Showing posts with label NoScript. Show all posts
Showing posts with label NoScript. Show all posts

Monday, February 19, 2018

Remedying high CPU usage in Firefox when visiting the Esquire site

I recently visted the Esquire site, and Firefox hung for many long minutes, with Process Explorer (a Task Manager alternative) showing very high CPU usage. To stop this, I had to end the Firefox process.

I experienced this with Firefox 38.8 and 39.0.3, both on Windows XP SP3. These two browser versions are relatively close to one another, but in different computers, which led me to conclude, that the issue is server-side.

The culprit is a possibly malformed font file with the .css extension:

assets.hearstapps.com/sites/esquire/assets/css/fonts-deferred.afa78bb.css

This is the file that you have to block.

If you use NoScript already, don't visit the Esquire site yet, and go instead to NoScript Options.
• In the Other tab, there is the ABE subtab;
• Click the USER rule/set in the left pane, and paste the following code into the right pane:

#ESQUIRE HIGH RESOURCE USAGE
Site .assets.hearstapps.com/sites/esquire/assets/css/fonts-deferred*
Deny INCLUSION(FONT,CSS)

#This is a widespread tracker or ad service of some kind.
#Used by Esquire, too.
Site .nexus.ensighten.com
Deny

Click OK.

You can now try out the Esquire website. Works for me.

05.10.2018 Update: I've shortened the Site line to end with fonts-deferred*. NoScript's ABE should still match the pattern. The reason was, that the original file was fonts-deferred.afa78bb.css, which contains alphanumeric content that may be used for version tracking server-side. Removing those numbers and including a wildcard makes the line relatively future-proof from newer versions of the same file.

Saturday, September 24, 2016

Postimehe otseblogi ja NoScript

Firefoxis on NoScript laiendus kasulik selleks, et blokeerida skripte ning säästa arvutiressursse — et arvuti oleks kiirem. See sobib olukorras, kus masin pole kõige uuem, kuid ajab asja ära.

Probleem seisnes selles, et Postimehe otseblogi miskipärast ei näidanud, ehkki NoScriptis olid kõik Postimehe/PMO domeenid lubatud.

Tegemist oli konkreetselt töölaua-Firefoxiga, kuid sama asi kehtib teiste Firefoxi- ja Gecko-põhiste lehitsejatega, sh SeaMonkey, GNU IceCat, Debian Iceweasel jt.

Selgus, et otseblogi laaditav failitüüp ei olnud Firefoxile sobilik (failitüübi kontroll ei lasknud faili läbi), ning otseblogi ei laadinud enam. See paistis silma lehitsejakonsoolis (Tööriistad > Veebiarendajale > Browser Console).

Lahendus:
  • Minna about:config lehele, otsida parameeter nimega
    noscript.inclusionTypeChecking.exceptions
  • Väärtusele lisada järgmine tekstiosa koos tühikuga alguses:
    http://f.pmo.ee/s/failid/live/*.liv
Otseblogiga artikkel tuleb uuesti laadida, ning nüüd peaks otseblogi töötama.

Väike ääremärkus, et Androidi-Firefoxi ja IceCatMobile lehitsejatega, kus ka NoScript peal, selliseid probleeme pole, sest nendes on NoScripti mobiiliversioon vähemfunktsionaalne.

Lahendus oli NoScripti foorumis.

Sunday, May 15, 2016

Useful apps exclusive to Android


This is a copy of a comment I wrote in a YouTube discussion to someone who recommended that "[I] get an iPhone".

I've formatted and edited the comment with some additions into this blogpost. While it does harken back to a previous post I wrote about reducing one's Android's resource usage, then this one is more about some of the useful apps I use that are exclusive to Android.

An iPhone or any new smartphone is beyond my means, and I wouldn't be able to run some specific apps only available on Android, such as:
  • Adblock Plus for Android. Works only on Wi-Fi, but blocks in-app ads;
     
  • Firefox for Android. It's got Reader Mode, which saves an article, only keeps relevant article content, and allows white-on-black reading.

    Firefox extensions, which only run on Firefox-based mobile browsers:
    • NoScript Anywhere — blocks scripts and trackers run by scripts, and thus reduces browser resource usage. Its whitelist allows running scripts on sites I whitelist through the NoScript menu in Firefox;
    • Privacy Settings — allows users to switch off a number of default Firefox settings to make the browser less resource-hungry and more secure;
    • Stylish — allows users to locally change the appearance of webpages displayed in a browser (make them dark, etc. to save battery life). People can download or make their own userstyles.
    • Save Link Menus — allows saving links or webpages from Firefox to the local file system.

  • Vim Touch — a very advanced text editor. This adds to productivity (I can create and edit content);
  • Hacker's Keyboard — I need this to use VimTouch, to easily navigate in text, and to quickly switch between languages without going to settings every time. This keyboard app is very lightweight compared to most native virtual keyboards;
  • Unicode Map — to search for, view, and copy Unicode characters;
  • VLC Media Player. 'Nuff said;
  • Arity — a scientific calculator, but I sometimes use it to calculate expenses when shopping for multiple things with a limited budget.
There some other apps with functionality not particularly unique to any mobile ecosystem:
  • Sparse RSS — to subscribe to podcasts;
  • Units — a very nice unit converter;
  • MuPDF — a lightweight viewer for PDF, OpenXPS and CBZ files;
The above apps are all Free / Open Source Software (FOSS), and available at the F-Droid app repository.
    Stock app —
  • FM Radio. I can listen to plain FM radio and listen to great music for free and without ads. Estonia's public broadcaster ERR is just that awesome. They even provide small "what's playing" pages, so I can check out the artist and song.

    FM radio functionality is not on most iPhone models, and not on most Windows phones either. My phone even supports RDS.

  • Some proprietary apps:
  • TeamViewer — I sometimes do computer support for friends and relatives;
  • The local weather widget.

This post is licensed under CC-BY-SA-3.0.

