<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Why NoScript Blocks Web Fonts</title>
	<link>http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Wed, 08 Feb 2012 12:02:49 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Y.A.Winston Smith</title>
		<link>http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-23027</link>
		<dc:creator>Y.A.Winston Smith</dc:creator>
		<pubDate>Sun, 23 May 2010 18:28:58 +0000</pubDate>
		<guid>http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-23027</guid>
		<description>Have you ever tried to explain to intelligent, but never-before computer users, sometimes 80-years-old and above, how the dangers of the web and all its traps - THEN try to explain Giorgio's excellent program and WHAT TO DO to stay protected AND get to view the site?

It's one thing to set up Ghostiary and the like, make them search through Scroogle and use behind-the-scenes beacon and unwanted add-on killers. - but NOSCRIPT? I love the program, though it is the most aggravating thing I've used at times. For someone who doesn't understand the basic concept of a script they cannot see, forget it! Is it possible to create a Few Scripts or No Script Lite, which, despite its name would be much more complicated - something that can let them use their computers - my parents use their computer - and the web, where living at home (long story) and RTFM means Ring the Family Maven ('Maven' long A short e, equal emphasis on both syllables, transliterated Yiddish - in Yinglish: 1) a true expert,&#34;That maven got the machine back up in no time&#34; or 2) a puffed up incompetent (used sarcastically as a cutting insult without maladicta  &#34;Such a wine maven, he can't even open a bottle of champagne without breaking the cork&#34;) (Maladicta mod. academic Latin:  &#34;bad words&#34; (see George Carlin's 'Seven words you can never say on TV' words that are neither blasphemous or call upon one's Deity(ies) to justly condemn a person, or inherently  bad except that they have been socially decided insults or just bad language ... for absolutely no reason in particular)...
... that would allow me to put stronger security on their network AND get some rest?

&#34;Here comes a candle to light you to bed&#34;</description>
		<content:encoded><![CDATA[<p>Have you ever tried to explain to intelligent, but never-before computer users, sometimes 80-years-old and above, how the dangers of the web and all its traps - THEN try to explain Giorgio&#8217;s excellent program and WHAT TO DO to stay protected AND get to view the site?</p>
<p>It&#8217;s one thing to set up Ghostiary and the like, make them search through Scroogle and use behind-the-scenes beacon and unwanted add-on killers. - but NOSCRIPT? I love the program, though it is the most aggravating thing I&#8217;ve used at times. For someone who doesn&#8217;t understand the basic concept of a script they cannot see, forget it! Is it possible to create a Few Scripts or No Script Lite, which, despite its name would be much more complicated - something that can let them use their computers - my parents use their computer - and the web, where living at home (long story) and RTFM means Ring the Family Maven (&#8217;Maven&#8217; long A short e, equal emphasis on both syllables, transliterated Yiddish - in Yinglish: 1) a true expert,&quot;That maven got the machine back up in no time&quot; or 2) a puffed up incompetent (used sarcastically as a cutting insult without maladicta  &quot;Such a wine maven, he can&#8217;t even open a bottle of champagne without breaking the cork&quot;) (Maladicta mod. academic Latin:  &quot;bad words&quot; (see George Carlin&#8217;s &#8216;Seven words you can never say on TV&#8217; words that are neither blasphemous or call upon one&#8217;s Deity(ies) to justly condemn a person, or inherently  bad except that they have been socially decided insults or just bad language &#8230; for absolutely no reason in particular)&#8230;<br />
&#8230; that would allow me to put stronger security on their network AND get some rest?</p>
<p>&quot;Here comes a candle to light you to bed&quot;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-22944</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Wed, 28 Apr 2010 13:20:48 +0000</pubDate>
		<guid>http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-22944</guid>
		<description>@&lt;a href="http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-22941" rel="nofollow"&gt;Anonymous Coward&lt;/a&gt;:
Nope, because using the built-in preference you can't choose to selectively allow web fonts on pages you trust or temporarily allow specific font instances.</description>
		<content:encoded><![CDATA[<p>@<a href="http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-22941" rel="nofollow">Anonymous Coward</a>:<br />
Nope, because using the built-in preference you can&#8217;t choose to selectively allow web fonts on pages you trust or temporarily allow specific font instances.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous Coward</title>
		<link>http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-22941</link>
		<dc:creator>Anonymous Coward</dc:creator>
		<pubDate>Tue, 27 Apr 2010 15:06:09 +0000</pubDate>
		<guid>http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-22941</guid>
		<description>Is the browser.display.use_document_fonts preference set to 0 essentially the same as the &#34;Forbid @font-face&#34; option?</description>
		<content:encoded><![CDATA[<p>Is the browser.display.use_document_fonts preference set to 0 essentially the same as the &quot;Forbid @font-face&quot; option?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stewart</title>
		<link>http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-22861</link>
		<dc:creator>Stewart</dc:creator>
		<pubDate>Fri, 02 Apr 2010 15:30:57 +0000</pubDate>
		<guid>http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-22861</guid>
		<description>Personally, I also use noscript. Nevertheless, I must say that firefox is way much better that Internet explorer.</description>
		<content:encoded><![CDATA[<p>Personally, I also use noscript. Nevertheless, I must say that firefox is way much better that Internet explorer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jack</title>
		<link>http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-22840</link>
		<dc:creator>Jack</dc:creator>
		<pubDate>Fri, 26 Mar 2010 04:31:38 +0000</pubDate>
		<guid>http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-22840</guid>
		<description>The author of the program should make a script to make this page into a readable colour theme.

