Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Free Software Foundation Introduces JShelter Browser Add-on to Restrict JavaScript API
Its FOSS ^ | 2 October 2021 | Staff

Posted on 10/05/2021 3:42:03 AM PDT by ShadowAce

The Free Software Foundation has unveiled the project JShelter , which develops a browser add-on to protect against threats posed by JavaScript on websites, including hidden identification , movement tracking, and user data collection. The project code is distributed under the GPLv3 license. The add-on is prepared for Firefox , Google Chrome , Opera , Brave, Microsoft Edge and other browsers based on the Chromium engine.

The project is being developed as a joint initiative funded by the foundation NLnet Foundation. JShelter has also been joined by Giorgio Maone, the creator of the add-on NoScript , as well as the founders of the project J ++ and the authors of the add ons JS-Shield – and JavaScript Restrictor . The add-on is used as a basis for the new project JavaScript Restrictor .

JShelter can be thought of as a firewall for JavaScript APIs available to sites and web applications. The add-on provides four levels of protection, as well as a flexible API access configuration mode. Level zero completely allows access to all APIs, the first one includes minimal locks that do not disrupt the work of pages, the second level balances between locks and compatibility, and the fourth level includes strict blocking of everything unnecessary.

API blocking settings can be tied to individual sites, for example, for a certain site, you can strengthen the protection, and for another, disable it. You can also selectively block certain JavaScript methods, objects, properties, and functions, or spoof return values ​​(for example, give false information about the system). Separately, the NBS (Network boundary shield) mode is highlighted, which does not allow pages to use the browser as a proxy between the external and local networks (all outgoing requests are intercepted and analyzed).

Blocked or restricted APIs:



TOPICS: Computers/Internet
KEYWORDS: browser

1 posted on 10/05/2021 3:42:03 AM PDT by ShadowAce
[ Post Reply | Private Reply | View Replies]

To: rdb3; JosephW; martin_fierro; Still Thinking; zeugma; Vinnie; ironman; Egon; raybbr; AFreeBird; ...

2 posted on 10/05/2021 3:42:15 AM PDT by ShadowAce (Linux - The Ultimate Windows Service Pack )
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

FWIW, you can install the extension in MS Edge from the Chrome store, but it’s buggy including some visual issues. Glad to see they’re expanding this. I miss NoScript.


3 posted on 10/05/2021 3:54:37 AM PDT by rarestia (Repeal the 17th Amendment and ratify Article the First to give the power back to the people!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: rarestia
Yeah--I'm not sure how much time I would spend online if I did not have Noscript.

I cannot stand ads.

4 posted on 10/05/2021 4:41:17 AM PDT by ShadowAce (Linux - The Ultimate Windows Service Pack )
[ Post Reply | Private Reply | To 3 | View Replies]

To: ShadowAce

Not just ads, real time 3rd party tracking API scripts too. I couldn’t live without NoScript either. The last year I have noticed sites are getting wise to JS blocking and have them shut down if it detects any JS blocking at all. Will this get around that Ace?


5 posted on 10/05/2021 5:01:56 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 4 | View Replies]

To: rarestia

Why can’t you have NoScript?


6 posted on 10/05/2021 5:03:37 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Openurmind
Not sure. If a site won't perform its function with my NoScript, I don't go to that site.

I've got Twitter, Facebook, and most Google services blocked. As a result, I don't get to some sites--including a couple of "conservative" sites--because they block the whole site when they detect my blocking.

7 posted on 10/05/2021 5:04:13 AM PDT by ShadowAce (Linux - The Ultimate Windows Service Pack )
[ Post Reply | Private Reply | To 5 | View Replies]

To: ShadowAce

I have found that if I do turn on the top Script listed “Domain.com” it meets the requirement needed to load the site. But then it adds several more scripts to the list NoScript is blocking. So even though I allowed the site JS so that things render correctly, NoScript is still catching and blocking the extra hidden stuff they try to shove on me when I toggle on the JS.

Once in awhile I might have to turn on the domain CDN too. The problem with some websites even if honest and innocent is that the website also incorporates JS for functions and graphics such as radio button links and Icons. So I think you can safely toggle on the top domain listing because NoScript is still blocking everything else.

Cool thing is, it will get around paywalls most times with just this top listing toggled on. :)


8 posted on 10/05/2021 5:19:51 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Openurmind
Cool thing is, it will get around paywalls most times with just this top listing toggled on. :)

Yeah--and I never see ads on youtube.

9 posted on 10/05/2021 5:26:43 AM PDT by ShadowAce (Linux - The Ultimate Windows Service Pack )
[ Post Reply | Private Reply | To 8 | View Replies]

To: ShadowAce

An example of this is our site. Hit it with NoScript. It is written in 99% PHP, so there is very little JS incorporated. You can see that the only thing not rendering correctly are the button icons, and the minimum needed in site “user experience” cookies to remember what you did for “your posts/viewed posts” Etc... For some reason button icons must be a challenge for PHP, but they still function.

But you can safely toggle on the one domain listing. We have absolutely NO hidden 3rd party scripts local from the site. Unfortunately though, when things are embedded such as videos “their” scripts are then added. I would personally like to outlink everything like here but folks like embedded stuff.

https://timelessauthors.com/


10 posted on 10/05/2021 5:40:16 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 7 | View Replies]

To: ShadowAce

Same here, I can also get around the major news site paywalls too. They have the content inline at the top of the stack before it reads down to the paywall cover page lines. :)

Shhh... lol


11 posted on 10/05/2021 5:44:28 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 9 | View Replies]

To: ShadowAce

Went and read it, looks like it is just like NoScript...


12 posted on 10/05/2021 5:55:08 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rarestia

https://microsoftedge.microsoft.com/addons/detail/noscript/debdhlbmgmkkfjpcglcbjadbhhekgfjh?hl=it-IT%3Fhl%3Dit-IT%22%3Fhl%3Dit-IT%3Fhl%3Dit-IT%22


13 posted on 10/05/2021 5:58:23 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 3 | View Replies]

To: ShadowAce

I use YesScript for a javascript blocker. Ghostery & uBlock Origin for privacy/ad blocker and Enhancer for Youtube to tweak youtube to my liking.


14 posted on 10/05/2021 6:16:40 AM PDT by Pollard (PureBlood)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Openurmind

NoScript was developed (almost) exclusively for Firefox and related browsers. They never ported it over to Chrome or Edge. There are some hacks one can use to make it work, but it’s not the same.


15 posted on 10/05/2021 8:49:57 AM PDT by rarestia (Repeal the 17th Amendment and ratify Article the First to give the power back to the people!)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Openurmind

Thank you for that, openurmind. That’s a recent addition. I hadn’t checked recently.


16 posted on 10/05/2021 8:55:00 AM PDT by rarestia (Repeal the 17th Amendment and ratify Article the First to give the power back to the people!)
[ Post Reply | Private Reply | To 13 | View Replies]

To: ShadowAce

This might hurt Facebook and Twitter etc from spying on you : )


17 posted on 10/05/2021 11:27:33 AM PDT by minnesota_bound (I need more money. )
[ Post Reply | Private Reply | To 1 | View Replies]

To: rarestia

Absolutely my privilege, I hope it is stable for you. They have an addon at the Chrome store also but the comments say it broke when they recently updated it. So it is apparently buggy.


18 posted on 10/05/2021 5:45:05 PM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 16 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson