<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: NoScript</title>
	<atom:link href="http://blog.jonudell.net/2007/11/07/noscript/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.jonudell.net/2007/11/07/noscript/</link>
	<description>Strategies for Internet citizens</description>
	<lastBuildDate>Sat, 11 Feb 2012 19:45:11 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Douglas Crockford, No Script, and IT Policy — nateirwin.net</title>
		<link>http://blog.jonudell.net/2007/11/07/noscript/#comment-162663</link>
		<dc:creator><![CDATA[Douglas Crockford, No Script, and IT Policy — nateirwin.net]]></dc:creator>
		<pubDate>Tue, 26 Apr 2011 23:48:59 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2007/11/07/noscript/#comment-162663</guid>
		<description><![CDATA[[...] by the way, it looks like Jon Udell asked himself a similar question when he read Douglas&#8217; [...]]]></description>
		<content:encoded><![CDATA[<p>[...] by the way, it looks like Jon Udell asked himself a similar question when he read Douglas&#8217; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nateirwin.net &#187; Blog Archive &#187; Douglas Crockford, No Script, and IT Policy</title>
		<link>http://blog.jonudell.net/2007/11/07/noscript/#comment-125766</link>
		<dc:creator><![CDATA[nateirwin.net &#187; Blog Archive &#187; Douglas Crockford, No Script, and IT Policy]]></dc:creator>
		<pubDate>Sun, 02 Nov 2008 19:01:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2007/11/07/noscript/#comment-125766</guid>
		<description><![CDATA[[...] by the way, it looks like Jon Udell asked himself a similar question when he read Douglas&#8217; [...]]]></description>
		<content:encoded><![CDATA[<p>[...] by the way, it looks like Jon Udell asked himself a similar question when he read Douglas&#8217; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Luther von Ruckerson</title>
		<link>http://blog.jonudell.net/2007/11/07/noscript/#comment-90328</link>
		<dc:creator><![CDATA[Luther von Ruckerson]]></dc:creator>
		<pubDate>Wed, 21 Nov 2007 13:47:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2007/11/07/noscript/#comment-90328</guid>
		<description><![CDATA[I&#039;m a complete idiot and I&#039;ve been using noscript for years.  All I know is that it blocks crap I don&#039;t need to see.  When I want to see crap I just switch the thingy.  Done and done.]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m a complete idiot and I&#8217;ve been using noscript for years.  All I know is that it blocks crap I don&#8217;t need to see.  When I want to see crap I just switch the thingy.  Done and done.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Luther von Ruckerson</title>
		<link>http://blog.jonudell.net/2007/11/07/noscript/#comment-90326</link>
		<dc:creator><![CDATA[Luther von Ruckerson]]></dc:creator>
		<pubDate>Wed, 21 Nov 2007 13:46:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2007/11/07/noscript/#comment-90326</guid>
		<description><![CDATA[I&#039;m a complete idiot and I&#039;ve been using noscript for years.  All I know is that it blocks crap I don&#039;t need to see.  When I want to see crap I just switch the thingy.  Done and done.]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m a complete idiot and I&#8217;ve been using noscript for years.  All I know is that it blocks crap I don&#8217;t need to see.  When I want to see crap I just switch the thingy.  Done and done.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://blog.jonudell.net/2007/11/07/noscript/#comment-78409</link>
		<dc:creator><![CDATA[Mark]]></dc:creator>
		<pubDate>Fri, 09 Nov 2007 13:35:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2007/11/07/noscript/#comment-78409</guid>
		<description><![CDATA[@Shital: this is nothing like &quot;OMG cookies are malicious&quot;.  This is like &quot;there&#039;s a bug in QuickTime that allows remote sites to execute arbitrary applications on MY machine with no warning... unless you&#039;re running NoScript.&quot;  (NoScript users were protected even on whitelisted sites.)  Details here: http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox  (The bug has since been corrected.  Make sure you&#039;re up to date on everything.)]]></description>
		<content:encoded><![CDATA[<p>@Shital: this is nothing like &#8220;OMG cookies are malicious&#8221;.  This is like &#8220;there&#8217;s a bug in QuickTime that allows remote sites to execute arbitrary applications on MY machine with no warning&#8230; unless you&#8217;re running NoScript.&#8221;  (NoScript users were protected even on whitelisted sites.)  Details here: <a href="http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox" rel="nofollow">http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox</a>  (The bug has since been corrected.  Make sure you&#8217;re up to date on everything.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim Chase</title>
		<link>http://blog.jonudell.net/2007/11/07/noscript/#comment-77527</link>
		<dc:creator><![CDATA[Tim Chase]]></dc:creator>
		<pubDate>Thu, 08 Nov 2007 12:15:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2007/11/07/noscript/#comment-77527</guid>
		<description><![CDATA[&quot;Would you say that strategy is equivalent to whitelisting those 30 sites in IE by placing them in the trusted zone?&quot;

Certainly not.  For one thing, anything in an IE Trusted Zone has very liberal access to what can be installed on your machine.  Especially neferious ActiveX controls.

Additionally, it&#039;s very easy to use NoScript to temporarily permit a site, but the next time you start your browser, it&#039;s banned again.  This is good for single-use instances but you don&#039;t want to give carte blanch access for the site.  On the other hand, adding a site to the Trusted Zone requires explicit revocation of those permissions, even if you only wanted to hit a one-off page.

Also, to also address the issue of &quot;with so much AJAX out there, how can you survive without JS?&quot;, it&#039;s not all that hard.  Good web developers plan for graceful degredation.  The bad ones tend to make sites that are dysfunctional without it.  Bad sites aren&#039;t usually worth visiting.  The small intersection wherein lie &quot;good sites that are break without JS&quot; are the handful that are in my whitelist.  These include annoying bits of work-related sites, banking, Gmail, etc. where I&#039;ve evaluated the risk and decided that it&#039;s worth giving this site permission to run arbitrary JS code on my machine.]]></description>
		<content:encoded><![CDATA[<p>&#8220;Would you say that strategy is equivalent to whitelisting those 30 sites in IE by placing them in the trusted zone?&#8221;</p>
<p>Certainly not.  For one thing, anything in an IE Trusted Zone has very liberal access to what can be installed on your machine.  Especially neferious ActiveX controls.</p>
<p>Additionally, it&#8217;s very easy to use NoScript to temporarily permit a site, but the next time you start your browser, it&#8217;s banned again.  This is good for single-use instances but you don&#8217;t want to give carte blanch access for the site.  On the other hand, adding a site to the Trusted Zone requires explicit revocation of those permissions, even if you only wanted to hit a one-off page.</p>
<p>Also, to also address the issue of &#8220;with so much AJAX out there, how can you survive without JS?&#8221;, it&#8217;s not all that hard.  Good web developers plan for graceful degredation.  The bad ones tend to make sites that are dysfunctional without it.  Bad sites aren&#8217;t usually worth visiting.  The small intersection wherein lie &#8220;good sites that are break without JS&#8221; are the handful that are in my whitelist.  These include annoying bits of work-related sites, banking, Gmail, etc. where I&#8217;ve evaluated the risk and decided that it&#8217;s worth giving this site permission to run arbitrary JS code on my machine.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Simon Willison</title>
		<link>http://blog.jonudell.net/2007/11/07/noscript/#comment-77477</link>
		<dc:creator><![CDATA[Simon Willison]]></dc:creator>
		<pubDate>Thu, 08 Nov 2007 10:43:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2007/11/07/noscript/#comment-77477</guid>
		<description><![CDATA[engtech / Shital Shah: the most important thing you are protecting yourself against is security bugs in the web applications that you use. A huge number of applications have either XSS or CSRF holes in them (definitions on Wikipedia) and such sites are open to a wide range of malicious attacks. Using NoScript means that even if a site you use has a security hole attackers will find it much harder to use it to exploit your acconut.]]></description>
		<content:encoded><![CDATA[<p>engtech / Shital Shah: the most important thing you are protecting yourself against is security bugs in the web applications that you use. A huge number of applications have either XSS or CSRF holes in them (definitions on Wikipedia) and such sites are open to a wide range of malicious attacks. Using NoScript means that even if a site you use has a security hole attackers will find it much harder to use it to exploit your acconut.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shital Shah</title>
		<link>http://blog.jonudell.net/2007/11/07/noscript/#comment-77387</link>
		<dc:creator><![CDATA[Shital Shah]]></dc:creator>
		<pubDate>Thu, 08 Nov 2007 07:11:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2007/11/07/noscript/#comment-77387</guid>
		<description><![CDATA[Good. Now developers and support people have to worry about one more variant. Since when JavaScript became malicious?  If you could elaborate please... Yeah, page can get annoying and would automatically drive out visitors... but malicious? That&#039;s different. If you are reffering to &quot;malicious&quot; as in &quot;cooikies are malicious&quot; then you are just firing off wrong alarms and adding lot of cost to lot of development shops and support people and waste of time on part of consumers.]]></description>
		<content:encoded><![CDATA[<p>Good. Now developers and support people have to worry about one more variant. Since when JavaScript became malicious?  If you could elaborate please&#8230; Yeah, page can get annoying and would automatically drive out visitors&#8230; but malicious? That&#8217;s different. If you are reffering to &#8220;malicious&#8221; as in &#8220;cooikies are malicious&#8221; then you are just firing off wrong alarms and adding lot of cost to lot of development shops and support people and waste of time on part of consumers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon Udell</title>
		<link>http://blog.jonudell.net/2007/11/07/noscript/#comment-77120</link>
		<dc:creator><![CDATA[Jon Udell]]></dc:creator>
		<pubDate>Wed, 07 Nov 2007 23:04:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2007/11/07/noscript/#comment-77120</guid>
		<description><![CDATA[&quot;What’s the sell? What am I protecting myself from?&quot;

Intrusive behaviors ranging from the merely annoying to the downright malicious.]]></description>
		<content:encoded><![CDATA[<p>&#8220;What’s the sell? What am I protecting myself from?&#8221;</p>
<p>Intrusive behaviors ranging from the merely annoying to the downright malicious.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon Udell</title>
		<link>http://blog.jonudell.net/2007/11/07/noscript/#comment-77118</link>
		<dc:creator><![CDATA[Jon Udell]]></dc:creator>
		<pubDate>Wed, 07 Nov 2007 23:01:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2007/11/07/noscript/#comment-77118</guid>
		<description><![CDATA[&quot;I never notice the lack of JavaScript, nor Java, nor Silverlight on websites when using my slimmed-down browser.&quot;

Really? I guess it&#039;s been a while since I tried that experiment. The latter two are low-percentage, but JavaScript? With all the AJAXy stuff going on these days? That&#039;s interesting.

Also interesting: You&#039;re in a position to notice the difference if something JavaScript-based went missing. Most civilians wouldn&#039;t.]]></description>
		<content:encoded><![CDATA[<p>&#8220;I never notice the lack of JavaScript, nor Java, nor Silverlight on websites when using my slimmed-down browser.&#8221;</p>
<p>Really? I guess it&#8217;s been a while since I tried that experiment. The latter two are low-percentage, but JavaScript? With all the AJAXy stuff going on these days? That&#8217;s interesting.</p>
<p>Also interesting: You&#8217;re in a position to notice the difference if something JavaScript-based went missing. Most civilians wouldn&#8217;t.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon Udell</title>
		<link>http://blog.jonudell.net/2007/11/07/noscript/#comment-77116</link>
		<dc:creator><![CDATA[Jon Udell]]></dc:creator>
		<pubDate>Wed, 07 Nov 2007 22:59:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2007/11/07/noscript/#comment-77116</guid>
		<description><![CDATA[&quot;There’s a notification about blocked scripts, but there’s also an option to turn it off which I did early in the game&quot;

Would you say that strategy is equivalent to whitelisting those 30 sites in IE by placing them in the trusted zone?]]></description>
		<content:encoded><![CDATA[<p>&#8220;There’s a notification about blocked scripts, but there’s also an option to turn it off which I did early in the game&#8221;</p>
<p>Would you say that strategy is equivalent to whitelisting those 30 sites in IE by placing them in the trusted zone?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: engtech</title>
		<link>http://blog.jonudell.net/2007/11/07/noscript/#comment-77074</link>
		<dc:creator><![CDATA[engtech]]></dc:creator>
		<pubDate>Wed, 07 Nov 2007 21:27:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2007/11/07/noscript/#comment-77074</guid>
		<description><![CDATA[Interesting idea... but I&#039;ve never had a problem with javascript/java enabled web sites, so why bother? (especially from a civilian point of view). What&#039;s the sell? What am I protecting myself from?]]></description>
		<content:encoded><![CDATA[<p>Interesting idea&#8230; but I&#8217;ve never had a problem with javascript/java enabled web sites, so why bother? (especially from a civilian point of view). What&#8217;s the sell? What am I protecting myself from?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott Reynen</title>
		<link>http://blog.jonudell.net/2007/11/07/noscript/#comment-77072</link>
		<dc:creator><![CDATA[Scott Reynen]]></dc:creator>
		<pubDate>Wed, 07 Nov 2007 21:16:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2007/11/07/noscript/#comment-77072</guid>
		<description><![CDATA[&lt;i&gt;However, having just installed it, I find it to be a Java/Silverlight blocker and a Flash allower...Just curious: Why?&lt;/i&gt;

