By James RoperPosted Wednesday 10th December 2008 03:13 GMT
The NoScript plugin can't help you with any Facebook security vulnerabilities... To use Facebook, you need Javascript, so you need Facebook whitelisted in the NoScript configuration. Because it's whitelisted, you are now vulnerable to any XSS attacks, because XSS vulnerabilities usually mean injecting Javascript into files that are sourced from Facebook. So, either you use Facebook, and are vulnerable whether you have NoScript installed or not, or you don't use Facebook, in which case you don't need NoScript to protect you.
By RopataPosted Wednesday 10th December 2008 05:57 GMT
NoScript is able to distinguish XSS from JavaScript running locally. Its XSS filter even remains active when you allow js globally. For example embedded Youtude vids are blocked until you explicitly allow them.
And *everybody* should use NoScript -- XSS attacks are very common, and malicious js is not just limited to obscure corners of the web. Even big sites get compromised sometimes.
By Anonymous CowardPosted Wednesday 10th December 2008 08:59 GMT
And frankly anyone not using NoScript, AdBlock Plus and Adblock Filterset.G Updater is a bit stupid. And anyone not capable of or getting annoyed over operating NoScript shouldn't be let anywhere near a computer.
By Leo DavidsonPosted Wednesday 10th December 2008 09:09 GMT
I tried using NoScript. I love the idea of it in principal. Unfortunately half an hour of using it will made me realise how much of the web depends on Javascript. The majority of sites I visited were completely broken and I have to keep whitelisting things to the point that it seemed utterly pointless.
If pretty much breaking the entire Internet is your idea of a fix then I'd rather be broken. Here's a similar fix: Turn off your computer.
I went back to using Flashblock instead.
I'd love it if Javascript wasn't used so (IMO) gratuitously. (It's used wonderfully on many sites but on others, where you're being served a static page, it makes me wonder WTF the site authors were thinking.) If I only had to whitelist a few sites, like I do with Flashblock, then NoScript would be great. Having to whitelist a huge number of sites is a giant hassle and makes me question what I'm protecting myself from when so many things are granted an exception.
By Jason DePriestPosted Wednesday 10th December 2008 17:00 GMT
Hey AC, Adblock Filterset.G does not work with AdBlock Plus and, in fact, the AdBlock Plus folks tell you not to install it if you have AdBlock Plus (http://adblockplus.org/en/faq_project#filterset.g).
I wonder if Firekeeper would catch it... it picks up some other attacks.
Comments on: Facebook ignores huge security hole for four months
Easier answer #
By Moss Icely Spaceport Posted Wednesday 10th December 2008 03:12 GMT
NoScript won't help you. #
By James Roper Posted Wednesday 10th December 2008 03:13 GMT
Is it just me... #
By Anonymous Coward Posted Wednesday 10th December 2008 03:54 GMT
"an ugly worm dubbed Koobface" #
By James O'Brien Posted Wednesday 10th December 2008 05:20 GMT
But James, XSS is *remote* script! #
By Ropata Posted Wednesday 10th December 2008 05:57 GMT
How fast? #
By TeeCee Posted Wednesday 10th December 2008 08:23 GMT
NoScript Does Work #
By Anonymous Coward Posted Wednesday 10th December 2008 08:59 GMT
Top marks #
By Matthew Joyce Posted Wednesday 10th December 2008 09:05 GMT
NoScript: The cure is worse than the disease. #
By Leo Davidson Posted Wednesday 10th December 2008 09:09 GMT
@ James O'Brien #
By Jim Carter Posted Wednesday 10th December 2008 09:15 GMT
I reckon... #
By Farai Posted Wednesday 10th December 2008 09:59 GMT
Patched? #
By Anonymous Coward Posted Wednesday 10th December 2008 10:29 GMT
NoScript's Anti-XSS protection, James #
By Giorgio Maone Posted Wednesday 10th December 2008 10:30 GMT
'Within three hours of posting this story...' #
By Aaron Posted Wednesday 10th December 2008 13:52 GMT
@Ropata #
By Dave Posted Wednesday 10th December 2008 14:18 GMT
Examples don't work here... #
By Pierre Posted Wednesday 10th December 2008 15:23 GMT
@Pierre #
By Moddy Posted Wednesday 10th December 2008 16:27 GMT
bad advice #
By Jason DePriest Posted Wednesday 10th December 2008 17:00 GMT
I told ja, I told ja! #
By Pete "oranges" B. Posted Thursday 11th December 2008 03:02 GMT