Recaptcha works with a word from a scanned book and a &#34;real&#34; word. Supposedly the user doesn't know which. In reality the &#34;real&#34; word is easily identifiable. CAPTCHAs are a nuisance, an usability and accessibility nightmare and an embarrassing fail.
ReCAPTCHAs are no different. Even the name is a sign of stupidity.</description>
		<content:encoded><![CDATA[<p>The author of the program should make a script to make this page into a readable colour theme.</p>
<p>Recaptcha works with a word from a scanned book and a &quot;real&quot; word. Supposedly the user doesn&#8217;t know which. In reality the &quot;real&quot; word is easily identifiable. CAPTCHAs are a nuisance, an usability and accessibility nightmare and an embarrassing fail.<br />
ReCAPTCHAs are no different. Even the name is a sign of stupidity.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew</title>
		<link>http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-22822</link>
		<dc:creator>Andrew</dc:creator>
		<pubDate>Thu, 25 Mar 2010 06:38:27 +0000</pubDate>
		<guid>http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-22822</guid>
		<description>@Ryan Allen. Get a clue. Has it ever occurred to you that Windows 7 != Windows 95? OSX is a security nightmare (Apple often react slowly to exploits) and the same linux newbs who say this rubbish are the ones telling users to go grab randomly repackaged deb/rpm files off google (from untrustworthy developers), when the original developers don't support their packaging system. Hilariously, they also don't realise that Microsoft would NEVER make many of the serious and obvious security issues distro's like Ubuntu had (like sudo authentications which could be reused by viruses to easily escalate privs, or exposing passwords in full text). Of course, people like you are simply sheep. 


Never realised that web font's were so complex. I'd imagine though that web font support will be locked down to be more secure in the future though (maybe with the mozilla 2 platform)</description>
		<content:encoded><![CDATA[<p>@Ryan Allen. Get a clue. Has it ever occurred to you that Windows 7 != Windows 95? OSX is a security nightmare (Apple often react slowly to exploits) and the same linux newbs who say this rubbish are the ones telling users to go grab randomly repackaged deb/rpm files off google (from untrustworthy developers), when the original developers don&#8217;t support their packaging system. Hilariously, they also don&#8217;t realise that Microsoft would NEVER make many of the serious and obvious security issues distro&#8217;s like Ubuntu had (like sudo authentications which could be reused by viruses to easily escalate privs, or exposing passwords in full text). Of course, people like you are simply sheep. </p>
<p>Never realised that web font&#8217;s were so complex. I&#8217;d imagine though that web font support will be locked down to be more secure in the future though (maybe with the mozilla 2 platform)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam Langley</title>
		<link>http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-22813</link>
		<dc:creator>Adam Langley</dc:creator>
		<pubDate>Thu, 25 Mar 2010 00:52:39 +0000</pubDate>
		<guid>http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-22813</guid>
		<description>Chromium passes all web font through a sanitiser first which, as one of it's actions, removes the hinting tables.

