LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 02-03-2016, 01:24 AM   #1
Gregg Bell
Senior Member
 
Registered: Mar 2014
Location: Illinois
Distribution: Xubuntu
Posts: 2,034

Rep: Reputation: 176Reputation: 176
Is NoScript a good idea?


I got NoScript as an add-on for Firefox browser. Every website I open it says that a certain number of scripts are currently forbidden. How do I know if the site is dangerous or not? And I have a vague idea of what scripts are but what's so dangerous about them? Thanks.
 
Old 02-03-2016, 07:40 AM   #2
rtmistler
Moderator
 
Registered: Mar 2011
Location: USA
Distribution: MINT Debian, Angstrom, SUSE, Ubuntu, Debian
Posts: 9,883
Blog Entries: 13

Rep: Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930
I've used NoScript for years. Unfortunately I've found it to be, both a helpful/simple process as well as potentially difficult.

Here are my global thoughts and/or $0.02:
  1. I use it and let it stop stuff. From the start, most everything is blocked and I slowly add what I agree with, however I know sometimes it is difficult to determine what should be agreed with
  2. The main website such as linuxquestions.org, I accept, as an example, because I intentionally got there
  3. A secondary script that looks close, like lq-feedback.org, I'd probably accept that, but also ONLY if I felt there were items on a page where I could not see or do stuff, I am actually fine with not accepting a script if I feel that a page I'm looking at operates how I need it too
  4. The more difficult ones are things like my bank. NoScript does print out the list of scripts blocked in the status bar, or also in the NoScript menu. You can "temporarily" accept a script and see what that does for you. You can then also disallow that script if you feel it did you no good, and once you get a page where you want it, you can then make the permissions permanent.
  5. The bigger problems are very active pages, like movie pages, game pages, stuff where advertisement is huge, and the site is more commercial. I only go so far, but if I think I really want to see something (usually I'm not surprised to see that it is something stupid and I needed have bothered actually) I'll temporarily accept all for that page. Only to find that there are now newer added scripts needing to be approved. Sometimes at that point I'll see enough to say, "Gee, do I really want to see this stupid video, versus not? Or I'll choose to forge ahead and accept the next round.
  6. Largely, once I go to enough of my regular web pages and accept the right scripts, things are fine and I have little maintenance for it at all. But bear in mind that I'm probably a very boring web user. For instance I'm already saying that I don't kill myself to play games or watch videos online, so I'm mainly reading stuff, news, technical stuff, or searching for information
 
2 members found this post helpful.
Old 02-03-2016, 07:56 AM   #3
rokytnji
LQ Veteran
 
Registered: Mar 2008
Location: Waaaaay out West Texas
Distribution: antiX 23, MX 23
Posts: 7,101
Blog Entries: 21

Rep: Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474
Quote:
How do I know if the site is dangerous or not?
Install WOT add on and then search the url. I Fly with Ghostery myself instead of No Script.
I know it is not as thorough as No Script but the nets shotgun approach of loading scripts made
using No Scripts a PITA for me.

Edit: To answer your original question. Is it a good idea? Yes it is. I am just a laid back linux user who flys loosey goosey.

Last edited by rokytnji; 02-03-2016 at 08:00 AM.
 
2 members found this post helpful.
Old 02-03-2016, 09:41 AM   #4
rknichols
Senior Member
 
Registered: Aug 2009
Distribution: Rocky Linux
Posts: 4,776

Rep: Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212
It's more of a PITA than it's worth, IMO. All but a tiny fraction of web sites require Javascript. You can spend 10 minutes or so trying to figure out which of the blocked sites on the page need to be allowed to let the page work, but on many sites even "Temporarily allow all this page" needs to be clicked on two or three times in order to get all the necessary levels of scripting allowed. Then there's the issue of commerce sites where at some point you are warned, "Do not reload the page or use your browser's "Back" button or you may be charged twice," and you find yourself stuck on some page that won't load without some script that's still blocked, and you try to allow it in NoScript, only to see the message that the page needs to be reloaded in order to do that. What do you do now? Was your order entered or not? Eventually you learn to "Allow scripts globally (dangerous)" whenever you're doing anything that involves real money.
 
1 members found this post helpful.
Old 02-03-2016, 02:28 PM   #5
timl
Member
 
Registered: Jan 2009
Location: Sydney, Australia
Distribution: Fedora,CentOS
Posts: 750

Rep: Reputation: 156Reputation: 156
I use it in a similar way yo post #2. If I don't have a visible need for a script then do I need it? For example I have been running noscript on LQ for a while now and I have managed quite well without google-analytics
 
1 members found this post helpful.
Old 02-03-2016, 03:06 PM   #6
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,974

Rep: Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623
I almost always use it.

Almost never see a site that doesn't get some stuff blocked.

The more ways you limit exposure the better.

One time it saved my behind. It blocked an advertisement on Popsi.com that was malware.

If I go to a site, I only what that site. You'll see news type pages seem to be the worst.
 
1 members found this post helpful.
Old 02-03-2016, 03:13 PM   #7
Timothy Miller
Moderator
 
Registered: Feb 2003
Location: Arizona, USA
Distribution: Debian, EndeavourOS, OpenSUSE, KDE Neon
Posts: 4,003
Blog Entries: 26

Rep: Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521
Quote:
Originally Posted by rknichols View Post
It's more of a PITA than it's worth, IMO. All but a tiny fraction of web sites require Javascript. You can spend 10 minutes or so trying to figure out which of the blocked sites on the page need to be allowed to let the page work, but on many sites even "Temporarily allow all this page" needs to be clicked on two or three times in order to get all the necessary levels of scripting allowed. Then there's the issue of commerce sites where at some point you are warned, "Do not reload the page or use your browser's "Back" button or you may be charged twice," and you find yourself stuck on some page that won't load without some script that's still blocked, and you try to allow it in NoScript, only to see the message that the page needs to be reloaded in order to do that. What do you do now? Was your order entered or not? Eventually you learn to "Allow scripts globally (dangerous)" whenever you're doing anything that involves real money.

This is how I think. I used to use it, and it works, but managing it is a PITA, and many sites you have to enable SO MUCH to get their content to work (CNN.com, NFL.com) that it does absolutely no good. I also found that the already poor performance of firefox was made even WORSE when noscript was running but allowing everything. So eventually I just gave up and removed it entirely.
 
1 members found this post helpful.
Old 02-03-2016, 03:13 PM   #8
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,623

Rep: Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651
one very GOOD way to start to figure out JUST WHAT that script is doing is to middle click on it's name on the no-script pop up menu

for example here as i type this
cloudflare and netdna-ssl are currently allowed

middle click on "cloudflare" a new tab opens and at the top is the no script " WOT "
click on the link
https://www.mywot.com/en/scorecard/cloudflare.com
and read the opinions

you can also go to the scripts web site
https://www.cloudflare.com/

there is a ton of information available on the middle click option


now as much as i DISLIKE cloudflare this forum USES IT!!! for the top menu

|| home || forums || HGL || reviews || and so on.....
 
4 members found this post helpful.
Old 02-03-2016, 04:06 PM   #9
timl
Member
 
Registered: Jan 2009
Location: Sydney, Australia
Distribution: Fedora,CentOS
Posts: 750

Rep: Reputation: 156Reputation: 156
Thanks for that John. A lot of information to be gleaned.
 
Old 02-03-2016, 09:06 PM   #10
Gregg Bell
Senior Member
 
Registered: Mar 2014
Location: Illinois
Distribution: Xubuntu
Posts: 2,034

Original Poster
Rep: Reputation: 176Reputation: 176
Quote:
Originally Posted by rtmistler View Post
I've used NoScript for years. Unfortunately I've found it to be, both a helpful/simple process as well as potentially difficult.

