Bonum Certa Men Certa

Managing NoScript Whitelists and Some Tor Browser Observations

Reprinted with permission from Ryan Farmer

One of the things that does bug me about using NoScript….



Is that is keeps the text file it exports in a different format with “modern” browsers.



So I can pass around one exported list by occasionally stomping the exported file with a fresh one with the latest permissions from LibreWolf and then pass it around to my other browsers that can use the WebExtension.



SeaMonkey, on the other hand, uses a “Classic” unsupported version of NoScript which uses a different list format.



So I end up maintaining a special version of the list, a second time, just for SeaMonkey.



I’m hoping that the upcoming update adds enough backported JavaScript and WebComponents work that more sites start behaving normally in SeaMonkey.



Having to pay my electric bill through another browser is a real bummer, and some sites like Walmart just look weird, although humorously, Walmart is currently bungled in Firefox to the point where you can’t schedule a grocery pickup time and checkout, but in SeaMonkey that works fine, but the site looks a little weird. So I can shop for food in SeaMonkey, but not Firefox.



I’d report a site compat bug to Mozilla, but I’d get the usual “Go to Hell, also CoC” Standard Reply assuming they even took any action on the bug report at all.



Even the modern version of NoScript does not appear to have a special button to disable WASMs.



I think you can stop them with blocking Object to Trusted Sites, but not sure about this, and it seems more destructive than surgically removing WASM with a preference.



I noticed while I was playing with the Tor Browser last night, that the “Safer” setting, starts disabling some features that aren’t widely used while just browsing the Web. It leaves JavaScript on (but only for HTTPS sites), but it starts disabling some of the crappy features that you often don’t need.



If you look at the monthly Mozilla security updates, a lot of them address High and Critical CVEs that WASM itself adds to the browser.



That’s why I set javascript.options.wasm to False in all my browsers in about:config, so even sites I allow to run JavaScript can’t load WASM blobs on me.



I just want to pay my phone bill, not risk having executables sent down the hatch.



It seems the Tor Project agrees that WASMs are a special danger that adds a significant amount of attack surface to the browser, beyond what JavaScript alone is capable of, and it’s not really that important.



So I’ve set my copy of the Tor Browser to the safer setting. It’s not what I’d like (static content Web sites), but it’s probably the best you can do and have the Web as it is work at all.



They should move the slider closer to the user interface so the user can dial it up and down faster, and set it to Safest if they want to run silent, run deep for a while, and not take chances on scripts and stuff on .onion sites.



Best practices for .onion sites are to remain accessible to users who can only look at static content.



The way that people typically get unmasked on Tor is partially “active content” being on in the browser, and partially that the police will set up a site that requires logging in.



Then the court issues a broad warrant that authorizes a “Network Investigative Technique” or a NIT, which is just fancy talk for “You are authorized to attack every user who sets up an account and attempt to plant malware on the machine.”



Basically, interacting with a site like this adds you to the warrant’s scope, so sites that require logging in are a big red flag that “there’s a reason why”.



So the issue of Tor unmaskings are part technical and part legal.



In most cases, it’s a two-part thing where the user hands them both parts.



Unfortunately, Tor Browser is set by default to have almost all the same vulnerabilities as Mozilla Firefox.

Recent Techrights' Posts

Wikipedia - Like Some Free Software Projects Infiltrated and Bribed - Bans Its Own Founder
Over the years we've named (not shamed) some projects and organisations that got corrupted by money and ended up banning their own founders
The “Aktion T4” at the European Patent Office (EPO) Saves Money for the President's Own Purse
Call for parents of children with special needs
SLAPP Censorship - Part 116 Out of 200: 5 Years of Multiparty Lawfare Against Techrights, Funded by Americans and Also by Third Parties (Including Microsoft Salaries)
The public and our government will be informed in full
After IBM's Shares Collapsed the CEO is Trying the "Quantum" Trick Again, Bolstered by a Demented Dictator in the White House
from what we can gather IBM's CEO is trying to get the US government to participate in the scam
 
