Karmastic
Posts: 1650
Joined: 4/5/2012 From: Los Angeles Status: offline
|
quote:
ORIGINAL: RedMagic1 quote:
ORIGINAL: Karmastic u don't understand the no-script add-on. it already prevents cross-requests as well by default. Karmastic, please stop. RequestPolicy provides a granularity of control that NoScript does not. From the RequestPolicy FAQ: quote:
RequestPolicy is a tool that gives you a default deny policy for cross-site requests. RequestPolicy allows you to whitelist cross-site requests you trust. How does RequestPolicy help you where NoScript does not? RequestPolicy will protect you from various attacks that NoScript will not (such as CSRF attacks, though there some special cases that NoScript protects against) and will give you greater privacy while browsing. Also, RequestPolicy will give you finer-grained control over JavaScript and plugins when you use it with NoScript. For example, if you whitelist a domain with NoScript to allow it to run JavaScript, then that domain will also be allowed to run JavaScript when you are on any other site that you have whitelisted with NoScript. RequestPolicy makes sure that when it is JavaScript from a third-party site, it will still be restricted unless you have allowed those cross-site requests. Conversely, NoScript gives you protection that RequestPolicy does not. RequestPolicy will not keep you safe from malicious JavaScript or vulnerable plugins on the current site you are visiting, So, NoScript is absolutely essential for browser security. Having two separate tools that each do their specific jobs well is the best approach. NoScript is an amazing extension and is absolutely essential (like RequestPolicy) to using Firefox securely. It is best to use both RequestPolicy and NoScript. Please stop saying things that are false. I know a lot of people on this forum in real life, including at least one person who has already posted on this thread, and your providing incorrect security advice to them disturbs me. i didn't say anything about how good or bad RequestPolicy is, so why are you acting like i did? i cared enough to make a top post suggesting some tools. you wish to disparage one tool, saying it's useless, and that's just not true. so i corrected u. if u want to say there's a better more complete tool, then i welcome you doing that without trying to accuse me of giving false information.
|