSafe details popup won't close the popup
    - Streamlined syncing to take up significantly less nodes
    - Improved support for the syncing of very large blacklists/whitelists
    - Added a notification pop-up that will appear in the bottom-right corner of your screen when your settings have been successfully synced (you can disable this in the Options page)
    Note: this WILL NOT show when settings have been synced FROM your Google Account, only TO, to prevent headaches ;)
    - Added the ability to force Settings Syncing TO and FROM your current device in the Options page
    - Auto-syncing will occur 30 seconds after the last settings/whitelist/blacklist update in order to ensure compliance with the rate limits Google has set (10 per minute and 1,000 per hour)
    - Added maps.gstatic.com to the default whitelist for new users for Google Maps Streetview support

    v1.0.6.3 - Thursday, December 27, 2012
    - Happy Holidays everyone :) I stayed up overnight developing and testing one of the most anticipated features for ScriptNo/ScriptSafe, which is... Cross-Device Settings Auto-Syncing! (settings = your configuration AND your whitelist/blacklist!)
    - Updated to Manifest v2 (more efficient, more secure)
    - Renamed to "ScriptSafe" from "ScriptNo"
    - Updated unwanted domains blocklist with latest lists
    - Default whitelisting of Gmail and YouTube for new installations only (to be less disruptive for new users)
     
    Last edited: Dec 29, 2012
  4. moontan

    moontan Registered Member

    Joined:
    Sep 11, 2010
    Posts:
    3,931
    Location:
    Québec
    Re: ScriptNo to ScriptSafe

    not a problem andryou.
    there are lot more important things in life than software.
    im happy to see you have your priorities straight. :)
     
  5. tlu

    tlu Guest

    Re: ScriptNo to ScriptSafe

    Indeed, script blocking seems to be more reliable now. Thanks for the update, Andrew :thumb:
     
  6. woomera

    woomera Registered Member

    Joined:
    May 21, 2004
    Posts:
    212
    Re: ScriptNo to ScriptSafe

    i think the creator made the right choice by changing the name. no more confusion with the noscript extension for FF so it can now stand out more.
     
  7. woomera

    woomera Registered Member

    Joined:
    May 21, 2004
    Posts:
    212
    Re: ScriptNo: Discussion

    i decided i install this extension today, ive been using the built-in blocker till now but i have a question,

    does ScriptSafe support blocking of plugins as well? i wanna know so i can enable the overlapping settings in chrome.
     
  8. andryou

    andryou Registered Member

    Joined:
    Nov 15, 2011
    Posts:
    21
    Re: ScriptNo: Discussion

    It does, (e.g. object, embed, applet, video, audio), it works well with PDF files during my tests :)

    You have the power of choice, try running both concurrently, or one or the other and see which works best for you.

    Also, thank you all for your kind words!

    EDIT: It's now 7:08am, calling it a night, good night everyone!
     
    Last edited: Dec 29, 2012
  9. woomera

    woomera Registered Member

    Joined:
    May 21, 2004
    Posts:
    212
    Re: ScriptNo: Discussion

    thank you for your reply, and good night.
     
  10. woomera

    woomera Registered Member

    Joined:
    May 21, 2004
    Posts:
    212
    Re: ScriptNo: Discussion

    btw i forgot, i have a feature request, is it possible to add an option to sync rules with the built-in blocker?
    e.g. if i create a trust rule for google.com in scriptsafe then a rule automatically created under java & plugin settings with ALLOW option.

    thank you
     
  11. andryou

    andryou Registered Member

    Joined:
    Nov 15, 2011
    Posts:
    21
    I'll look into that, I've just released a series of updates fixing some bugs:

    v1.0.6.9 - Saturday, December 29, 2012
    - v1.0.6.9: fixed syncing issue by adding a check (user setting); miscellaneous bug fixes; note: syncing does not seem to be working for MacOS: https://code.google.com/p/scriptno/issues/detail?id=153
    - v1.0.6.8: fixed major bug where whitelist/blacklist would seem to be "erased". Created a built-in restore process to restore your lists. My sincere apologies everyone.
    - v1.0.6.5: fixed a minor potential issue with importing synced whitelists/blacklists into ScriptSafe

    https://chrome.google.com/webstore/detail/scriptsafe/oiigbmnaadbkfbmpbfijlflahbdbdgdf