Tuesday, March 29, 2016

Pisut kriitikat "Postimehe" uue "mobiilielamuse" aadressil ja paar lahendust aeglastele nutitelefonidele

Kiirelt kirjutet ja sõnakas postitus, nii et kes loeb, on hoiatatud.
    Tingimused:
  • Vanem nutitelefon, operatsioonisüsteemiks Android 2.3 Gingerbread.
    Igal Androidil on vaikimisi lehitseja, mille kokkuleppeline nimi on "Android Browser"; kasutajaliideses lihtsalt "Internet".

    Android 2.3-ga kaasas käiv lehitseja on tehnoloogiliselt ja moraalselt vananenud, ning ei esita modernseid lehekülgi enam õigesti.
  • Sellest johtuvalt on kaasaegsete mobiililehtede vaatamiseks peale pandud Firefox Androidile. Et see vanemal seadmel enam-vähem kasutatav oleks, on Firefoxi lehitsejas suurem osa ressursinõudlikke funktsioone välja lülitatud, samuti on peal laiendus NoScript Anywhere (edaspidi NoScript), mis blokeerib vaikimisi skriptid kõikidelt tundmatutelt saitidelt ja lubab käitada vaid kasutaja poolt hallatava valge nimekirja kaudu lubatud skripte. Väga mugav.
Kuni selle aasta märtsi mingi kuupäevani oli "Postimehe" (edaspidi PMO) mobiiliversioon enam-vähem kasutatav, ning selle ajani kehtinud PMO mobiili jaoks sobiva ja kasutatava disaini küljendajatele tuleb jagada ohtralt kiitust. Sest see Disain töötas hästi.

Kui anonüümne kommenteerimine oli võimalik, sai ka kommenteerida, ning artikleid sai samuti segamatult lugeda.

Siis tuli 2016.a. märtsi keskpaik ja natuke peale seda, kui PMO lugemiseks avaldati üks ressursimahukas äpp (õieti mobiiliversiooni uus wrapper), avaldati paar päeva hiljem ka sellele ekstra küljendatud spetsiaalne m.postimees.ee.

Lihtne oleks ju öelda, et juhe jooksis kokku.

Valesti läks see, et PMO uus versioon tehti automaatseks, mis uuendab sisu ise, mis omakorda on oma loomult päris ressursimahukas tegevus.

Tõepoolest — silmailu on, aga selle saavutamiseks on ohverdatud kasutatavust.

Tuleb nentida, et kasutatavuse huvides ei oleks mina m.postimees.ee varianti mobiilseadmete jaoks üldse käiku lasknud, sest u. 2016.a. märtsi teise pooleni üleval olnud ise-mitte-uuesti-laadiv lahendus töötas mobiili-Firefoxis hästi.

Niigi lülitati 2015. aastal välja Postimehe WAP/WML-versioon, mis oli ülikiire ja -mugav viis uudiste lugemiseks. Ma tõesti ei tea, mis WAP-versooni väljalülitamise põhjuseks võis olla, kuid kahtustan, et sellega oli võimalik lugeda ka selliseid artkleid, mis käisid tavapäraselt "Postimees Pluss" alla. Jaa, WAP (WML) eelised jõudsid kohale alles 10-15 aastat hiljem.

Lahendus

Erinevalt töölaua-Firefoxis olevast NoScriptist ei ole Androidi-Firefoxis võimalik NoScripti valget nimekirja detailselt toimetada. Samuti ei võimalda mobiilse NoScripti kasutajaliides konkreetselt alamdomeenide lubamist/mittelubamist.
26.04.2016: ^ Veidi täpsustatud sõnastust.
Niisiis: Firefoxis on about:config seadetest extensions.nsa.policy alt võimalik kopeerida JSON formaadis olevat valget/musta nimekirja, mida on küll võimalik teksti kujul toimetada, aga koodi iseärasuse tõttu saab seda teha ainult tekstiredaktoris.
(Firefoxile mõeldud NoScript-i ametlik nimetus on NoScript Anywhere, ehk NSA...)
Jama on selles, et see JSON-rida on pikk üherealine tekstijoru. (Õnneks on JSON formaat suhteliselt lihtsalt loetav.)

Selle toimetamiseks on niisiis vaja tekstiredaktorit; isiklikult soovitan kahte äppi:
  • VIM Touch-nimelist tekstiredaktorit, mis on väike, võimas, ja algajale suhteliselt keeruline selgeks saada. A kui selge on, on lihtsam.
  • Hacker's Keyboard, mis annab Samsung Keyboard vms asemel täieliku sõrmistiku kõigi vajalike nuppudega.


VIM-i tundjad tõenäoliselt teavad, mida selle JSON-joruga edasi teha; praegu pikemalt ei seleta kui vaid niipalju, et JSON rida tuli kopeerida ja asetada VIM-i, siis iga domeeen käsuga :s/\,/&^M/g eri reale, siis sorteerida, ning siis toimetada ja lisada domeeni järele 1 või 0; 1 vastavalt lubab, 0 keelab. Komad lõppu ka, v.a. kõigeviimane domeen. Ärge unustage tegemast varukoopiat.

Supp seisneb selles, et PMO uudiste normaalseks lugemiseks tuli mul blokeerida ära http://m.postimees.ee ja lubada http://www.postimees.ee .
Varem arvasin, et alamdomeene võis lubada ainult http:// prefiksiga ja et ilma polnud võimalik; kuid vähemalt alates NoScript versioonist 3.5a11 sai seegi lõpuks võimalikuks.

Siiski jäin endise praktika juurde, ning turvalised domeenid on vajadusel alati https:// prefiksiga: näiteks kõik Google'i domeenid.
m.postimees.ee tuli blokeerida selleks, et uudiseid vaid lugeda; www ja kõik teised alamdomeenid lubasin selleks, et uudiseid kommenteerida (teoreetiline võimalus on olemas ju), ning mis põhiline — et kommentaare saaks reitida (lisada + või – ).

pmo.ee teise taseme domen on vaikimisi lubatud, teised reklaami- ja muud domeenid mitte. Blokeeritud oli eraldi http://ads.postimees.ee . Sest akut peab säästma.

PMO temaatilised alamdomeenid on kontseptuaalselt iseenesest hea, kuid kuna neid on palju, siis NoScripti valge nimekirja toimetamisel on nende käsitsi lisamine ebamugav. Vähemalt pole edaspidi vaja neid lubada/blokeerida.

Reklaam ja reklaamiblokeerijad

Tõepoolest, "Postimees" elatub osaliselt ka reklaamirahast, kuid erinevalt kaasaegsetest PC-arvutitest on vanemate arvutite ja mobiilidega tihtipeale see lugu, et vähese võimsusega on ka sama vähe mõtet reklaame vaadata ja lugeda. Mobiil-interneti puhul tuleb arvestada ka sellega, et inimesed reklaamide tõmbamise eest tegelikult väga maksta ei taha.
Miks mitte lisada PMO tellimus telefoniarvele näiteks?
Võib ju väita, et vähevõimas nutitelefon on oma omaniku peegelpilt, aga niisuguseid inimesi on ka, ehk "üksteist peab hoidma," nagu ühes armsas laulus sõnat'.

Hästivarustatud tavakasutaja koos uusima nutimudeli ja põhimõtteliselt piiramatu mobiilsidega selliste asjade pärast eriti muretsema ei pea.

Kvaliteetväljaandena on Postimees Online on siiski üks väheseid, kus on huvitavaid ja informeerivaid reklaame, ning neile klikitakse/toksatakse vajadusel peale küll. Teadlik reklaamitarbija tõepoolest mõistab iga kliki/toksamise väärtust.

Tõsi küll, võimalik on kasutada ERR-i kui tasuta uudistekanalit.

Infoallikatena on PMO ja ERR mitmes mõttes asendamatud. Delfi kui uudisteallika väärtuse kohta 'ei kommentaari,' kuigi nene mobiilse veebi jaoks mõeldud lahendus paistab (pea) kõigist oma lugejaist hoolivat... või noh, oma lugejate mobiiltelefonidest... :>

Lõpuks töötasin välja parima lahenduse võimalikest. Aga sellest juba tulevases postituses.
Uuendatud 26.04.2016.

Sunday, March 27, 2016

Firefox for Android on slow phones. Some practical advice.

This one was supposed to be a quick post; I might update it later on. And then I got carried away, and spent about four to six hours writing the post's content and refining its wording.

* That Firefox for Android can render better than the aged native browser on Android 2.3, is great, but at the moment, I won't go into detail about that.
* This post is not about desktop Firefox. I might write about issues current in desktop Firefox in a future post.

Contents

* What happened
* My phone is slow now.
* What to do. Extensions to speed up Firefox

Until today, I have avoided that "What I Use" post, but every once in a while comes a time, when I am not afraid to write about what I use. Even if it's not the newest kit.

Why I downgraded

After Firefox 45.0 was released, one early and now resolved issue was connection misbehavior with Firefox 45.0 and NoScript 3.5a10. Very soon, NoScript 3.5a11 was released, which fixed the issue.

Then, after upgrading, I also discovered, that Firefox 45.0 turned to using the Firefox-native toolkit for its main menu, which is slower than the natively formatted main menu in Firefox 44.0.2 and earlier.

For this and then-the earlier issue, I decided to downgrade back to Firefox 44.0.2 from version 45.0. The slow and inefficient main menu became cause not to upgrade any further on my device—except for testing.
Note, that when upgrading or downgrading apps in Android, use the overwrite method when installing; Do not uninstall the existing app version to then install a different version, or this action will forever delete all your user data for the app.

Backround

Thus, it slowly dawned on me, that my phone is showing its age. It's a Samsung Galaxy Mini 2, which model was released four years ago,[as of March 2016] but I got it in late 2013 as a pass-me-down, after it had two nearly grave misadventures with its previous owner.

* The Galaxy Mini 2 has an 800 MHz Snapdragon S1 CPU (specifically, MSM7227A), which is on the lower end of processors built on the ARMv7-A architecture, and uses the ARM Cortex A5 processor core.
* The phone runs Android 2.3.6 "Gingerbread", and won't be upgraded to a newer offical Android version.
* The device has just enough minimum required RAM memory to run Firefox for Android.

This soup of specifications essentially shows what the minimum for running a very modern version of Firefox for Android can be.

That major apps — such as Facebook and games — are not present, is a given. I've also excised other apps that I did not deem necessary anymore: BBC, ERR, Postimees, and a local service provider's player app.

What to do

In Firefox settings, disable telemetry and plugins. The Privacy Settings extension will make it simple to turn off other stuff.

Extensions to speed up Firefox

The following details two extensions that I use in Firefox for Android to have a reasonably passable browsing experience.

NoScript Anywhere.
In my phone, NoScript Anywhere ("NSA") makes browsing with Firefox a usable experience:
NoScript blocks scripts and plugins from running, and users can use the NoScript menu item to create an internal domain-based whitelist of sites which won't work without scripts. With this, NoScript not only blocks scripts, but also advertisements generated by scripts.
Another thing that shows the phone's age, is that the local daily "Postimees" launched a redesign of their mobile experience this month, and now their site redirects to their brand-new mobile site, which, if JavaScript-enabled, updates every ten minutes with AJAX, and that slows down the experience and the phone, and presumably eats away at the battery, too.

The obvious solution was to forbid postimees.ee from running scripts, thus removing it from the allowed sites list. This mangled the design somewhat, but at least the site will display reasonably responsively. Yes, it's a simplistic workaround, but it makes it possible to read news there, even if the site is not functional. The functional part was the possibility to rate comments, but "Postimees" removed the ostensibly anonymous commenting functinality. Most people just don't care to create a burner account on social media, and neither do they care risking their primary social media/e-mail accounts.

Privacy Settings
Another Firefox extension that reduces resource usage, is Privacy Settings. It's available at the Mozilla Add-ons site. With Privacy Settings, it's possible to switch off components that I don't have any need for. There are some settings that I have kept on, as switching all things to 'secure' may break rendering or accessing places like Instagram. While Privacy Settings won't work on older Firefox versions that can still run on Android 2.2 or earlier, or on ARMv6 CPUs, the extension's website has a breakdown of some of the about:config settings that one can modify manually.

I'm also considering the Policy Control extension, as it would reduce resource usage even further, and introduce more fine-grained control over which website can use which resources.

Thursday, January 21, 2016

Can't see Instagram in Firefox?

Trouble was, that Instagram and embedded Instagram pictures recently stopped loading in Firefox.
This also affects other Gecko-based browsers.
> If you want to skip the story, jump to solution.

While I also use NoScript on desktop Firefox, and on Firefox for Android, all the necessary instagram domains were allowed.

On the desktop, I'm mostly using Firefox 39.0.3, because it plays well with Flash. (There were no issues like that with other browsers.) First I thought, that this was because I wasn't using the latest Firefox. As this Firefox version plays well with Flash, I didn't want to upgrade to the latest version, because with the latest Firefox, Flash playback on YouTube is jerky since Firefox 40.

But the Instagram issue repeated, when I was also using the latest Firefox for Android. Initially I thought, that this was the fault of Instagram, and since I don't use Instagram or Facebook, I didn't think much beyond that. And for a month or so, I couln't resolve it.

But when Instagram showed in a different computer in the latest desktop Firefox (43.0.4) with the same extensions installed, I began to investigate again.

When reloading a random Instagram page while also watching the Firefox Browser Console, I found an error, which, in pasted form, looks like this:
05:16:59.308 An error occurred during a connection to instagramstatic-a.akamaihd.net:443.

Peer attempted old style (potentially vulnerable) handshake.

(Error code: ssl_error_unsafe_negotiation)
1
After some searching, I found the solution in a game forum.

SSL safe negotiation setting

Turned out, that when perusing the Privacy Settings extension of Firefox, I had turned all the settings to most secure, and among them turned on security.ssl.require_safe_negotiation. After I turned that off, Instagram showed again.

If you don't have the Privacy Settings extension installed, go to about:config and type in or paste security.ssl.require_safe_negotiation . The boolean setting value for it should be false. If not (if it's true), then double-click the setting or press enter on it to set it to false. Or right-click for context menu to Toggle.


Otherwise, the Privacy Settings extension is awesome, and I recommend it to everyone.

Whereas people who manage instagramstatic-a.akamaihd.net, should implement new-style SSL/TLS handshakes to keep their corner of the web safe.

So this was the issue that affected me.

NoScript

If, on the other hand, the above is not an issue, then you might be having NoScript installed to defend your browser from malware, and among other things, it's blocking Instagram domains, which means they're not in the whitelist. Jump to domains.

NoScript has a blue "S" button that shows the status of whether a page is completely blocked, half-blocked (content from other domains has been blocked, which is most common), or completely allowed.

That button is usually visible in the location bar, or accessible through Firefox's hamburger menu. (If the blue 'S' is not there either, click the green Customize button in the hamburger menu to see if the NoScript button is listed in the 'Additional Tools and Features' section.)

One can change NoScript domain permissions thus:
* Hover the pointer over the blue "S" button, which launches a menu with a list of domains. If the NoScript menu is very long, it has small up and down arrows for scrolling.
* To whitelist a domain, click on "Allow domainname.tld". Alternately, domains can be blocked by clicking on "Block domainname.tld". This can be done in one go for several domains.
* Once the cursor hovers away from the menu, NoScript will automatically reload the affected page (or pages in other tabs). If a page or pages don't reload (per custom settings), they can be reloaded manually.

For Instagram, the following domain names must be allowed:
platform.instagram.com
instagramstatic-a.akamaihd.net
www.instagram.com
The above are all third-level domains, because they contain three name components separated by periods/dots.

By default, NoScript shows only base second-level domains, such as instagram.com without the www and a dot. For most common users with NoScript, allowing instagram.com and akamaihd.net is sufficient.

Wednesday, April 3, 2013

Mozillale NoScripti installimine Windows Vistas

Seesinane on siis eestikeelne kokkuvõte oma varasemast ingliskeelsest blogipostitusest. Alguses kirjutasin selle kohta ühele sõbrale, ning kuna tekst osutus siiski pikemaks, leidsin ma seejärel, et jutt vajab avaldamist.

Hiljuti ühes Windows Vistaga masinas avastasin Mozilla 1.7.13. Tegemist on siis tarkvarapaketiga, mille lehitsejamoodul on sama vana kui Firefox 1.0.8 (Aprill 2006; esitlusmootor pärineb 2004. aastast ja Mozilla enda arhitektuur 2001.-st aastast).

Et Mozilla mõnede lehekülgede JavaScripti pärast kokku ei jookseks, läks alguses palju aega, et kuidas sellele NoScript nii peale panna, et töötaks, sest umbes sama vanale Firefoxile Knoppix 4.0.2-s (2005) sai küll. Lõpuks jätsin asja katki...

Mõni kuu hiljem leidsin lahenduse (Mozilla tuli käima panna administraatori õigustega) ja siis panin peale NoScripti, aga nii, et see tuli kindlasti installida Mozilla kasutajaprofiili kataloogi.

SeaMonkey 1.1-ga sellist probleemi ei tohiks olla, sest SeaMonkey 1.1 ja Windows Vista arendus/väljalase langes umbes samale ajale, et põhimõtteliselt sai seda Vista jaoks siis veel kohendada nii, et oleks parem ühilduvus.

SeaMonkey 1.1.19 on üks viimastest vabatarkvaralistest graafilistest lehitsejatest, mis töötab Windows 98/Me peal.

Monday, March 11, 2013

Installing NoScript to Mozilla in Windows Vista

This blog post describes how to install NoScript to Mozilla Application Suite in Windows Vista.
In all actuality, this should also apply to other compatible Mozilla extensions.

