Bonum Certa Men Certa

Managing NoScript Whitelists and Some Tor Browser Observations

Reprinted with permission from Ryan Farmer

One of the things that does bug me about using NoScript….



Is that is keeps the text file it exports in a different format with “modern” browsers.



So I can pass around one exported list by occasionally stomping the exported file with a fresh one with the latest permissions from LibreWolf and then pass it around to my other browsers that can use the WebExtension.



SeaMonkey, on the other hand, uses a “Classic” unsupported version of NoScript which uses a different list format.



So I end up maintaining a special version of the list, a second time, just for SeaMonkey.



I’m hoping that the upcoming update adds enough backported JavaScript and WebComponents work that more sites start behaving normally in SeaMonkey.



Having to pay my electric bill through another browser is a real bummer, and some sites like Walmart just look weird, although humorously, Walmart is currently bungled in Firefox to the point where you can’t schedule a grocery pickup time and checkout, but in SeaMonkey that works fine, but the site looks a little weird. So I can shop for food in SeaMonkey, but not Firefox.



I’d report a site compat bug to Mozilla, but I’d get the usual “Go to Hell, also CoC” Standard Reply assuming they even took any action on the bug report at all.



Even the modern version of NoScript does not appear to have a special button to disable WASMs.



I think you can stop them with blocking Object to Trusted Sites, but not sure about this, and it seems more destructive than surgically removing WASM with a preference.



I noticed while I was playing with the Tor Browser last night, that the “Safer” setting, starts disabling some features that aren’t widely used while just browsing the Web. It leaves JavaScript on (but only for HTTPS sites), but it starts disabling some of the crappy features that you often don’t need.



If you look at the monthly Mozilla security updates, a lot of them address High and Critical CVEs that WASM itself adds to the browser.



That’s why I set javascript.options.wasm to False in all my browsers in about:config, so even sites I allow to run JavaScript can’t load WASM blobs on me.



I just want to pay my phone bill, not risk having executables sent down the hatch.



It seems the Tor Project agrees that WASMs are a special danger that adds a significant amount of attack surface to the browser, beyond what JavaScript alone is capable of, and it’s not really that important.



So I’ve set my copy of the Tor Browser to the safer setting. It’s not what I’d like (static content Web sites), but it’s probably the best you can do and have the Web as it is work at all.



They should move the slider closer to the user interface so the user can dial it up and down faster, and set it to Safest if they want to run silent, run deep for a while, and not take chances on scripts and stuff on .onion sites.



Best practices for .onion sites are to remain accessible to users who can only look at static content.



The way that people typically get unmasked on Tor is partially “active content” being on in the browser, and partially that the police will set up a site that requires logging in.



Then the court issues a broad warrant that authorizes a “Network Investigative Technique” or a NIT, which is just fancy talk for “You are authorized to attack every user who sets up an account and attempt to plant malware on the machine.”



Basically, interacting with a site like this adds you to the warrant’s scope, so sites that require logging in are a big red flag that “there’s a reason why”.



So the issue of Tor unmaskings are part technical and part legal.



In most cases, it’s a two-part thing where the user hands them both parts.



Unfortunately, Tor Browser is set by default to have almost all the same vulnerabilities as Mozilla Firefox.

Recent Techrights' Posts

IBM May be Sued for Mass Layoffs Via PIPs
Some whole threads (with all the long comments in them) recently got nuked by thelayoff.com
GNU/Linux is a Platform for Work (Usage Surges in Daytime)
GNU/Linux 15% in daytime
What I Learned in London
some ministers still help us in our fight for press freedom in the UK
 
A Vortex of Beacons (or "Bluetooth Everywhere" Vision)
If someone (or someones) calls you paranoid for taking about "beacon"-like functionality, there will be no lack of authoritative citations (e.g. Web links) they can be provided to prove them wrong
Falkland Islands: GNU/Linux Elevated to 6%
GNU/Linux usage seems to have increased a lot there
Links 16/08/2026: Reading Outside, Going Offline More, and Art of Computer Programming
Links for the day
The Question of Patience
Is there a lesson here somewhere?
Links 16/08/2026: Ceuta Reports Social Control Media Used as a Weapon
Links for the day
Links 16/08/2026: Europe in Crisis of Droughts While Energy- and Water-Consuming, Pollution-Emitting Chatbots Are Spread by GAFAM (US) to Keep a Ponzi Scheme Going
Links for the day
We Need Rain, Not Chatbots
There's no "anti-AI" (it's not even AI), there's opposition to fraud, to plagiarism, and to companies that profit more when there's global warning (caused in part by their business activities)
SLAPP Censorship - Part 151 Out of 200: Dealing With Sleazy People and Companies That Steal (While Employing These Sleazy People)
we offer a quick summary and we're reflecting
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, August 15, 2026
IRC logs for Saturday, August 15, 2026
Gemini Links 16/08/2026: Sterrenkijker Releases, Solar Gemini Server
Links for the day
At IBM, Workers 'Expire' Early ("Next Step" is 'Voluntary' Layoffs Decades Before Retirement Age)
It seems like the "new normal" is layoffs not existing or barely existing because companies hide them
EPO "Cocaine Communication Manager" - Part XVI - The German State Does Not Enforce the Law Against European Patent Office Officials
It's not acceptable that Europe's second-largest institution can get away with crime time and time again
Germany's National Broadcaster (DW English) to Air Julian Assange Film This Coming Week
It seems rather sad that we live in a world where rich thugs can get away with so many horrible things
WordPress is Bloatware and Bloated Software Guarantees Security Incidents
This site turns 20 in about 11 or 12 weeks from now and it was never cracked, not even when it ran WordPress
Too Many Chiefs (or Chefs) at IBM, They Don't Know How to Run a Company (With a 100+ Year or Century-Old Brand Recognition Advantage)
It seems like a consensus opinion; some line managers or middle managers are too selfish or self-deceiving
Bluetooth and Wi-Fi on Gym Equipment Can Endanger Several Parties
Joy oh joy! Give us more "smart" things
Microsoft Silent Layoffs This Month (PIPs and More "Buyouts", Driving Out the Workforce), According to Insiders
They know it's happening because they see it and fellow workers talk about it, even if the media keeps mum
Clacton's Election Was a 'Show Election'
At least some people squeezed out some "free press" out of this charade [...] That the media kept boosting parodies as the alternative/s to the bigot is a topic we wrote about a great deal over the past 3 weeks
Omarchy is Already Dying
Same as the life cycle of slopfarms
Windows is Burning
Windows is the "burning platform" of the year
Gemini Links 15/08/2026: Stress, Jetlag, and GPU Hype (Waste of Energy for Amusement, Fake 'Currencies', and Now for Mass Plagiarism)
Links for the day
Links 15/08/2026: XBox Rotting Further, "France’s Top Court Strikes Down Ban on Social Media for Children"
Links for the day
SLAPP Censorship - Part 150 Out of 200: Always Independently Verify What People Claim to Be (or Find Yourself in a Jason Arday-Type Moment/Dilemma)
I'm not a cardiologist and Garrett was never a security expert
Links 15/08/2026: "There Is No A.I." (Slop Plagiarism Isn't Intelligence) and Its "Impact on the Environment Is Absolutely Horrifying"
Links for the day
Gemini Links 15/08/2026: Gratitudes, "Microflier" Drones, and Literate Programming
Links for the day
IBM's PIPs and RAs (Layoffs) Going on, Interns as 'Scabs'
It seems like a consensus (also in Reddit, we took a quick look)
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, August 14, 2026
IRC logs for Friday, August 14, 2026
Gemini Links 14/08/2026: Slower Internet, Logging Off Made Easy, and Human Code
Links for the day
Links 14/08/2026: "Mystery of Dark Oxygen", People Despise Slop, and Backlash Grows Against Fake Currencies (Energy-Wasting Scam Like Slop)
Links for the day
Free Publicity
They say there's no such thing as "bad press" or that every publicity is good publicity, sometimes free publicity
Farage's fears, media hijacked by-election, what really happened in Clacton
Reprinted with permission from Daniel Pocock
It's Friday. A Ton of People Departing From IBM and Red Hat.
A mere subset of people who announce this in public at Microsoft's LinkedIn
GNU/Linux and ChromeOS Beyond 11%
Combined with ChromeOS, it's already past and beyond 11%
Chatbots/LLMs Are the Next "Clown Computing", Pure Hype, a Serious Mistake
Programs that scan text and emit something similar (but full of errors)
Links 14/08/2026: Slop 'Music' Causing Problems, Slop Data Centre Contractor Unpaid (Massive Debt), and The Cyber Show Says We're "Colonised By Wankers"
Links for the day
Fake Growth of Social Control Media is Misleading
nowadays people look for alternatives - ones not controlled by MElon, CPC, and Kapo-Berg
statCounter: Windows Down to All-Time Low of 25%, Android Leads the Pack, GNU/Linux About to Leapfrog Apple, Overtaking MacOS
The situation was very different in past years
Microsoft's Mass Layoffs (Including 'Voluntary' Secret Layoffs) Take Their Toll on Seattle
How much longer can they hide their crises?
Planet Fedora ("Fedora People") is Just IBM Staff, Former IBM Staff, and LLM Slop
this is what Fedora boils down to now
Explanation of What Will Happen to Red Hat (and Other Acquired Companies) After August
In short, a lot will be scuttled; history shows it happens over and over again
SLAPP Censorship - Part 149 Out of 200: It Took a Long Time to Show What Jason Arday (at Cambridge) and Harvey Weinstein (in Hollywood) Really Were
Really bad when society endures abuse because the abusers silence their exposers
Gemini Links 14/08/2026: 32-bit RISC-V and BlackBerry
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, August 13, 2026
IRC logs for Thursday, August 13, 2026