As with all Chromium code, it's BSD licensed: http://code.google.com/p/ots/</description>
		<content:encoded><![CDATA[<p>Chromium passes all web font through a sanitiser first which, as one of it&#8217;s actions, removes the hinting tables.</p>
<p>As with all Chromium code, it&#8217;s BSD licensed: <a href="http://code.google.com/p/ots/" rel="nofollow">http://code.google.com/p/ots/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ⬡</title>
		<link>http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-22804</link>
		<dc:creator>⬡</dc:creator>
		<pubDate>Thu, 25 Mar 2010 00:09:14 +0000</pubDate>
		<guid>http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-22804</guid>
		<description>Er, my statement didn't quite make sense... the whitelist itself obviously has to be saved, but automatically adding the URLs/domains/etc of any font that matches a whitelisted hash to the allow list would of course be a bad idea - the file needs to be tested every time it's downloaded.</description>
		<content:encoded><![CDATA[<p>Er, my statement didn&#8217;t quite make sense&#8230; the whitelist itself obviously has to be saved, but automatically adding the URLs/domains/etc of any font that matches a whitelisted hash to the allow list would of course be a bad idea - the file needs to be tested every time it&#8217;s downloaded.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ⬡</title>
		<link>http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-22803</link>
		<dc:creator>⬡</dc:creator>
		<pubDate>Thu, 25 Mar 2010 00:06:10 +0000</pubDate>
		<guid>http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-22803</guid>
		<description>Personally, I use NoScript not so much for security as to block annoying scripts, which seem to be about 95% of the scripts out there. It's just too bad those scripts tend to appear on sites that require scripts for basic functionality that has no need to require scripts - like, for example, the comment form on this very page. (ReCaptcha's no-script version has never worked.)

Whitelisting fonts based on a secure hash (not MD5) would be one good idea, so long as that whitelist is not saved anywhere - otherwise the server could easily return a good font once, and any arbitrary data the next time.

Hopefully someone will fix/replace the font library so it's secure enough for this functionality to be trustworthy...
(maybe replace the VM with Lua bytecode? ;-) )</description>
		<content:encoded><![CDATA[<p>Personally, I use NoScript not so much for security as to block annoying scripts, which seem to be about 95% of the scripts out there. It&#8217;s just too bad those scripts tend to appear on sites that require scripts for basic functionality that has no need to require scripts - like, for example, the comment form on this very page. (ReCaptcha&#8217;s no-script version has never worked.)</p>
<p>Whitelisting fonts based on a secure hash (not MD5) would be one good idea, so long as that whitelist is not saved anywhere - otherwise the server could easily return a good font once, and any arbitrary data the next time.</p>
<p>Hopefully someone will fix/replace the font library so it&#8217;s secure enough for this functionality to be trustworthy&#8230;<br />
(maybe replace the VM with Lua bytecode? ;-) )</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lina Inverse</title>
		<link>http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-22800</link>
		<dc:creator>Lina Inverse</dc:creator>
		<pubDate>Wed, 24 Mar 2010 22:20:54 +0000</pubDate>
		<guid>http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/#comment-22800</guid>
		<description>Ryan Allen: I run Firefox on my x86-64 Linux system, not Windows, so I'd say the security it provides me is no joke.</description>
		<content:encoded><![CDATA[<p>Ryan Allen: I run Firefox on my x86-64 Linux system, not Windows, so I&#8217;d say the security it provides me is no joke.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

