If you want to be anonymous in real life, buy a big coat. Online, and for your PC, it’s more complex. Why do it? To shore up your identity, safeguard data, secure eCommerce and give peace of mind.
This guvGuide helps you find the level of anonymity to suit you, to take control of your identity, to enjoy faster, safer surfing and, in Part 4…
…to control javascript, disabling risk while retaining functionality.
A comprehensive guide, spread over 5 posts:-
I’ve endeavoured to make this guide as comprehensive as possible; detailed, yet bulleted. But hey, if there’s something missing, you’ve got a suggestion, or a disagreement, please leave a comment below, and we’ll improve the guide. Tx.
“What’s javascript,” you may ask? Others thinking, “Just disable it.” And others, “Gotta love it.”
Modern javascript sure is cool, arguably the rum in the punch, and important for user experience with many sites, including mine. Then again, it can present a security vulnerability, so it pays to know how to avoid problems.
As with cookies, as we turn our attention to measures that can help with anonymous surfing, we must each consider our online habits, our level of online experience and the degree of user experience – or interaction – that we require. This is because, if we wanted total security and no risk, we would be left with a bland, yet perhaps still fulfilling experience. On the other hand, if we threw caution to the wind, risking all, we may have an improved experience, but perhaps with dashed anonymity and, if we haven’t follows the steps in Part One, a box full of viruses.
For most, there needs to be a balance somewhere between risk and interactivity. Hopefully this guide will help you to find your balance.
First up, javascript has nothing to do with java, another language, (and a coffee.) Totally different things. Let’s get that straight.
Javascript is a language widely used to help build websites. Some variation of javascript is used in most modern sites because it’s super-good at doing certain things that other languages can’t, else it does them better.
Most commonly, it is employed to assist user experience, by adding user-page interaction. For instance, on Guvnr.com, it is employed:-
Javascript is used for many, many more things, besides, that add to user experience, helping us to wade through complicated web pages such as online shops and banks, far more easily. And they can also do a huge amount of stuff behind the scenes.
Internet Explorer.
What?
Internet Explorer.
The single biggest security threat, the main concern with javascript, isn’t javascript at all. It’s Internet Explorer, which is the most vulnerable browser. That’s because:-
It’s easy to see why popularity is a problem, a bit like pickpockets flocking to crowds. But that javascript-related security flaw? If you really want to know what that is, yawn, insert techy stuff…
Microsoft has this technology called ActiveX and, to make that more effective, IE has a few added file system commands which other browsers don’t use. These file system commands can be manipulated by an unscrupulous web developer, in rare cases, with unsavoury results. I could go on, but we’d be here all day. However, let me just say, there have been two major scares with IE7 in the last 6 months. Or was it 3? Well, it was at least more than any other browser had.
No.
You’re having me on.
Look. Here’s the deal. This is what you have to read…
Any web browser can be exploited, potentially. Internet Explorer is widely considered, amongst the web security industry, to be the most vulnerable, for the reasons above. It’s still a difficult hit, these days, for very frequently updated browsers. And in reality, an actual attack more generally relies on the web user doing one of the following:-
So really, it’s about user discretion, common sense.
If you are a pirate, spin the dice and can’t keep it in your pants, then turn off javascript for dodgy sites.
If you prefer to surf CNN, Barclays Bank and the Church of England, you’ll most likely be fine.
If you want to be really safe – sorry Bill – bin Internet Explorer and surf safer with an alternative browser. The safest of all is Firefox, for the simple reason that there is an add-on that can be used, called…
This is an add-on, a plugin, that you set up to allow or disable javascript globally, or on individual sites.
A lot of people have downloaded it. In fact, 37,884,458 people. (I just looked.)
I’ve just downloaded and installed it myself. Here’s some detail…
Ha! I tried it out on my site, guvnr.com, because I know exactly what scripts there are. It ran none. Damn! My site was rendered a non-javascript puny raw-html of a thing. Most upsetting. So look. Here’s the deal. If you use NoScript as a result of this review, you must allow scripts on my site. Only fair.
OK…seriously.
It’s good. But it’s tedious to use on the catch-all scripts setting, especially if like me you surf a diverse range of sites, because most modern sites are javascript-rich. I lasted ten minutes with that setting, before changing to allow javascripts globally which means, basically, it’s useless. Then again, I can always turn it back on, easily enough, so that’s flexible. And if you’re unsure about a site, you can easily activate it for the one site.
NoScript is easy to configure. At the bottom of my browser window, there’s a little icon which, when clicked, allows me to quickly enable scripting for the particular page. There’s an options box too, detailing, for example:-
I’m impressed. I’ll put together a guvUtorial about this plugin, but don’t wait up.
With the exception of NoScript, there is no halfway house. If you want to disable javascript, here’s what you do:-
Internet Explorer 6 – if you’re using that browser, you should go to Windows Update and upgrade to IE7 (or bin it altogether for Opera or Firefox!)
To ENABLE javascript, reverse the procedure. For Chrome, replace ‘disable’ with ‘enable’.
Best advice? Run NoScript. Set it to allow scripts on sites you trust, like the bank. And surf safe. You’ll have to install Firefox and scrap IE… so no loss there. For random surfers, particularly those with less experience of the web, I would recommend it highly. For those navigating the web’s extremities, else for those wanting absolute security of their data, it’s a must. But all that said, with the settings set to allow javascripts, my copy may as well not be installed at all. But I won’t delete it. It may be useful sometime. And there’s some insurance there. Orthodox surfers will agree.
For the record, my advice would be:-
Nearly there! Tomorrow, in Part 5, we’ll carry out the single most important task to attain web anonymity, by setting up the proxy server. Join me for that, with a special guvUtorial video, so you can see just how easy it is to do.
Jump to another section of the anonymity guide:-
What have I forgotten? Tons probably. Your comments are valued …
E>T>V January 28th, 2009 at 5:10 am
the web don’t work without javascript
the_guv January 28th, 2009 at 4:01 pm
@E>T>V I agree
E>T>V January 29th, 2009 at 5:23 am
noscript is good as, but firefox is slow
the_guv January 29th, 2009 at 3:50 pm
@E>T>V firefox does use a lot of memory. You can tweak it though…there are lots of guides on youtube. I use firefox for most stuff, and chrome as a side browser to help speed things up.
How to Surf Anonymously & Hide Your PC: Part 3 - How to Set Cookies March 4th, 2009 at 5:49 am
[...] Part 4: Controlling Javascript [...]
koshala August 20th, 2009 at 4:18 pm
can you tell me how to hack a web page
the_guv August 23rd, 2009 at 9:08 am
@koshala .. well, I could but then I’d have to …
SAVE TIME! target="_blank" Hack Using jQuery Javascript - GUVNR January 29th, 2010 at 6:22 am
[...] Want to find out more about Javascript, and the cool-as NoScript Fiefox plugin? Read my guide Don't Get HaCkEd by Javascript – Surf Safe Anonymous Pt 4. [...]
BWHS March 10th, 2011 at 9:29 pm
Seems like php is better for security.