The NoScript Misnomer
thehackerblog.com
thehackerblog.com
Regardless, I've replaced both extensions with uBlock Origin. While UB in default deny mode is not as fine grained as NS, it does the job and doesn't compromise on default whitelists at the expense of a little breakage (gorhill is very adamant on this point).
This is probably overkill for the average person, but after so many years of using noscript+requestpolicy I am used to sites being broken by default and having to fix them if needed, to me this is an acceptable tradeoff for the increased security.
The only exception to this rule for me is when I order something on a website, in that case I find it too risky to run with tight blocking (due to redirections to the payment site and so on) and just run a completely default firefox in its own vm that I snapshot before and revert to after.
Warning: Hosts file too large. Could cause problems with Windows DNS Cache.
What is difference between uBlock and uBlock Origin?
EDIT: From Google searches I have learned that uBlock Origin started as fork of uBlock, but maintained by the guys who started uBlock.
You make it sound like NoScript should not be trusted. In reality, nothing is secure but NoScript is one of the better security options (perhaps best?) for helping to prevent a specific set of attacks that use js to enable.
A flaw was found - and promptly fixed. You are (inadvertently I believe) leading people to drop NoScript and possibly go with something else. Another less mature security tool will have its own share of flaws - likely months or years until they will reach relatively similar ground as NoScript.
No, NoScript does not protect against JS browser vulnerabilities.
Of course it does, it's just not perfect.
That is quite different from protecting against JS browser vulnerabilities.
Now, if NoScript added JS sandboxing of some advanced variety employing heuristics such that it detected attempts to exploit vulnerabilities and blocked that code (whilst avoiding solving the halting problem!), then I'd consider a weaker form of the statement, such as "NoScript protects against many JS browser vulnerabilities", as true. But AFAIK, it doesn't do anything like that.
It doesn't even employ signature based techniques that could also protect against some vulnerabilities.
Those 5 organizations have easier ways to attack you than rely a relatively little used extension to a relatively little used web browser. And attacking any of those 5 organizations is no easy feat.
Firefox + NoScript is still one of the best bang for the buck security improvements any ordinary user can make. Is it foolproof? heck no. Will it stop even a brainless script kiddie intent on hacking you? Not necessarily. But it will eliminate a number of drive by attacks.
Readers should keep converting their moms and dads and grandmas to Firefox + NoScript. Simple and great bang for the buck security.
Two things that may not be intuitively clear to every reader:
1. No way do all of those sites actually do full security audits for every .js file on their domain. (Google comes close.)
2. The specific kind of security flaw we're talking about is not necessarily "interesting" outside the context of NoScript. There are plenty of clientside DOM corruption bugs that don't even get documented, let alone fixed, because they can't easily be used to compromise a user session. But they will work fine for getting the right chunk of malicious JS delivered to end-users.
I'm not anti-NoScript. But don't kid yourself about its utility against browser JS vulns. Before you get your dad to install NoScript, make sure he's patched. Try to get him to switch to Chrome while you're at it.
The whitelist did surprise me last time, though. I was baffled why gmail was working without me having to permanently allow it. Then I discovered the whitelist. Woah. What a dumb idea.
https://github.com/avian2/noscript
For example, this seems to be the change that was pushed as a response to this discovery:
https://github.com/avian2/noscript/commit/398ae6eadd2f40c8b7...
Oh dear.
Edit:
I reported it on the same thread since it's still active.
Edit: Someone else reported it, it seems.
The article itself mentions that a patch was pushed within hours of contacting the author. Not much vetting can be done in such short time.
Btw., like a few others have noted for theirs, my whitelist does not contain those entries in question. It might be because my installation is relatively old and they weren't pushed retroactively.
>Giorgio doesn't generally add CDNs to the default whitelist. I'm not sure why he added googleapis.com, except that google.com is already on the default whitelist (so people can use GMail to get support), and googleapis.com is controlled by Google anyway.
My whitelist did not contain this domain, possibly because updates don't change the whitelist retroactively. Which is a good thing if it is part of a policy to never update a users whitelist without them knowing.
Until I see a real audit that looks at bypassing noscript code, I will continue using and promoting noscript as a great tool for safe browsing. No one can deny that a large majority of web exploits use javascript to launch, even when the exploit is in another media or protocol like MS Office or Adobe flash.
Noscript is powerful but it was also never aimed at the general public. In my opinion the general public can benefit from it but only as a shield against unwanted website loading from unknown domains. Because anyone who is not very experienced in the web and able to tie domains to website features will simply use the "allow this page temporarily" feature.
Which in my opinion is fine, it's better protection than not having noscript. But it's not the way noscript was designed to be used.
I personally switched to Policeman (https://addons.mozilla.org/en-US/firefox/addon/policeman/) a while ago, and there it's pretty clear that you can remove the built-in rule set.
I actually like it better than uMatrix: policeman shows you the full url of the blocked resource that you can inspect before allowing, and cross-domain request are very easy to follow.
The only thing I wished is per-domain control of most modern browser extensions, like, for example: disable CSS animations everywhere except when I allow it to. Likewise for <audio>, <media>, GL, and whatever useless feature I don't need 99.99% of the time.
uMatrix has already per-domain boolean control of "agent spoofing" and related settings, it would be awesome if the above would be included there.
NoScript was a bit more forward thinking in that regard: you can disable media/GL globally except for whitelisted sites, but then again without cross-domain control you end-up whitelisting everything.
As for the claim of any subdomain on any website it depends on your settings. Again I haven't used it in a while, but I do know that it was definitely highly configurable.
Edit:
Didn't finish my thought but: It's not too hard to remove links you don't trust from the list since it's not so big, I actually have to say I find the majority of URL's on the list to be quite helpful, especially when trying to figure out how to safelist hotmail with all the numerous domains they use.
I thought that was the reason you installed NoScript?
Stopping javascript isn't going to stop tracking anyway - the big players still track who's loading their button images, for example.
Maybe it fights some tracking as a side effect, but that's not the reason you install it, because it's not made for that and therefore is not very effective.
Also, CDNs are quite problematic since they are often hosting many different scripts of which you only want to allow some. A finer-grained path/subdomain matching would be ideal here - you could allow * .example.com, example.com/*, or example.com/script.js.
http://who.is/whois/zendcdn.net
Domain had registered on June 12, 2015
A site is on the default whitelist of the addon that can contain a malicious payload. Any site on the internet could therefor have a link to this payload. Granted, I'm not sure what sort of malicious JS payloads there are, other than crashing a browser, that doesn't involve some XSS.
NoScript isn't a comprehensive security/privacy suite. It's just a crucial component.