Conditions:To install NoScript in an account with administrator rights,
  • you must run Mozilla as administrator.

    For how to properly install NoScript in a guest account, see below.
    Attempting to install in any other way won't work. Yes, I've tried it myself before I found the solution.
  • I chose NoScript 1.1.4.7, because it's the last version for Firefox 1.0.x.
    The reason is that Firefox 1.0.8 uses version 1.7.13 of the Gecko layout engine, which also matches the last version of Mozilla Application Suite. Any newer version might be incompatible, and I haven't tested NoScript 1.10, which is the last version for SeaMonkey 1.1.
  • Since Mozilla 1.7.13 is eight years old and does not support modern web standards, installing any extension from addons.mozilla.org requires more steps:
      To download version 1.1.4.7 of NoScript from addons.mozilla.org,
    • go to its version section there and hover over the 1.1.4.7 section so that the Download Now link which looks like a button becomes visible.
    • Right-click on the Download Now link, choose to "Save Link Target As..." from the context menu, then save the extension into a folder of your choice. The Mozilla extension is saved with the .xpi file extension (but not installed.)
    • 01.03.2014 update:
      If that does not work (because of design changes at a.m.o), go instead to Mozilla's relevant addons folder for NoScript at ftp://ftp.mozilla.org/pub/addons/722/, and scroll down to the chosen version.
      Firefox addons developers, either by tradition and culture or requirements from a.m.o, append their addons' XPI files with product acronyms as markers of compatibility with a client program in such a way that amongst browsers, fx stands for Firefox, sm for SeaMonkey, and mz for Mozilla. This should inform users of older client versions as to which extension version is still compatible.

      As I skimmed over Mozilla's NoScript FTP folder with above knowledge, I noticed that the most recent NoScript version marked with mz is actually 1.8.2.1. I don't remember having tested that version with Mozilla in Windows Vista before, but I hope other adventurous users might be lucky. Maybe in the future I will get to test that version, too.
    • in Mozilla, browse to the on-disk location of the saved extension, and click on it to install. The filename should be noscript-1.1.4.7-fx+mz+sm+fl.xpi
  • Given the circumstances, always install NoScript and any other extension into the user profile and not the general installation folder, because it may be rather difficult to remove it afterwards.
  • Once the extension reports it's installed, exit Mozilla.
  • Then start Mozilla again as Administrator to finish the install process, then exit Mozilla again.
  • Start Mozilla normally.
Added L., 01.03.2014.:

Installing NoScript in a normal/guest account.

Now, in a normal or guest account, it needs more work, mainly because of the differing designs of Windows Vista and Mozilla. We should remember that Mozilla 1.7.13 was made to run in Windows 95...

It won't be necessary to run Mozilla as administrator, because it will launch the instance with administrator credentials, which then brings its own settings as set in the administrator account.

Installing NoScript into Mozilla in a non-admin account mostly follows the steps of installing in the user profile space. After that, restarting Mozilla fails with this error:

"The program must close to allow a previous installation attempt to complete. Please restart."

The result in the background is that Mozilla starts, and starts xpicleanup.exe.
The following is an assumption: xpicleanup.exe wants to delete xpicleanup.dat, and unlike in Windows xp and older, the latter file is placed not where xpicleanup.exe anticipates it to be. xpicleanup.exe then fails to delete the file, Mozilla exits, and renders xpicleanup.exe an orphan process, hanging in memory. Trying to start Mozilla several times leaves more instances of xpicleanup.exe in memory. These processes must be ended either from Task Manager or Process Explorer.
Finding xpicleanup.dat within your profile, deleting or renaming it to xpicleanup.bak does the trick, and Mozilla will start again, with NoScript installed and functioning. (I usually rename such files as filename.ext.bak in order to preserve its extension, might I ever need the original and now renamed file again.)

xpicleanup.dat for a normal/Guest account (yours might be named differently) is located at —

C:\Users\Guest\AppData\Local\VirtualStore\Program Files\mozilla.org\Mozilla\

^ to browse there, enable viewing of hidden files at folder options (Alt or F10 > Menu > Tools > Folder Options)

Useful instructions from a post by Alice at MozillaZine Forums.

A little bit of background information and history

Mozilla Application Suite (Mozilla) was not designed with Windows Vista in mind, so using it in a modern operating system is not without obstacles. Yes, it does run, but this post about installing extensions sort of shows where some of the caveats lie.

Mozilla was at the time the open source base for Netscape, and version 1.0 of Mozilla was released on 05.06.2002, which is roughly 11 years ago as of 2013. I mean, wow, eleven years. Anyways, Mozilla was released to a wide variety of operating systems and for just as wide a variety of versions of each, including Windows 95, Windows 98, Windows 98 SE, Windows Me, Windows 2000 (released 17.02.2000) and Windows XP (itself released on 25.10.2001).

After version 1.0, Mozilla progressed to have quick developments over its lifetime by getting new features added, but not too much by way of changes to its baseline architecture.

Longevity
Mozilla's penultimate 1.7.13 version came out on 21.04.2006, just five and a half months before the RTM version of Windows Vista was finalized on 08.11.2006. Windows Vista was released to general availability on 30.01.2007.
 
Mozilla 1.7 Alpha is dated 23.02.2004, and 1.7 itself came out on 17.06.2004, so there is two years and about two months of time between 1.7 Alpha and 1.7.13, and exactly two years between 1.7 RC1 (21.04.2004) and 1.7.13.
After mozilla.org ceased development of Mozilla Application Suite, another team took over development and renamed the project SeaMonkey. Windows Vista was not released yet by the time SeaMonkey 1.0 arrived on 30.01.2006, but beta versions of Vista had to have been available already.
 
SeaMonkey 1.1.xx (18.01.2007 and on) was thereafter developed to accommodate Windows Vista, with SeaMonkey 1.1.19 (16.03.2010) being the last version of the 1.1 line, and the last for Windows 98/Me. Note that Windows 7 was released on 22.10.2009, so there's a great possibility that SeaMonkey 1.1.19 should run well on that operating system, too.Three years and nearly two months between SeaMonkey 1.1 and 1.1.19.

Overall, if I discount layout engine changes, then Mozilla and SeaMonkey are essentially the same product and programmatically the same infrastructure. When taking into account the release dates of Mozilla 0.8/0.8.1 (14.02.–26.03.2001), when it finally became reasonably stable and usable, and SeaMonkey 1.1.19 (16.03.2010), then that whole architecture has lasted for about nine years. Ten when factoring in development time, but that's a stretch considering official titles. If I were, on the other hand, to also consider Classilla, a browser for Mac OS 9, and the latest version of which was released on 19.10.2012, then all in all, Mozilla's run could certainly be timed to ten years from Mozilla 1.0, eleven years from Mozilla 0.9.5 (12.10.2001), and almost twelve years since Netscape 6 (06.12.2000).

Such a long lifetime for one branch of development is a testament to its quality and reliability over a long span of time.

Future

The reason to have NoScript in Mozilla is that the browser is just so old and can easily crash with a piece of JavaScript newer than what Mozilla can support. It should be of relevant help that the post that follows this one, is a tutorial on installing extension uninstallers in Mozilla and SeaMonkey.

Friday, June 22, 2012

Cannot play videos on Yahoo! News?

Symptom: This often happens with users of Firefox and other Gecko-based browsers, when:
• they can't show most news videos on the Yahoo! News website and some other Yahoo! properties;
• the commenting system is not functional (can't properly view and post comments).

Privacy-conscious users, and/or those who wish for their browsers to consume less resources, use a script blocking add-on, such as NoScript. I often have NoScript configured to allow/disallow full domains (like d.yimg.com) and not just second-level domains (just yimg.com).

As it often happens, allowing only full subdomains instead of just second-level domains brings with itself more issues.

By default, NoScript includes a whitelist of second-level domains without which major services' functionality would be wholly disabled. The whitelist also contains yahoo.com, yimg.com, and yahoopis.com). The instructions herein are for users who have chosen to impose a more fine-grained control over the websites they visit.


Right, well, I finally played around with NoScript and found a solution:

NoScript:
    In addition to news.yahoo.com and screen.yahoo.com and maybe others, allow the following domains essential for video playback:
  • l.yimg.com
  • d.yimg.com
  • connect.facebook.net (If you're privacy-conscious, then allow temporarily).

  • 11.07.2012. Update: I later discovered that non-video news items also featured videos, so here's an addition of domains that must be allowed:
  • video.query.yahoo.com
  • yep.video.yahoo.com
  • yui.yahooapis.com (important on other Yahoo properties, even if not using video)
  • webplayer.yahooapis.com
Flashblock:
• Allow d.yimg.com
^ Including only that domain in the Flashblock whitelist will have the video area rendered with the Flashblock placeholder. Clicking on it will start playback (note that ads are also played).
• Allow l.yimg.com
^ In regular news items that included video, disallowing l.yimg.com wouldn't even load the Flashblock video placeholder.

If you want video to load automatically, allow the above domains, and news.yahoo.com and screen.yahoo.com (and/or other Yahoo! properties as necessary from the Flashblock toolbar button).

Conclusion

Even if l.yimg.com and d.yimg.com are enabled in NoScript, the crucial part for some erroneous coding reason is connect.facebook.net; If that is not allowed, most video code and commenting functionality won't load. Note that connect.facebook.net is the primary culprit. This has been discussed before at forums.informaction.com (a NoScript and web security forum).

Monday, April 25, 2011

Somehow installing, configuring, and using NoScript in K-Meleon 1.5 via Wine

I am assuming that you probably already know how to use Wine and know your way around the computer.

The conditions: Knoppix 4.0.2, because it runs passably with 128 Mb of RAM, in a situation where no swap space is available. This version of Knoppix has a really outdated version of Wine, which makes it difficult to use Windows programs there. There may be people stuck with either that version of Knoppix or that old version of Wine. At least this post provides a case study, which I hope could be of some interest.

The only reasonable place I could find NoScript for K-Meleon 1.5.4 is from extensions.geckozone.org/KMES-NoScriptEn. The version is 1.7.8.0 and it's from 17.06.2008 (that's 2 and 3/4 years old as of April 2011).

First off, change installer's .exe file rights for it to be an executable. Like this from the command line:
chmod u+x "K-Ext(1.1-1.5-1.6)_NoScript(1.7.8.0).exe"
^ u = for current user; + = add/enable; x = executing;
The filename is wrapped in double quotes, because it contains parentheses "()".
In my case, the first round of installation didn't work. Later I specified this target install directory:
z:\mnt\hda1\Program Files\K-Meleon
^ can't remember if I specified an upper- or lowercase letter z
and installation worked after that.

K-Meleon should not be running during installation, so run it after installation.

27.04.2011.–: After a relatively quick-and-dirty article which turned out to be far more specific than originally anticipated and still quick-and-dirty, I've updated the following with information which will make K-Meleon slightly easier to use as it is, with what the setup is and all...
When running K-Meleon through Wine in Knoppix 4.0.2 (remember that it's from 2005 and very outdated) and when you're stuck with such a set-up:
  • The NoScript button menu can be used with a mouse by right-clicking on the NoScript button and holding the pointer device button down and dragging the cursor to the necessary command (shortcut menus will otherwise turn off after right-clicking on an item and hovering a mouse cursor over its menu; I've seen this in TWM, don't know how it works in other window managers).

    Other ways:
    • Click on the NoScript button, then use menu hotkeys (underlined) to perform a function;
    • or consider dragging the pointer through the NoScript menu via the main Tools menu.
  • Saving configuration changes in the NoScript Options window does not work, because it's impossible to save settings by clicking the OK button, but you can otherwise close the window (saving options may work with newer versions of Wine; haven't tried this myself).

