<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: A Fistful of Pixels</title>
	<link>http://hackademix.net/2011/05/22/a-fistful-of-pixels/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Wed, 16 May 2012 22:29:23 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24921</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Tue, 19 Jul 2011 09:40:09 +0000</pubDate>
		<guid>http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24921</guid>
		<description>@&lt;a href="http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24920" rel="nofollow"&gt;Reto in Geneva/Switzerland&lt;/a&gt;

The "25% slow down" you read about is referred just to the browser *startup* time (i.e. the time the browser takes to start when you summon it first time) and, even so, the measurement has been widely criticized for its methodological flaws. 
However, if you take it for good, this just means that NoScript's initialization adds about 1/10 of second to the browser time to start. Is this something you can live with? On the other hand, by preventing lots of useless content from being loaded and executed, NoScript sensibly reduces page load times, CPU burden and memory consumption. What's more important to you, performance-wise? 
At any rate, the startup time is being optimized as well, but don't forget that taken alone it is a misleading metric.</description>
		<content:encoded><![CDATA[<p>@<a href="http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24920" rel="nofollow">Reto in Geneva/Switzerland</a></p>
<p>The &#8220;25% slow down&#8221; you read about is referred just to the browser *startup* time (i.e. the time the browser takes to start when you summon it first time) and, even so, the measurement has been widely criticized for its methodological flaws.<br />
However, if you take it for good, this just means that NoScript&#8217;s initialization adds about 1/10 of second to the browser time to start. Is this something you can live with? On the other hand, by preventing lots of useless content from being loaded and executed, NoScript sensibly reduces page load times, CPU burden and memory consumption. What&#8217;s more important to you, performance-wise?<br />
At any rate, the startup time is being optimized as well, but don&#8217;t forget that taken alone it is a misleading metric.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Reto in Geneva/Switzerland</title>
		<link>http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24920</link>
		<dc:creator>Reto in Geneva/Switzerland</dc:creator>
		<pubDate>Tue, 19 Jul 2011 07:30:19 +0000</pubDate>
		<guid>http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24920</guid>
		<description>Hello, 

Using your add-on since always,

I believe its an important one... :-)

BUT It seems it slows down Firefox of 25% !!!

I think it would be nice if you put an effort
on Firefox RAM's use...

Thanks for taking this critic in account and improve this point for one of the next Version :-)</description>
		<content:encoded><![CDATA[<p>Hello, </p>
<p>Using your add-on since always,</p>
<p>I believe its an important one&#8230; :-)</p>
<p>BUT It seems it slows down Firefox of 25% !!!</p>
<p>I think it would be nice if you put an effort<br />
on Firefox RAM&#8217;s use&#8230;</p>
<p>Thanks for taking this critic in account and improve this point for one of the next Version :-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Björn</title>
		<link>http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24868</link>
		<dc:creator>Björn</dc:creator>
		<pubDate>Sun, 26 Jun 2011 11:08:25 +0000</pubDate>
		<guid>http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24868</guid>
		<description>And now the protocol is gone…</description>
		<content:encoded><![CDATA[<p>And now the protocol is gone…</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24860</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Mon, 20 Jun 2011 13:37:30 +0000</pubDate>
		<guid>http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24860</guid>
		<description>It's been an AMO bug see http://forums.informaction.com/viewtopic.php?f=8&#038;t=6626</description>
		<content:encoded><![CDATA[<p>It&#8217;s been an AMO bug see <a href="http://forums.informaction.com/viewtopic.php?f=8&#038;t=6626" rel="nofollow">http://forums.informaction.com/viewtopic.php?f=8&#038;t=6626</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Reolo</title>
		<link>http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24859</link>
		<dc:creator>Reolo</dc:creator>
		<pubDate>Mon, 20 Jun 2011 13:24:56 +0000</pubDate>
		<guid>http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24859</guid>
		<description>OT:
@Maone, it's the second time I receive automatic RC updates for Noscript, why I don't get only final versions?</description>
		<content:encoded><![CDATA[<p>OT:<br />
@Maone, it&#8217;s the second time I receive automatic RC updates for Noscript, why I don&#8217;t get only final versions?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sergio Leone</title>
		<link>http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24771</link>
		<dc:creator>Sergio Leone</dc:creator>
		<pubDate>Mon, 30 May 2011 23:26:53 +0000</pubDate>
		<guid>http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24771</guid>
		<description>@ Thrawn, 

