Bonum Certa Men Certa

Managing NoScript Whitelists and Some Tor Browser Observations

Reprinted with permission from Ryan Farmer

One of the things that does bug me about using NoScript….



Is that is keeps the text file it exports in a different format with “modern” browsers.



So I can pass around one exported list by occasionally stomping the exported file with a fresh one with the latest permissions from LibreWolf and then pass it around to my other browsers that can use the WebExtension.



SeaMonkey, on the other hand, uses a “Classic” unsupported version of NoScript which uses a different list format.



So I end up maintaining a special version of the list, a second time, just for SeaMonkey.



I’m hoping that the upcoming update adds enough backported JavaScript and WebComponents work that more sites start behaving normally in SeaMonkey.



Having to pay my electric bill through another browser is a real bummer, and some sites like Walmart just look weird, although humorously, Walmart is currently bungled in Firefox to the point where you can’t schedule a grocery pickup time and checkout, but in SeaMonkey that works fine, but the site looks a little weird. So I can shop for food in SeaMonkey, but not Firefox.



I’d report a site compat bug to Mozilla, but I’d get the usual “Go to Hell, also CoC” Standard Reply assuming they even took any action on the bug report at all.



Even the modern version of NoScript does not appear to have a special button to disable WASMs.



I think you can stop them with blocking Object to Trusted Sites, but not sure about this, and it seems more destructive than surgically removing WASM with a preference.



I noticed while I was playing with the Tor Browser last night, that the “Safer” setting, starts disabling some features that aren’t widely used while just browsing the Web. It leaves JavaScript on (but only for HTTPS sites), but it starts disabling some of the crappy features that you often don’t need.



If you look at the monthly Mozilla security updates, a lot of them address High and Critical CVEs that WASM itself adds to the browser.



That’s why I set javascript.options.wasm to False in all my browsers in about:config, so even sites I allow to run JavaScript can’t load WASM blobs on me.



I just want to pay my phone bill, not risk having executables sent down the hatch.



It seems the Tor Project agrees that WASMs are a special danger that adds a significant amount of attack surface to the browser, beyond what JavaScript alone is capable of, and it’s not really that important.



So I’ve set my copy of the Tor Browser to the safer setting. It’s not what I’d like (static content Web sites), but it’s probably the best you can do and have the Web as it is work at all.



They should move the slider closer to the user interface so the user can dial it up and down faster, and set it to Safest if they want to run silent, run deep for a while, and not take chances on scripts and stuff on .onion sites.



Best practices for .onion sites are to remain accessible to users who can only look at static content.



The way that people typically get unmasked on Tor is partially “active content” being on in the browser, and partially that the police will set up a site that requires logging in.



Then the court issues a broad warrant that authorizes a “Network Investigative Technique” or a NIT, which is just fancy talk for “You are authorized to attack every user who sets up an account and attempt to plant malware on the machine.”



Basically, interacting with a site like this adds you to the warrant’s scope, so sites that require logging in are a big red flag that “there’s a reason why”.



So the issue of Tor unmaskings are part technical and part legal.



In most cases, it’s a two-part thing where the user hands them both parts.



Unfortunately, Tor Browser is set by default to have almost all the same vulnerabilities as Mozilla Firefox.

Recent Techrights' Posts

Why Cyber Resilience Act (CRA) Won't Work
American companies don't follow laws, they work around them
Net Gain of 50 Gemini Capsules in Just One Month
a big jump in just one month
Keeping Linux Reliable
If Linux becomes a lot more reliable in the future, it'll be an "hey hi" miracle. If Linux becomes a lot less reliable in the future, we'll know why and who is responsible for it.
Cyber Show on the Fallacy of Salary/Ego as a Function of Wisdom in the Era of Pyramid Schemes (Cheating People Using Buzzwords and Complicit Media)
"the remuneration fallacy and the role of reluctance as a negative feedback force."
EPO's Local Staff Committee Munich Organises General Assembly Next Week, the Goal is to Oust the Corrupt President and Derail His Unlawful Agenda
They're aiming to show Campinos the door
 
