About

Randy Tyler is a recognized pioneer and expert in Online Volunteer program development. Since 1998, his work has been noted by numerous news sources from The New York Times to CTV's Canada AM, and shared with non-profit organizations through provincial, national and international conference presentations and published articles. Randy provides training, workshops, presentations and consultation for non-profit organizations. He is a Gold Medallist graduate of both the University of Winnipeg and the University of Manitoba. For further information, please visit: http://www.RandyTyler.org

The following content is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 Unported License.

TwitterFacebookLaconi.ca/Identi.caPlurkLinkedIn

Security Expert Recommends (Firefox Addon) NoScript TabNabbing Default be Changed

No-script-blocks-unfocused-tab

Prevent TabNabbing with Firefox's NoScript Addon

Since v1.9.9.81, the Firefox Addon "NoScript" has included the capability to block the refreshing of content on unfocused tabs (unfocused meaning not the current tab[s] in use) in order to prevent Tabnabbing (which is basically the hijacking of one of your browser's unfocused tabs for malicious purposes).

In episode 253 of the Security Now podcast, Security Expert Steve Gibson recommended changing NoScript's default (option 1), which only blocks refreshes on Untrusted (sites), Unfocused tabs to blocking Unfocused tab refreshing on both Trusted and Untrusted (sites), which is option 3. This change in the NoScript' Addon cannot be made through NoScript's GUI options but must be made through Firefox's address bar as follows:

  1. In Firefox's Address bar, type "about:config" (without the quotes) and hit enter
  2. In the filter text field, type "noscript.forbidBGRefresh", without quotes
  3. Right Click on the "noscript.forbidBGRefresh" entry and select "modify"
  4. Change the integer value from 1 to 3 (see the screen capture above) and click "ok"
  5. Close your browser and re-start

Note: The line below the "noscript.forbidBGRefresh" entry entitled "noscript.forbidBGRefresh.exceptions' is to add any site where the blocking of unfocused tab refreshing affects a site's function.

For further details about TabNabbing and changing the NoScript Addon settings, please see the Security Now transcript (PDF) for podcast episode 253, which is available at the following URL:

http://www.grc.com/sn/sn-253.pdf

For further information about virtual volunteering, visit Online Volunteering Tips, Technology and Tools or Pioneering Online Volunteering Program Developer Randy Tyler.

Tags   Browser   Firefox   GRC.com   Gibson   IT   NPTech   NoScript   Nonprofit   Online-Volunteering   Randy-Tyler   Security   Security-Now   Steve-Gibson   TabNabbing