Thanks, but I wouldn't use IE to e-mail my grandmother on her anniversary, much less do online banking with it.

&#34;for better or worse, in terms of proper website rendering, it has the most developer support.&#34;

For worse, methinks.   My sites render fine in  Fx. What if my bank is the victim of, say, an XSS attack  or a clickjack attack?  And did you know that there are a few financial sites that won't work unless you allow doubleclick or amazon or whatever? Possibly in iFrame. Facilitates such attacks.

I deleted IE from this machine a couple of years ago, along with all support files that weren't needed by the OS itself.</description>
		<content:encoded><![CDATA[<p>@ Thrawn, </p>
<p>Thanks, but I wouldn&#8217;t use IE to e-mail my grandmother on her anniversary, much less do online banking with it.</p>
<p>&quot;for better or worse, in terms of proper website rendering, it has the most developer support.&quot;</p>
<p>For worse, methinks.   My sites render fine in  Fx. What if my bank is the victim of, say, an XSS attack  or a clickjack attack?  And did you know that there are a few financial sites that won&#8217;t work unless you allow doubleclick or amazon or whatever? Possibly in iFrame. Facilitates such attacks.</p>
<p>I deleted IE from this machine a couple of years ago, along with all support files that weren&#8217;t needed by the OS itself.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thrawn</title>
		<link>http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24766</link>
		<dc:creator>Thrawn</dc:creator>
		<pubDate>Mon, 30 May 2011 00:05:38 +0000</pubDate>
		<guid>http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24766</guid>
		<description>@Sergio Leone:
Hmm...maybe the suggested best practice of using a separate browser session for sensitive activities is a use case for Internet Explorer? After all, it should only be let loose on highly-trusted sites anyway! Browse in Firefox, then close it (and let it save your session), open IE, follow bookmarks to your bank/webmail/etc (or configure your homepage to open them automatically), close IE, back to Firefox for browsing. Methinks it has potential.

Of course, IE doesn't have to be the trusted-sites-only browser; anything could be. But it's available on Windows machines without installation, and for better or worse, in terms of proper website rendering, it has the most developer support.</description>
		<content:encoded><![CDATA[<p>@Sergio Leone:<br />
Hmm&#8230;maybe the suggested best practice of using a separate browser session for sensitive activities is a use case for Internet Explorer? After all, it should only be let loose on highly-trusted sites anyway! Browse in Firefox, then close it (and let it save your session), open IE, follow bookmarks to your bank/webmail/etc (or configure your homepage to open them automatically), close IE, back to Firefox for browsing. Methinks it has potential.</p>
<p>Of course, IE doesn&#8217;t have to be the trusted-sites-only browser; anything could be. But it&#8217;s available on Windows machines without installation, and for better or worse, in terms of proper website rendering, it has the most developer support.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sergio Leone</title>
		<link>http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24756</link>
		<dc:creator>Sergio Leone</dc:creator>
		<pubDate>Wed, 25 May 2011 08:06:05 +0000</pubDate>
		<guid>http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24756</guid>
		<description>Grazie for the plug, Signore. I repeatedly ranted against the jazz-it-up look of Fx3  (The  Ugly) vs. the clean, simple lines of Fx2 (The Good), and was derided for it. Now, Fx4 (The  Bad) goes too far in the other direction, with gray-on-gray icons on top, and no status bar on the bottom for icons of add-ons, their status, and easy use of same. Getting rid of the URL bar is idiotic, after all the time and trouble spent getting color codes to show standard or EV SSL/TLS,  or even just the  yellow icon.

Does the attack work  when a non-secure-site tab  is &#34;morphed  into&#34;  a  secured  one? 

One of the contributing factors is an ADD-lebrained generation that cannot possibly bear life with fewer than half a dozen tabs open. As a very wise man wrote, 

&#34;Best Practice: Before engaging in sensitive activities like financial management, close *all* browsers, tabs, windows, whatever. Then re-open a fresh browser, do your banking, and *close it* before resuming non-sensitive browsing.&#34;. 

Anything that requires a username and password is, by definition, sensitive to some degree. This Best Practice would seem to defeat the tab-morphing attack completely. In the meantime, it's a good idea to allow users leeway to configure the toolbars, etc., that will or will not be visible, but a very bad idea to strip out everything  at the factory.  So yes,  I'm  with you, amico:  We still need A Few Pixels More. 

by the way, that  Best Practice quote is  found by  clicking the  link in my sig, which takes you to my alter ego, The Man With No Name But Who Posts Under One. Post #28160. (I think Bad Behavior blocked an attempt to put the entire PHP post address in the Website block. And I'm going blind trying to read the **** recaptcha nonsense words. There must be a better way.)</description>
		<content:encoded><![CDATA[<p>Grazie for the plug, Signore. I repeatedly ranted against the jazz-it-up look of Fx3  (The  Ugly) vs. the clean, simple lines of Fx2 (The Good), and was derided for it. Now, Fx4 (The  Bad) goes too far in the other direction, with gray-on-gray icons on top, and no status bar on the bottom for icons of add-ons, their status, and easy use of same. Getting rid of the URL bar is idiotic, after all the time and trouble spent getting color codes to show standard or EV SSL/TLS,  or even just the  yellow icon.</p>
<p>Does the attack work  when a non-secure-site tab  is &quot;morphed  into&quot;  a  secured  one? </p>
<p>One of the contributing factors is an ADD-lebrained generation that cannot possibly bear life with fewer than half a dozen tabs open. As a very wise man wrote, </p>
<p>&quot;Best Practice: Before engaging in sensitive activities like financial management, close *all* browsers, tabs, windows, whatever. Then re-open a fresh browser, do your banking, and *close it* before resuming non-sensitive browsing.&quot;. </p>
<p>Anything that requires a username and password is, by definition, sensitive to some degree. This Best Practice would seem to defeat the tab-morphing attack completely. In the meantime, it&#8217;s a good idea to allow users leeway to configure the toolbars, etc., that will or will not be visible, but a very bad idea to strip out everything  at the factory.  So yes,  I&#8217;m  with you, amico:  We still need A Few Pixels More. </p>
<p>by the way, that  Best Practice quote is  found by  clicking the  link in my sig, which takes you to my alter ego, The Man With No Name But Who Posts Under One. Post #28160. (I think Bad Behavior blocked an attempt to put the entire PHP post address in the Website block. And I&#8217;m going blind trying to read the **** recaptcha nonsense words. There must be a better way.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sabret00the</title>
		<link>http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24740</link>
		<dc:creator>sabret00the</dc:creator>
		<pubDate>Mon, 23 May 2011 12:28:29 +0000</pubDate>
		<guid>http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24740</guid>
		<description>The site identity block seem to be getting a lot of mentions lately, but it's obsolete for the vast majority of the net and especially so in a conversation where we're discussing the removal of the url bar. A prime example is this very site. Click the site identity block and what do you get? Nothing. How is that helpful to anyone? Saying that URLs are obsolete to the average Joseph/Josefine is all well and done, but surely if that is such a case, the emphasis should be on educating the average user of it's importance and role?</description>
		<content:encoded><![CDATA[<p>The site identity block seem to be getting a lot of mentions lately, but it&#8217;s obsolete for the vast majority of the net and especially so in a conversation where we&#8217;re discussing the removal of the url bar. A prime example is this very site. Click the site identity block and what do you get? Nothing. How is that helpful to anyone? Saying that URLs are obsolete to the average Joseph/Josefine is all well and done, but surely if that is such a case, the emphasis should be on educating the average user of it&#8217;s importance and role?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AnonymousCoward</title>
		<link>http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24738</link>
		<dc:creator>AnonymousCoward</dc:creator>
		<pubDate>Mon, 23 May 2011 08:10:49 +0000</pubDate>
		<guid>http://hackademix.net/2011/05/22/a-fistful-of-pixels/#comment-24738</guid>
		<description>@Asa Dotzler
Cart before Horse; give us the site identity block and let us evaluate it before disappearing the only plain UI tool left for individuals to verify web navigation.   All warning systems have failed so far, so pardon the skepiticism about this airware.
And that those who are alert to subversion of the web find the address bar a help should be deprived of it because it's &#34;not a big win&#34; seems a tad dismissive.  Then again, if all Firefox wants is to look after Important-But_Inattentive Mobile Users In A Hurry, then say it now and I can get moving on a push for a fork of Fx-with-UI-feedback.  
See, the problem with one-web-fits-all is that while the web has indeed been mostly taken over by commerce, and all power to you and your mates in your work to make users meld seamlessly with services, some of us are forced to access government and financial organisations through web interfaces only and know that those organisations are mostly years behind your bleeding edge in their attention to users' security.  
So, in sort of the same way as ISPs with any sense are getting up and running towards IPv6 with dual stack addressing, it's really only fair that Firefox should continue to provide dual old-style UI feedback/new style fingerpoken ideograms ... until us dinosaurs who can read and compare text die out. 
Fx participant here, since Firebird.
NS participant since V1.0
The complete, entire pressure for the development of Firefox was to get back diverse user control from MS of what web pages were delivering.  NoScript took up the baton as even Firefox lost sight of the way that the web and browsers had become the battlefield for malware, and I hope there's enough still under the hood to allow us to support anybody else who wants to step up to the plate and continue to allow that diversity some agency. 

