One at least needs to have JavaScript disabled when on Tor or you'll easily be compromised and Firefox 23 now ships with JavaScript always-on.
http://boingboing.net/2013/08/04/anonymous-web-host-shut-dow...
One at least needs to have JavaScript disabled when on Tor or you'll easily be compromised and Firefox 23 now ships with JavaScript always-on.
http://boingboing.net/2013/08/04/anonymous-web-host-shut-dow...
[1] The version numbers are here https://blog.torproject.org/blog/new-tor-browser-bundles-and... Note: these version numbers were not vulnerable to the exploit, patched in June & note the day the exploitation took place (August)
[2] Background on deterministic builds and binary verification http://lwn.net/SubscriberLink/564263/1ab0ab93a900ecea/
Of course, it increases the surface area of attack for exploits, but is there something else I'm missing?
It's on by default, as it always has been. And the option to turn it off was removed from the main options dialog. This is for sensible reasons -- many users turn it off either accidentally, or without understanding what it means ("this must be that insecure Java thing I keep hearing about") which breaks many websites.
But the 0.01% of people who like to browse without JS enabled can still do so via about:config -- look for "javascript.enabled". Or they can use an add-on. Or they can wait a version or two (I'm not sure the exact timeline) whereupon you'll be able to disable it via the developer tools UI.
> It's on by default, as it always has been.
You're being overly pedantic and I'm sure you knew what I meant when I said it ships always-on.
Disagree.
> He's a Firefox developer, the clarifications are interesting
That's good. Then he ought to recall what's in the release notes for Firefox 23: http://www.mozilla.org/en-US/firefox/23.0/releasenotes/
> "Enable JavaScript" preference checkbox has been removed and user-set values will be reset to the default