Earlier This Year Microsoft's Chief Liar Frank Shaw Lied About the Layoffs. Now He's Leaving.
he's nowhere near retirement age
Gemini Links 11/09/2026: Small Things and "Hitching Your Wagon"
Links for the day
Links 11/09/2026: Tristan Buckmaster Ripped Off by Slop, Social Control Media Spreads Hatred for Profit
Links for the day
Animals Smarter Than Chatbots
Quack quack goes the chatbot
IBM Isn't Reporting Layoffs, But It Removes Tens of Thousands of People From Its Workforce
Red Hat and IBM already mark people for removal
"A Tale of Two Antónios" Will Resume Soon
In November the site turns 20
Links 11/09/2026: Cyberattack in Berlin (Windows/Microsoft TCO) and Hype About Slop as 'Existential' Something; Scam Altman et al Caught Stealing/Plagiarising "Mathematical Breakthrough"
Links for the day
Microsoft/GNOME 9/11
Garrett and Graveley (Microsoft/GNOME) will have a lot to explain
9/11 Was a National Event, Not an International Event
They insist that back doors will "save lives"
Very Sloppy PR From a Dying IBM, Company in Disarray and in Need of Distractions
IBM could really use distractions right now
What a Price-Fixing Cartel Can Look Like
If your prices increase five-fold or ten-fold and so do your revenues/income, what does that tell us?
SLAPP Censorship - Part 178 Out of 200: Explaining to Your American Clients That Spending 130,000+ United States Dollars on a Single Hearing in Another Continent Means the UK's National Archives Will Retain in Perpetuity What Your Spouse or Girlfriend Said
Balabhadra (Alex) Graveley should ask Garrett how much money he has lost so far
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, September 10, 2026
IRC logs for Thursday, September 10, 2026
Latest IBM Gossip is, Over 25,000 People to be PIPed (by Year's End)
That figure, 10%, is different from 15% (what we saw a lot). 10% is over 25,000 staff.
Solidarity at EPO
"Many colleagues have made personal and professional sacrifices by participating in the ongoing strike and work-to-rule action"
Gemini Links 11/09/2026: Culture Stuck, Robot Symphony, and Back to Geminispace
Links for the day
Links 10/09/2026: Facebook Unsafe for Kids, Fake Songs (Against Right of Publicity, CG Forgeries Basically) a Growing Problem
Links for the day
Rust is Financially and Technically Controlled by Microsoft. Rust Foundation is a Front for Microsoft's Proprietary Software.
Rust is not and has never been about security
Gemini Links 10/09/2026: "I Don’t Want to Interact With Stochastic Parrots" and "ROOPHLOCH 2026!"
Links for the day
What the British School Closure (BSN Senior School Leidschenveen) Means to EPO Staff
The only European thing about the EPO is the staff
Standing in Solidarity With Matt Mullenweg
I don't trust the people and companies that want Mullenweg out. Neither should you.
Links 10/09/2026: "Smear Campaign Says Anti-Flock Movement Is Chinese Propaganda" and "Flock Employee Calls Cops on Reporter Filming Them"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, September 09, 2026
IRC logs for Wednesday, September 09, 2026
IBM's Senior VP of Infrastructure is Out, Silent Layoffs Still Going On
Some people imagine the CEO will also "retire" very soon (and "ahead of time")
Gemini Links 09/09/2026: Mechanical Cameras, "Super App", and Prusa Issues
Links for the day
SLAPP Censorship - Part 177 Out of 200: Manosphere Without Financial Transparency
It has moreover replaced a female worker with a male
Deadline Tomorrow (10th of September) to Appeal the EPO's Fleecing of Staff (Union to Make Legal Challenges)
Join them. Fight the good fight.
linuxstans.com Died, Then Came Back as Slop (LLM Junk)
Don't make the mistake or the assumption that merely 'dabbling in' or 'experimenting with' LLMs can be forgivable as it is a trust destroyer
Links 09/09/2026: GAFAM Fatalities in Miami International Airport, "Britain’s Health Crisis Is Becoming a Political Crisis"
Links for the day
Gemini Links 09/09/2026: "Adjective Is Subjective" and Walled Gardens
Links for the day
Plagiarism is Hardly a New Problem, It Predates Mainstream Media Getting Paid to Whitewash It as "Training" or "Hey Hi", Then Conflate Plagiarism With "Intelligence" or Deferred "Value"
"Quantum" isn't new either; it's a 'circle-jerk' for companies without direction, only hype
Links 09/09/2026: Airport 'Down' (Glasgow and Edinburgh), 'Open' 'AI' Losses Rise to Pace of 50 Billion Dollars in Losses Per Year
Links for the day
Unsafe at Any Speed, "Modern" Appliances
Appliances have gotten worse
SLAPP Censorship - Part 176 Out of 200: The Sex-Obsessed Non-Experts
We heard some sexual stories
European Patent Office (EPO): No Transparency and No Paper Trail
The incompetence is that of the management, i.e. sheer incompetence of people who never examined a patent in their entire lifetime
Gemini Links 09/09/2026: Going Out, Smartphone Addiction, Mapping the Geminispace
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, September 08, 2026
IRC logs for Tuesday, September 08, 2026