    Workarounds:
    • Configuring NoScript is possible only at about:config for settings (use the noscript text pattern in the about:config search bar to get NoScript-specific settings);
    • ^ Consider removing some default domains there from the noscript.default string;
  • Worse, the NoScript menu in K-Meleon (at least in the given configuration and set-up) won't show domain names in its menu (Shock! Horror!).
    • Now, the whitelist, which is not shown in about:blank, is only configurable in prefs.js at the local K-Meleon profile folder on the hard drive (from where K-Meleon is run). If you don't know what the prefs.js location of the current profile is, open Preferences, go to "Privacy & Security" preference category, click on the Cache tab and see the "Cache Folder:" entry, which shows the location of the current profile folder.

      An example location is here:
      "/mnt/hda1/Program Files/K-Meleon/Profiles/g1bb3r1sh.default"
      So, edit the prefs.js file with a text editor at this line:
       
      user_pref("capability.policy.maonoscript.sites","place.doma.in nam.es here.com in.alphabetic.al ord.er.com ea.ch doma.in na.me separated.wi.th a.space.com and.do not.break.the.li.ne");
       
      Make sure just in case that K-Meleon is not running when editing the file, because if you've saved the file and then exit K-Meleon, then K-Meleon is highly likely to overwrite your changes.

      13.09.2011.
      Given that I had been using K-Meleon like that for a longer while, I created a menu item in the TWM window manager, where I could directly open the prefs.js file from the menu.
    • Alternately, adding sites to whitelists works from the menu (see above), but since the above configuration does not make it possible for the K-Meleon URL bar to function and display addresses, then a user is limited to knowing the site domain and web page address in the following ways:
    • In K-Meleon, the tab bar is typically shown by default, so it should be enough to hover the mouse cursor over a page's tab button: This displays the tool tip, which then shows the site/page title and its partial address.
    • A user might know the site's domain name, if they've entered it themselves (because of limitations, entering a URL goes through editing bookmarks and accessing a bookmark set up for just that).

      A user can specify that only top-level domain names are added, by setting this in NoScript preferences through about:config, only that the whole point of NoScript to me is the fine-grained way in which some subdomains can be whitelisted, so that disruptive ones are duly excluded. Unfortunately, not directly seeing a site's domain name in the URL bar has security implications, including the fact that the non-functioning URL bar doesn't change color when visiting a secure site, though a bottom-right status bar indicator should work. Preferably, only safe sites should be visited. (Avoid clicking e-mail links, if you know they're dubious, but this requires at least some user education and this is where NoScript is useful. There is nevertheless a greater amount of security in running K-Meleon equipped with NoScript, no matter how limited it is, through Wine in Linux than in Windows 9x);
    • Some necessary domain names pulled by a page from (a) differently-named domain/s to fetch scripts and/or stylesheets across sites and subdomains are not displayed anyway (not even in the NoScript menu), so there is no direct way of learning which other domains must be allowed for scripting.
    • Consider disabling NoScript for the duration of the session, if you're using a service which requires logging in and if it's been impossible to learn what are the exact outside domains with necessary scripts.
    • The third option is to import domain names from other NoScript settings in other prefs.js files. This actually works. But what if using a new service that users a non-primary domain name for scripting? Or what if an existing service sometimes changes its subdomains?

Tuesday, January 25, 2011

Older Flashblock and NoScript for older Firefox and SeaMonkey versions

If you're ever stuck with an older computer and a Live CD (an older version of Knoppix) or an older computer with Windows 95/98/Me and an older version of Firefox or Mozilla or SeaMonkey, then useful extensions (add-ons, but not plugins) for these still exist and can be installed.

(If installing them from a website won't work, download an .xpi separately and install from local storage.)

The most recent version of NoScript to support —

• Mozilla Firefox 1.0.x (in my case): 1.1.4.7 (XPI)
01.02.2011.
Noscript caveat:
Version 1.1.4.7 does not block META redirects within <NOSCRIPT> elements in HTML. — I saw this with one Russian social networking site.

The noscript.forbidMetaRefresh boolean (set to true) in about:config only applies to refresh elements outside <NOSCRIPT> tags.

Turned out that the functionality blocking META-refresh-in-<NOSCRIPT>-tags was first introduced with version 1.1.4.8RC1 of NoScript, which only supports Mozilla Firefox 1.5 or newer.
02.02.2011.
Multiple Mozilla Firefox 1.0 caveats with the modern Internet:
  • Firefox 1.0 is so outdated that only "Basic", "Classic" and "Lite" versions of various popular services work. Remember to place these services' old versions' addresses in the Bookmarks menu or toolbar.
  • Windows Live sign-in doesn't work at all.
  • Nowadays' popular Websites use scripts and AJAX so intensively that NoScript is invaluable in suppressing unnecessary scripts that may hog system resources (also applies to Firefox 2 and SeaMonkey 1.x).
Windows 95 Firefox 1.5–1.5.0.3: NoScript 1.5.2 (XPI)
Firefox 1.5.0.4:NoScript 1.8.1.3
Firefox 1.5–NoScript 1.10SeaMonkey 1.1.17
–1.1.19
Windows 98/MeFirefox 2.0.0.20
28.01.2016.
Windows 2000Firefox 12.0NoScript 2.9.0.1rc1SeaMonkey 2.9.1
NoScript versions page

I know I haven't posted much about Flashblock, but it can be had from flashblock.mozdev.org

The legacy options presented in this post pertain to situations where it's impossible to upgrade to SeaMonkey 1.1.19, such as an out of date Live CD (and what if someone has only that?).

Yet when it comes to a Windows 9x operating system, then it's best to install or upgrade to SeaMonkey 1.1.19. Reasons for this in one of my previous posts.

Monday, December 6, 2010

Best Gecko-based browser for Windows 9x

The latest and last versions of Gecko-based browsers to run on Vanilla Windows 98/Me (and 95, with updates and other reservations) are
  • Mozilla Firefox 2.0.0.20 (Gecko 1.8.1.20, 20081217),
  • K-Meleon 1.5.4 (Gecko 1.8.1.24pre, released on 05.03.2010) and
  • SeaMonkey 1.1.19 (Gecko 1.8.1.24, released on 16.03.2010).
If there were a competition between the three, then the winner would be SeaMonkey.

