Opened 7 years ago

Last modified 3 years ago

#4794 reopened defect

NoScript Is Not Being Used Properly By The Tor Project

Reported by: DasFox Owned by: mikeperry
Priority: Medium Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: NoScript
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

Hi,

This isn't a bug, but I'm reporting this because this is not being handled correctly.

One of the main points of NoScript is not to allow anything, other than what is in your 'Whitelist', yet the Tor Project has set in the General options; 'Scripts globally allowed (dangerous)'

I think someone at Tor has overlooked that 'Dangerous' part, because this is not the correct method in which to use this application. In fact it seems silly the developer even has this option in NoScript.

I do know for a fact when you allow like this, then you let JavaScript leak out, creating more of a risk, so regardless of using Tor or not, this is not a good approach for the Tor Project
to be taking with NoScript and the Tor Browser Bundles should have this unchecked by default to give people the safest configuration possible.

Right now you are teaching people the incorrect way in which to use this and for those people, they are going to possibly look at Tor and mimic what they see for Firefox and make even a greater risk for themselves with Firefox through their ISP,etc...

Granted it doesn't make it the simplest, but people should learn to adjust, because it's the proper way in which you are suppose to be using this addon.

Also the Tor Project will need to change the 'Appearances' section to properly reflect this as well.

I've attached a screen shot how the 'Appearances' section looks in NoScript, of course with the 'Scripts globally allowed (dangerous)' unchecked. :)

THANKS

Child Tickets

Attachments (1)

noscript.png (37.3 KB) - added by DasFox 7 years ago.

Download all attachments as: .zip

Change History (3)

Changed 7 years ago by DasFox

Attachment: noscript.png added

comment:1 Changed 7 years ago by mikeperry

Resolution: not a bug
Status: newclosed

comment:2 Changed 3 years ago by bugzilla

Component: Firefox Patch IssuesApplications/Tor Browser
Milestone: TorBrowserBundle 2.2.x-stable
Resolution: not a bug
Severity: Normal
Status: closedreopened

This design should be revised.
Comments of NoScript devs are welcome.

Note: See TracTickets for help on using tickets.