    MacOS issue ticket opened on the Google Code Project I've set up: https://code.google.com/p/scriptno/issues/detail?id=153
     
  12. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,066
    Location:
    Canada
    Thank you so much, andryou! Indeed, you have to do what's most important for you and your family :)
     
  13. emmjay

    emmjay Registered Member

    Joined:
    Jan 26, 2010
    Posts:
    1,547
    Location:
    Triassic
    Re: ScriptNo to ScriptSafe

    I would like to know what that actually means. What is the manifest? The developer says that it makes it more secure. I googled manifest 1 and got a zillion hits, so it is going to be pretty much impossible for me to chase this down myself. If you don't mind, can you just give me a little tutorial on what the manifest is and why 2 is better than 1. It would be much appreciated.
     
  14. 1chaoticadult

    1chaoticadult Registered Member

    Joined:
    Oct 28, 2010
    Posts:
    2,342
    Location:
    USA
    Re: ScriptNo to ScriptSafe

    http://developer.chrome.com/extensions/manifestVersion.html
     
  15. emmjay

    emmjay Registered Member

    Joined:
    Jan 26, 2010
    Posts:
    1,547
    Location:
    Triassic
    Thank you.
     
  16. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Manifest 2 supports new content security policy and new features. One such feature is page detection of the extension - you can set it so that pages won't know what extensions are running. This is good for preventing fingerprinting, for one example.

    Content Security Policy is a really powerful way to make extension more secure, by forcing them to only load resources that are previously defined. You can force HTTPS this way, you can prevent XSS, you can prevent MITM, etc.

    There are some new capabilities like sandboxing eval(), and more.

    @AndrYou,

    Does the latest ScriptSafe use CSP?

    edit: isjavascriptenabled.com still loads "Yes".
     
    Last edited: Dec 30, 2012
  17. tlu

    tlu Guest

    Isn't CSP an integral part of Manifest 2?

    Not here! It doesn't show neither "Yes" nor "No". Only if I reload that site I see "no" flash up for the fraction of a second.
     
  18. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Yeah, I suppose it is.

    After a reload a I get "No" but that's always been the case. I consistently get "Yes" on first visit.
     
  19. The Red Moon

    The Red Moon Registered Member

    Joined:
    May 17, 2012
    Posts:
    4,101
    hi,
    Ive installed this extension but now lastpass will not log me into sites automatically.
    Any help please.?
    Thanks.o_O
     
  20. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,066
    Location:
    Canada
    Maybe scriptsafe is blocking the lastpass.com cookies?
     
  21. Brandonn2010

    Brandonn2010 Registered Member

    Joined:
    Jan 10, 2011
    Posts:
    1,854
    Does this still suffer from the asynchronous nature of Chrome, so scripts may load on a page before the extension loads?
     
  22. The Red Moon

    The Red Moon Registered Member

    Joined:
    May 17, 2012
    Posts:
    4,101
    hi and thanks.
    Problem solved,i use the extension button to allow the sites and now everything runs fine.:thumb:
     
  23. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,066
    Location:
    Canada
    Just a request, how about the option to "Allow all temp permissions" ?
     
  24. andryou

    andryou Registered Member

    Joined:
    Nov 15, 2011
    Posts:
    21
    wat0114: if you're in Block mode, you'll be able to see "Allow All Blocked For Session" in the popup widget. Is this what you want? :) (and vice-versa if you're in Allow mode)

    A new update! v1.0.6.10:

    v1.0.6.10 - Monday, December 31, 2012

    v1.0.6.10: made syncing more robust (tested extensively between my two PCs); added an option to be notified when settings are synced FROM your Google account; tweaked popup widget "Clear" button behaviour; fixed minor bug in Options page (when removing a domain from a whitelist/blacklist)

    Happy New Year everyone!
     
    Last edited: Dec 31, 2012
  25. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,066
    Location:
    Canada
    Actually, only the selected domains I've allowed temporarily. Thanks and a Happy New Year to you as well :)
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.