Have you checked up on how many thousands of security holes that the noscript extension has in it? There are probably lots of holes in that code just waiting to be discovered as well.
Are you sure you have the genuine noscript extension installed and not a malicious copy that deliberately creates vulnerabilities?
Turning off JIT to protect against a bug in it is a far superior solution to turning on something else which itself can also contain bugs.
Anyway bugs in Firefox is no more a reason for abandoning JavaScript than bugs in IE would be - just swicht to a better browser that doesn’t have all those bugs.
Man, what have you got against this extension?
To suggest it has thousands of security holes is simply hyperbolic.
You can install it via Mozilla’s official addon website, so if you can’t trust that, you can’t trust any other addon for FF.
Plus, if you visit the noscript site you can see that it is endorsed by various JavaScript advocates as well as the Chief Security Officer at Mozilla.
Losing battle perhaps?
I’m starting to think you have some kind of vendetta against the NoScript team as well, making claims about the security about a plug-in or application should be made solely on factual information, not conjecture. Granted you have a valid claim that plug-in’s can have flaws which could be taken advantage of, however to state that NoScript has thousands of flaws (as you said “how many” without “potential”) without backing up the claim tends to make you seem a little biased. I’ve yet to see any evidence to suggest having NoScript will make you any less safe than not using it, in fact everything I’ve read seems to show the complete opposite, there’s a good reason why security experts recommend NoScript, it offers a barrier of protection which is (granted) not as tight as turning off scripting entirely, but it does serve a valid purpose and does reduce the chances of client-side “bad” scripting being invoked.
My argument all along has been that a facility integrated into the browser is more likely to be secure than one that requires an extension or plugin.
I am not meaning to suggest that the noscript extension is insecure, just that if you want that option then you are better off with a browser that has that feature built in rather than one that requires an extension to supply it.
Where you have lots of extensions added to the browser (as you need in order to turn Firefox into a usable browser) then there is no way of telling if a combination of the particular extensions you have chosen has introduced a security hole that isn’t there unless a group of extensions are all installed together. It could be a matter of remove any one of the 50 or so extensions you have installed and the security hole goes away.
So there is no real way of telling that because someone has extensions ABC, DEF, GHI, JKL, MNO, PQR, STU, VWX, YZA, BCD, EFG, HIJ, KLM, NOP, QRS, TUV, WXY, and ZAB all installed in their copy of Firefox that they don’t have a security hole created by those extensions in combination that anyone with a different combination of extensions doesn’t have.
Where the browser supports the option without needing extensions it is far easier to test as everyone is running the same combination.
Anyway with the JIT security hole mentioned the best solution (assuming you want to stick with Firefox rather than switch to a better browsr) would be to upgrade to the more recent version of Firefox that fixes it. The second best solution would be to turn off JIT. There is nothing with that security hole that requires turning off JavaScript completely.
There was that squabble about NoScript interfering with the AdBlockPlus addon : )
Other than that, I’m pretty happy with NoScript. Again, I cannot say Yes No Yes No No to individual scripts directly via the browser itself, nor can I say Yes and No to particular domains! Otherwise, I would just have JS turned off completely in FF (in the way I have it completely off in Opera and Konqueror and Epiphany).
I don’t believe it’s secure when you must turn on ALL scripts, this includes the crap, just to make something (like a menu) work on a page (yesh, we all agree the page should work anyway, but you know, anyone can be a code monkey and build a website like that steaming pile of Movember…)
there’s a good example. I should be able to choose which scripts on Movember I turn on just to get the to site actually work without needing to let everything else in.
It is true that plugins, like widgets, are coded by different people and they’re not all well-coded. That and the bloat on FF is a reason not to have many FF extensions in the first place.