I suspect Flash has become too common as a content-delivery mechanism to turn off by default. I run one browser with none of the above, and another with all of it on. I never notice the lack of JavaScript, nor Java, nor Silverlight on websites when using my slimmed-down browser. But I often notice the lack of Flash and have to open things my other browser. No one&#039;s really using Java much anymore, nor Silverlight yet, and JavaScript generally degrades gracefully, being used mostly for interface enhancement rather than content delivery. But if you want to watch a video on many sites (notably YouTube), Flash is the only option.]]></description>
		<content:encoded><![CDATA[<p><i>However, having just installed it, I find it to be a Java/Silverlight blocker and a Flash allower&#8230;Just curious: Why?</i></p>
<p>I suspect Flash has become too common as a content-delivery mechanism to turn off by default. I run one browser with none of the above, and another with all of it on. I never notice the lack of JavaScript, nor Java, nor Silverlight on websites when using my slimmed-down browser. But I often notice the lack of Flash and have to open things my other browser. No one&#8217;s really using Java much anymore, nor Silverlight yet, and JavaScript generally degrades gracefully, being used mostly for interface enhancement rather than content delivery. But if you want to watch a video on many sites (notably YouTube), Flash is the only option.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://blog.jonudell.net/2007/11/07/noscript/#comment-77046</link>
		<dc:creator><![CDATA[Mark]]></dc:creator>
		<pubDate>Wed, 07 Nov 2007 20:08:58 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2007/11/07/noscript/#comment-77046</guid>
		<description><![CDATA[I have also used NoScript since its early days, but for me the best recommendation came from reading Planet Web Security. (You *are* reading Planet Web Security, aren&#039;t you?  http://planet-websecurity.org/ .)  The hackers on PWS are the kind of people who find the bugs that result in new point releases of Firefox (and other browsers).  They recommend NoScript, and in fact the NoScript author works with some of them to ensure that you are as protected as possible, even in the face of browser bugs.  Running NoScript can sometimes protect you from security holes in the browser itself.  It&#039;s much more than just site-specific whitelisting.]]></description>
		<content:encoded><![CDATA[<p>I have also used NoScript since its early days, but for me the best recommendation came from reading Planet Web Security. (You *are* reading Planet Web Security, aren&#8217;t you?  <a href="http://planet-websecurity.org/" rel="nofollow">http://planet-websecurity.org/</a> .)  The hackers on PWS are the kind of people who find the bugs that result in new point releases of Firefox (and other browsers).  They recommend NoScript, and in fact the NoScript author works with some of them to ensure that you are as protected as possible, even in the face of browser bugs.  Running NoScript can sometimes protect you from security holes in the browser itself.  It&#8217;s much more than just site-specific whitelisting.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim Chase</title>
		<link>http://blog.jonudell.net/2007/11/07/noscript/#comment-77037</link>
		<dc:creator><![CDATA[Tim Chase]]></dc:creator>
		<pubDate>Wed, 07 Nov 2007 19:41:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2007/11/07/noscript/#comment-77037</guid>
		<description><![CDATA[I&#039;ve used NoScript for years...I must be missing the prompts you&#039;re talking about.  There&#039;s a notification about blocked scripts, but there&#039;s also an option to turn it off which I did early in the game.  I have about 30 sites or so (mostly work-related) that are white-listed, and every other site is prevented from using JavaScript.  Most of the time it&#039;s not a problem, and if I need JS temporarily, enabling it is just a click away.  Almost all of the common browser vulnerabilities out there require JS which brings my exposure to a much more manageable level.]]></description>
		<content:encoded><![CDATA[<p>I&#8217;ve used NoScript for years&#8230;I must be missing the prompts you&#8217;re talking about.  There&#8217;s a notification about blocked scripts, but there&#8217;s also an option to turn it off which I did early in the game.  I have about 30 sites or so (mostly work-related) that are white-listed, and every other site is prevented from using JavaScript.  Most of the time it&#8217;s not a problem, and if I need JS temporarily, enabling it is just a click away.  Almost all of the common browser vulnerabilities out there require JS which brings my exposure to a much more manageable level.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

