As a security-conscious user, I’ve used NoScript since Firefox’s early days, but its restrictive nature has become frustrating. I’m often forced to go unprotected just to access websites with multiple scripts running on different domains, which defeats the purpose of using NoScript and balances security and usability that it once provided.
Is there a way to block browser JavaScript from executing commands that retrieve sensitive information from my local machine, while still allowing JavaScript that is only used for rendering web pages?
by sensitive information I’m referring to
greatly appreciate any insight
EDIT:
could be possible solution
https://discuss.grapheneos.org/d/16025-vanadium-and-what-to-use-on-desktop/19
Most of those things cannot be collected through JavaScript.
Local time can.
RAM can only be approximated to protect user privacy. Edit: And it’s not available on Firefox.
OS+version are already in your browser’s user-agent string that is sent out with every request you make.
Machine hardware cannot be enumerated. JavaScript can try to guess your GPU based on what it can do with WebGL.
There is no way to get a serial number or similar.
To spoof timezone/OS+version/browser+version … and disable WebGL, use https://sereneblue.github.io/chameleon/
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
much thanks to @gary_host_laptop for the logo design :)
Depends what you mean by local information
Your best method:
Use a socksv5 proxy with your browser so it can’t connect to localhost
Use a incognito browser for the login session
Website is able to get info of localhost?
Does this mean they are able to see what docker container I’m hosting?
many browsers allow connection to localhost ports, this is how discord opens discord links in the app and not the browser on people’s desktop computers.
I see, could you link to an article or video that explains more about how this is achieved? Is there a browser extension to disable a website from accessiing localhost connection?
socksv5 proxies, or you could dig into the settings and find a option to disable local connections (not sure where)
by sensitive information I’m referring to
Can I prevent javascript from running specific command that retrieve these information?
If any of that information is critical, you should not be running JavaScript. You should remote into a virtual machine and then browse from there.
Even the tor browser bundle gives away machine architecture
Personally I think a websites requires machine architecture is dubious and necessary, webpage should be functional without those info
your not wrong, but every browser exposes it via javascript. so if that is part of your threat model you can’t use a local browser.