Thanks Giorgio for the pointer.  Fistful of Pixels :-)</description>
		<content:encoded><![CDATA[<p>@Asa Dotzler<br />
Cart before Horse; give us the site identity block and let us evaluate it before disappearing the only plain UI tool left for individuals to verify web navigation.   All warning systems have failed so far, so pardon the skepiticism about this airware.<br />
And that those who are alert to subversion of the web find the address bar a help should be deprived of it because it&#8217;s &quot;not a big win&quot; seems a tad dismissive.  Then again, if all Firefox wants is to look after Important-But_Inattentive Mobile Users In A Hurry, then say it now and I can get moving on a push for a fork of Fx-with-UI-feedback.<br />
See, the problem with one-web-fits-all is that while the web has indeed been mostly taken over by commerce, and all power to you and your mates in your work to make users meld seamlessly with services, some of us are forced to access government and financial organisations through web interfaces only and know that those organisations are mostly years behind your bleeding edge in their attention to users&#8217; security.<br />
So, in sort of the same way as ISPs with any sense are getting up and running towards IPv6 with dual stack addressing, it&#8217;s really only fair that Firefox should continue to provide dual old-style UI feedback/new style fingerpoken ideograms &#8230; until us dinosaurs who can read and compare text die out.<br />
Fx participant here, since Firebird.<br />
NS participant since V1.0<br />
The complete, entire pressure for the development of Firefox was to get back diverse user control from MS of what web pages were delivering.  NoScript took up the baton as even Firefox lost sight of the way that the web and browsers had become the battlefield for malware, and I hope there&#8217;s enough still under the hood to allow us to support anybody else who wants to step up to the plate and continue to allow that diversity some agency. </p>
<p>Thanks Giorgio for the pointer.  Fistful of Pixels :-)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