Here are my global thoughts and/or $0.02:
  1. I use it and let it stop stuff. From the start, most everything is blocked and I slowly add what I agree with, however I know sometimes it is difficult to determine what should be agreed with
  2. The main website such as linuxquestions.org, I accept, as an example, because I intentionally got there
  3. A secondary script that looks close, like lq-feedback.org, I'd probably accept that, but also ONLY if I felt there were items on a page where I could not see or do stuff, I am actually fine with not accepting a script if I feel that a page I'm looking at operates how I need it too
  4. The more difficult ones are things like my bank. NoScript does print out the list of scripts blocked in the status bar, or also in the NoScript menu. You can "temporarily" accept a script and see what that does for you. You can then also disallow that script if you feel it did you no good, and once you get a page where you want it, you can then make the permissions permanent.
  5. The bigger problems are very active pages, like movie pages, game pages, stuff where advertisement is huge, and the site is more commercial. I only go so far, but if I think I really want to see something (usually I'm not surprised to see that it is something stupid and I needed have bothered actually) I'll temporarily accept all for that page. Only to find that there are now newer added scripts needing to be approved. Sometimes at that point I'll see enough to say, "Gee, do I really want to see this stupid video, versus not? Or I'll choose to forge ahead and accept the next round.
  6. Largely, once I go to enough of my regular web pages and accept the right scripts, things are fine and I have little maintenance for it at all. But bear in mind that I'm probably a very boring web user. For instance I'm already saying that I don't kill myself to play games or watch videos online, so I'm mainly reading stuff, news, technical stuff, or searching for information
Thanks rtmistler. Wow. I had no idea this was so complex. (By the time I got reading all these posts I'd been logged out!)
Well, I hear what you're saying about getting to the point where you have little maintenance, but I don't know as much as you do. And I have already had some problems with using Firefox (like doing "e-signatures") and don't want to have problems using my online banking. And on top of that I've been using Xubuntu for about four years now and have never had a problem (never using NoScript). I guess I can always disable NoScript when I do my bank stuff and then turn it back on when I surf the web. I think it's a good idea. It will just take a while to get the hang of it. Appreciate all your feedback.
 
Old 02-03-2016, 09:16 PM   #11
Gregg Bell
Senior Member
 
Registered: Mar 2014
Location: Illinois
Distribution: Xubuntu
Posts: 2,034

Original Poster
Rep: Reputation: 176Reputation: 176
Quote:
Originally Posted by rokytnji View Post
Install WOT add on and then search the url. I Fly with Ghostery myself instead of No Script.
I know it is not as thorough as No Script but the nets shotgun approach of loading scripts made
using No Scripts a PITA for me.

Edit: To answer your original question. Is it a good idea? Yes it is. I am just a laid back linux user who flys loosey goosey.
Thanks rokytnji. I had an earlier post about WOT and in it someone mentioned Bitdefender Traffic Light for Firefox. That one actually appealed to me more than WOT. That might be a way for me to go instead of NoScript. I don't know. Ha ha. I've got a lot to think about. (Ghostery seemed more about avoiding being tracked.)
 
Old 02-03-2016, 09:19 PM   #12
Gregg Bell
Senior Member
 
Registered: Mar 2014
Location: Illinois
Distribution: Xubuntu
Posts: 2,034

Original Poster
Rep: Reputation: 176Reputation: 176
Quote:
Originally Posted by rknichols View Post
It's more of a PITA than it's worth, IMO. All but a tiny fraction of web sites require Javascript. You can spend 10 minutes or so trying to figure out which of the blocked sites on the page need to be allowed to let the page work, but on many sites even "Temporarily allow all this page" needs to be clicked on two or three times in order to get all the necessary levels of scripting allowed. Then there's the issue of commerce sites where at some point you are warned, "Do not reload the page or use your browser's "Back" button or you may be charged twice," and you find yourself stuck on some page that won't load without some script that's still blocked, and you try to allow it in NoScript, only to see the message that the page needs to be reloaded in order to do that. What do you do now? Was your order entered or not? Eventually you learn to "Allow scripts globally (dangerous)" whenever you're doing anything that involves real money.
Thanks rknichols. Wow. That does sound like a PITA. I've had enough trouble using Paypal without NoScripts. I don't know. Right now I'm leaning toward using the NoScript but whenever I want to do online banking or buy something online disalbing it. Or I might get this Bit Defender Traffic Light for Firefox and forego NoScript altogether. Appreciate your feedback.
 
Old 02-03-2016, 09:21 PM   #13
Gregg Bell
Senior Member
 
Registered: Mar 2014
Location: Illinois
Distribution: Xubuntu
Posts: 2,034

Original Poster
Rep: Reputation: 176Reputation: 176
Quote:
Originally Posted by jefro View Post
I almost always use it.

Almost never see a site that doesn't get some stuff blocked.

The more ways you limit exposure the better.

One time it saved my behind. It blocked an advertisement on Popsi.com that was malware.

If I go to a site, I only what that site. You'll see news type pages seem to be the worst.
Thanks jefro. Yeah, if it saves you it's worth it. But don't you think something like WOT or Bitdefender Traffic Light for Firefox would alert you that the Posi.com site was nasty? (I'm looking to keep it simple.)
 
Old 02-03-2016, 09:26 PM   #14
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,311
Blog Entries: 28

Rep: Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137
I have gotten to quite like NoScript as it helps control misbehaving scripts; even well-intentioned websites can have misbehaving, but not necessarily malicious, scripts. I use NoScript routinely and find it's well worth the little bit of effort it takes to manage it, once you get the hang of it.

I read lots of newspaper websites, and some of them are quite heavily scripted (any Gannett site is virtually unusable, but Gannett is the MacDonalds of news so who cares?).

If I trust the site, I will routinely tell NoScript to trust all scripts from that site. I tend to trust sites that I know are run by trustworthy folks. For example, I trust my local newspaper's site, as I've been reading the paper since I was a wee tyke and I know how they do business.

Occasionally, depending on the site, I will tell NoScript to allow all scripts on that site; LQ would be one such site, eff.org would be another.

Sometimes, as when I wish to play an embedded video that doesn't want to play, I will tell NoScript to temporarily allow all scripts from the site.

I am too lazy to wade through the list of scripts one-by-one, and, if I'm browsing a site I know is legit, I think that's overkill to begin with. If it's a site I know is not legit, you won't find me browsing it in the first place.

Just my ramblings.

Last edited by frankbell; 02-03-2016 at 09:29 PM.
 
1 members found this post helpful.
Old 02-03-2016, 09:41 PM   #15
Gregg Bell
Senior Member
 
Registered: Mar 2014
Location: Illinois
Distribution: Xubuntu
Posts: 2,034

Original Poster
Rep: Reputation: 176Reputation: 176
Quote:
Originally Posted by John VV View Post
one very GOOD way to start to figure out JUST WHAT that script is doing is to middle click on it's name on the no-script pop up menu

for example here as i type this
cloudflare and netdna-ssl are currently allowed

middle click on "cloudflare" a new tab opens and at the top is the no script " WOT "
click on the link
https://www.mywot.com/en/scorecard/cloudflare.com
and read the opinions

you can also go to the scripts web site
https://www.cloudflare.com/

there is a ton of information available on the middle click option


now as much as i DISLIKE cloudflare this forum USES IT!!! for the top menu

|| home || forums || HGL || reviews || and so on.....
Thanks John. Interesting. I'm just wondering if I need that much information. It's like I went to Goodreads and it wouldn't let me do the least thing there. So I looked at the stuff on the menu and the first thing was something like gr.links (I made that up) and so I investigated it with hitting the shift and some other key (I have no middle click) and it seemed okay, so I hit 'temporarily allow gr.links' and I still couldn't do anything. So I hit 'temporarily allow all this page' and then it opened up.

And I went to that cloudflare link. (see attachment) Isn't that rating kind of messed up with the other font stuff? And how do you interpret that number? It was 92 but there was no reference point.
Attached Thumbnails
Click image for larger version

Name:	Selection_078.png
Views:	10
Size:	99.2 KB
ID:	20721  
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Good idea jefro General 5 01-20-2015 09:12 AM
Linkedin.com - a good idea? honeybadger General 23 07-27-2012 04:51 AM
Good idea/bad idea: interface colors introuble General 5 10-30-2006 01:33 PM
Good idea? Berticus Linux - General 2 09-28-2005 10:19 AM
I think this is a good idea! pe2338 Linux - General 7 09-14-2003 05:52 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 04:07 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration