The article states that every time the plugin updates, it automatically opens up a webpage that serves malware. So technically the article is not wrong. NoScript forces your browser to open a malicious page, therefore it can be considered itself harmful.
You have to disconnect from the internet, restart Firefox, let it fail to load the page, then go to the settings menu and uncheck the box.
Now, the question is, do I trust a plugin that serves ads for malware?
BTW any info on when did they start doing that?
If I were to personally inspect every software (and hardware where possible) I use I would barely be up to date on 1995 versions of computing.
I outsource this trust to an aggregation of online communities I believe in. This post dramatically lessens my trust in NoScript.
It opens a page with an advertisement link for "Speedup My PC", not even the article claims that it serves malware, just that it "promotes" it. Going by the description of the detected malware signatures Speedup My PC isn't even harmfull by itself, it just is snake oil with no real use bejoind selling its own license.
Unless you click the link, download the exe, install it, fall for the detected issues notification and then proceed to buy a license nothing will happen.
This was fixed in Tor Browser 6.0.5[1] and Firefox 49[2]. Worth noting that the attack required a publicly-trusted certificate for addons.mozilla.org, which makes this a bit harder than just a run-of-the-mill MitM attack, though certainly possible for nation-state actors and the likes.
[1]: https://blog.torproject.org/blog/tor-browser-605-released
[2]: https://www.mozilla.org/en-US/security/advisories/mfsa2016-8...
In the most narrow sense. Since I can't in good conscience recommend it to normal people I am considering it harmful.
You can't really recommend it to normal people even without considering the author's advertising practices. NoScript is a tool for power users who understand a few things about how the web works.
uMatrix allows more fine-grained control than NoScript. It's basically based on three contexts (scopes): host, domain and global, but my experience is I only ever use the global and domain scopes. I would recommend starting by globally white-listing the popular CDNs (so scripts on all sites delivered e.g. through Google's CDN are always executed and <script> snippets to integrate Google widgets work).
Then, for a majority of trusted sites it's enough to just white-list the local domain (allow executing scripts from example.com when you are visiting example.com sites). Scripts included on foobar.org from example.com still remain blocked – this is the crucial difference between global and local scopes that NoScript doesn't lend to.
I would recommend always allowing XHR and iframes in the site-local scope. IIRC this is not in the default config but since XHR anyway requires scripting you can then easily control both XHR / scripting by just white-listing the site for scripting. So this is my uMatrix base configuration currently and a good starting point for migrating from NoScript:
* * * block
* * css allow
* * image allow
* 1st-party cookie allow
* 1st-party frame allow
* 1st-party xhr allow
I.e. CSS / images allowed from all sources (except those blocked explicitly). Cookies, frames and XHR allowed from the same site you are currently visiting. Only scripting must be allowed per-site, just like with NoScript.