IBM Sends Workers 'Packing', Sometimes With the "Low Performer" Label That Imperils Their Future
To many people out there, IBM correlates with deceit
Links 24/06/2026: Four-Day Workweeks, GM Cut 1,000 Workers at Its EV Plant, 21,000+ Oracle Layoffs
Links for the day
A Step in the Right Direction (EU) in the Fight Against LLM Slop From GAFAM (US)
We've already mentioned this in Daily Links, but let's discuss this a little further
SLAPP Censorship - Part 117 Out of 200: Libel Tourism or Defamation Forum-Shopping in the United Kingdom Condemned by the European Union (EU)
Last week we reminded readers that the EU had criticised UK defamation law
Demonstration Next Week at the European Patent Office (EPO), Administrative Council Seen as Complicit
Corruption in Europe hurts all of us
IBM is Now Hinged on False Accounting and False Promises
This is the legacy of the current CEO
"PARTNER CONTENT" or 'Content Farms' That Promote Slop and Misinformation (The Register MS)
The Register MS represents a big part of the problem we all face
Turn Off the Slop, It's Wasting Energy and Destroying the Planet (the Only Planet We Have)
Right now we see lots of headlines about energy shortages and drained-up reserves
Lessons From Almost 30 Years of Site-Building Activities
We still strive to become faster and lighter
Do Not Outsource (the Seductive Mirage)
Abandoning so-called 'conventional wisdom'
Media Complicit in IBM Fraud Meant to Prop Up the Share Price Based on Lies, Fabrications
Even IBM insiders are fuming at this
In Some Countries, Windows Has Lost Its Monopoly
Windows fell to an all-time low globally this month
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, June 23, 2026
IRC logs for Tuesday, June 23, 2026
Gemini Links 24/06/2026: Motivation, PostScript Printer, and Why Hyperscalers and the Smolnet are Compatible
Links for the day
The Media's "Satya Says" Syndrome Distracts From Grim Reality
how insiders see Microsoft slop
Oracle's Collapse Has Nothing to do With Slop, It's About Its Debt Exploding by Almost 50% in Just 12 Months
How are people meant to trust the media?
Now... a Word From Our Sponsor
Powerade
Links 23/06/2026: Microsoft Studio Closures and Journalism Subjected to Further Cuts
Links for the day
Gemini Links 23/06/2026: Gardens, Basketball, Blocking Hyperscaler, and New Commodore Phone
Links for the day
Links 23/06/2026: Apple Price Hikes and Technical Debt in Slop
Links for the day
Greece Ought to Curb the Threat of Social Control Media
its national discourse seems to be run by an American company called Facebook
State of the GNU/Linux Desktop (and Laptop)
The time to advocate GNU/Linux is now
The 'XBox Narrative' Distracts From Destructive Cuts Across the Whole of Microsoft
Microsoft is preparing to lay off a likely record-breaking number of people [...] this isn't just an XBox problem
SLAPP Censorship - Part 115 Out of 200: Spending the Next Decade Writing About SLAPPs and Trying to Fix the System
It's the same industry that got paid by corrupt EPO officials to try to cover up the corruption
Microsoft's Stock Fell Nearly $200, But the Real Problems Are Just About to Begin
if they dump slop, what will they tell shareholders?
The Cyber Show on Starmer and Software Freedom
The Cyber Show's Andy has just explained why our departing national leader wasn't all bad
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, June 22, 2026
IRC logs for Monday, June 22, 2026
Gemini Links 23/06/2026: Girlrotting, Homeworlds at BGA, Slop Ruins Sites
Links for the day
A Lifetime of Whistleblowing
Ellsberg did not have an easy life, but it was a rewarding life with a rich legacy focusing on justice
European Patent Office (EPO) Series: A Man With Many Missions...
Campinos – accompanied by Gilles Requena and Patrice Pellegrino
Links 22/06/2026: Ubisoft Co-founder Dies, Americans Have Turned Against Slop
Links for the day
Links 22/06/2026: "The Sycophancy Machine" and "Port 22 Open for 54 Days"
Links for the day
When People Who Make the Most Money Are the Best "Boot Lickers" (Sucking Up to Jeffrey Epstein's Circle and the Dictator)
Sucking up to rich people may pay off
The Aim is Not Fame
Reposted from schestowitz.com
"Internally Important, Externally Irrelevant": IBM in a Nutshell
Right now its debt spins out of control and its stock spirals down the drain
SLAPP Censorship - Part 114 Out of 200: Thousands of Long Articles to Come, Properly Covering the SLAPP Industry in the UK and Its Modus Operandi
"Stowell described SLAPPs as ‘a stain on our legal system’."
Finding a Way to Get Paid to Improve LibreJS
So now we have more people resurrecting LibreJS and improving it
Microsoft Can't Even Wait Until July, Shutdowns and Layoffs Already Happening
Mashable speak of "a grim picture for the state of Xbox."
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, June 21, 2026
IRC logs for Sunday, June 21, 2026
Gemini Links 22/06/2026: Appreciating Simple Things, Perfect Summer Evening, IRIX, Vim and so
Links for the day