New Update NoScript Security Suite

+1 :)

no_script.jpg
 
NoScript 13.5.6 (already released for Firefox)
v 13.5.6
============================================================
x file:// quirk mode compatibility, thanks peterbg for
reporting
x Add option to disable automatic page reloading on
permissions change (fixes issue #42)
 
I installed NoScript for old times sake and noticed it has an easy/allow option (reverting the default deny to default allow: "Automatically apply top-document's permissions to subdocuments and inclusions not configured yet"). I also enabled the third option (blocking top document capabilities in sub documents).
1768030735590.png


When I visited CNN and BBC I noticed that the CUSTOM icon is replaced by "temporarily AUTO-TRUSTED" with a clock.

When I clicked on the AUTO-TRUSTED icon, it changed to old CUSTOM icon (clicking custom allowed me to set custom capabilities for a domain).
 
Last edited:
The Chrome sandbox has probably become so strong that the need for additional containment has lowered. Also uBO with its dynamic filtering (on Firefox) probably took a big bite out of NoScript's user base. NoScript used to have a block all (first and third-party) risky stuff mode and a block only third-party risky stuff (temporarely set top domain to trusted).

This new mode adds a third mode (allow all, blacklist some by setting it to untrusted). Use case I can think of is are Brave and Vivaldi users who want to see what is happening under the hood with Noscript (is easier than using the browser's inspect mode) and may blacklist stuff missed by the build-in adblocker.
 
The Chrome sandbox has probably become so strong that the need for additional containment has lowered. Also uBO with its dynamic filtering (on Firefox) probably took a big bite out of NoScript's user base. NoScript used to have a block all (first and third-party) risky stuff mode and a block only third-party risky stuff (temporarely set top domain to trusted).

This new mode adds a third mode (allow all, blacklist some by setting it to untrusted). Use case I can think of is are Brave and Vivaldi users who want to see what is happening under the hood with Noscript (is easier than using the browser's inspect mode) and may blacklist stuff missed by the build-in adblocker.

Chrome sandbox does not reach its full potential by default.
 
  • Like
Reactions: LinuxFan58
I am playing with this new easy-allow NOScript mode in my Brave surfing profile for a few days (to find out whether a blacklist and anomaly tripwire has any practical use).

Because TRUSTED is the new DEFAULT (auto-trusted) mode, I decided to allow in TRUSTED only common capabilities to make it new default :-). Most websites should run fine with only below common capabilities (scripts, media, iframes, font, xmlhttprequests, lazy load and cascading style sheets).

1768033689026.png


To have a one-click allow all option, I used the DEFAULT profile to allow all, except depreciated plugins (objects) and LAN-access (I don't see why websites should access your LAN, maybe more knowledgeable members could explain what the use case for LAN-access is).
1768033921665.png


In this adopted EASY-ALLOW mode BBC.com and CNN.com work fine. I will test ride this setup for a few days and report issues encountered. Because scripts and subframes are still allowed it does not reduce third-party exposure a lot. By disabling less used capabilities this reduces the attack surface a bit, but its value lies in anomaly detection (NoScript will show blocked number in the icon when a website requires more capabilities, by setting it to default you can grant additional capabilities).
 
Last edited:
NoScript 13.5.7 (already released for Firefox)
v 13.5.7
============================================================
x [nscl] Improved document freezing and CSP insertion
x Control manually navigated top-level data: URIs
(tor-browser#44482)
 
NoScript 13.5.9 (seems released only for Firefox)
v 13.5.9
============================================================
x Fix missing https-only icon regression (thanks Ingo Brückl for reporting)



v 13.5.8
============================================================
x Fix site label misalignment (thanks Ingo Brückl for reporting)
 
NoScript 13.5.10 (released for Firefox and later for Chrome)
v 13.5.10
============================================================
x [UX] Smoother popup initialization
x [UX] Scrolling area optimization
x [UX] Fickering reduction
x [UX] Various visual tweaks
 
NoScript 13.5.12 (already released for Firefox)
v 13.5.12
============================================================
x Convert PNG images to WEBP
x [UX][Android] Improve support for increased font size
configurations
x Make deploy2tor.sh default to latest unpacked firefox
manifest.json
x [UX] Fix first selected preset not being focused
automatically on popup opening (issue #506)
x Prevent mid-session updates on Android in global PMB
(tor-browser#44398)
x [UX] Fix keyboard navigation regression (issue #506)
x [UX] Improved readability of focused icon buttons