The reasons are thus:
  • Under similar limited circumstances, SeaMonkey 1.1 is more responsive than Mozilla Firefox  2.
    Here's why: SeaMonkey 1.1's XPFE/XPToolkit-based user interface (UI) technology dates back to Mozilla Application Suite (v1.0 released 05.06.2002, but pre-releases were usable since a year before), while Mozilla Firefox 2.0 (2006) is completely based on a newer toolkit (XUL).
  • SeaMonkey 1.1.19 has a newer and more secure Gecko layout engine than Mozilla Firefox 2.0.0.20 and K-Meleon.
  • SeaMonkey 1.1 has been supported by the two most important extensions to grace web surfing: Flashblock and NoScript.
    K-Meleon also uses the native Windows API for its UI, meaning that it can't run extensions which normally work in SeaMonkey or Mozilla Firefox.

    While K-Meleon comes close with its quick UI responsiveness and its rendering engine, it's only good for websites that are safe and are known to not be resource-intensive. Most of the latter still exist as they are, but the most popular sites (for webmail and news) are regularly redesigned to include more fancy features and are therefore made more demanding by way of including extensive JavaScript and AJAX technologies and often embedding multiple manifestations of the Adobe Flash plugin.
Which is why SeaMonkey 1.1.19 adorned with NoScript and Flashblock extensions is about the best Gecko-based browser solution that there is for Windows 9x, even Windows 95.

The only caveat is that SeaMonkey requires at least 64 Mb of RAM to run passably and at least a 266 MHz CPU. Well, a Navigator-only one-window/one-or-two-tab solution works in a PC with just a slightly lesser CPU.

K-Meleon is best for computers with 32–48 Mb of RAM (certainly less than 64 Mb).
Some words of caution: Java and JavaScript could only be allowed for safe and non-demanding websites. Because of a lack of NoScript or like extension for K-Meleon, JavaScript should be turned off for casual browsing (sometimes even a Google Search result may cause a hiccup). Keeping Java on is only recommended when a user consciously recognizes a real and pressing need to use that plugin (maybe a map application over the web).

On Plugins

Although Adobe Acrobat Reader 6.0.6 (released/updated last in 2003) is about the last version for Windows 98 as far as I know, it is still outdated and so more vulnerable to attacks that use the Reader.

While older computers might best handle even older versions of Acrobat Reader, it's most important to disable Acrobat (Java)Script in the Reader's preferences, no matter the version. This should somehow prevent malicious websites using the Reader as an attack vector.

A complete alternative to using Adobe Reader in old computers is muPDF: It's much less resource intensive, supports the newest PDF document display standard (PDF 1.7) and does not use AcroScript. muPDF does not support interactive PDF elements; this is both a caveat and a security/speed measure. muPDF does capture the file type association in Windows, so when using the app, then it's an either-or situation between it and Acrobat Reader. It should still be a no-brainer in old computers.

Wednesday, August 18, 2010

Recap on SeaMonkey 1.1 > 2.0 migration: Add-on caveats

Themes

Even if a profile is migrated, SeaMonkey 2.0 will default to its default theme. If you used a Modern theme (built-in), then you'll have to choose it from the Add-on Manager and restart SeaMonkey. The selection and amount of themes for SeaMonkey 2.0 is different than for SeaMonkey 1.x.

Extensions (this is the difficult part)

  • Extensions must be installed anew.

  • The whitelist of servers where extensions and themes can be installed from might not be migrated.

  • Globally installing an extension requires administrative rights.

    Unlike with Mozilla Firefox, whereby globally installing an extension installs it into every private user profile for all users of an operating system (so that there are multiple copies around of the same extension), doing this for SeaMonkey actually installs the extension into SeaMonkey's extensions folder that resides in the program's install directory.

    The pitfall is that a limited Windows xp user would then be unable to update a required extension for compatibility. I had that with two spelling dictionaries.

    The quick-and-dirty solution in my case was to temporarily set the user as administrator, update the extension for compatibility and then remove the user's administrator credentials. Bah.

    While global extension installation could potentially be very convenient in terms of getting to install only one extension at once for all profiles (=different SeaMonkey users), it does introduce a number of security and other considerations:

    1. One is that, for example, in Windows xp, SeaMonkey is installed into the Program Files folder, where limited users have limited rights, which means that they cannot update the extension, even for compatibility (can't modify folder contents).

    2. If SeaMonkey were installed into a public directory — such as
      C:\Documents and Settings\All Users\Documents — then the whole suite would be left vulnerable to tampering either by its users or a malicious program (both would have to have awareness of the program's different location).

    3. Change user access rights for relevant extensions' folders where they are in
      Program Files\SeaMonkey\extensions.

      A few words of caution: I have not tried this myself, but some of the user support forum topics related to SeaMonkey have suggested that limited users should be given rights to the whole SeaMonkey install directory, so that they would be able to update their extensions. I do not recommend giving rights to the whole program directory, but giving rights to limited users for only the extensions directories.

      While this would make SeaMonkey reasonably tamper-proof, the extensions would be the few to remain vulnerable to tampering.


      To easily see which add-on is installed into which folder, install the MR Tech Toolkit extension. It extends the Add-on Manager with lots of useful tools, but the function you need is "Browse install directory" when right-clicking an extension.

      Once the Windows Explorer folder for the extension is open, click on the folder whitespace, and on the Properties command. This should open the Properties window for the current folder. There, in the Security tab, click on Users from the Group or User names list and click on the Modify checkbox in the "Allow" column. Click the Apply button, but don't leave the window yet. Click the Advanced button and in the "Advanced Security Settings for extensionfoldername" list, verify that the set permissions for separate user(s) or a group of users apply to "This folder, subfolders and files".

      This action thus leaves SeaMonkey more-or-less tamper-proof, but may leave directories of specific extensions vulnerable to tampering.

    4. Best to install extensions separately into every profile? What if there are more than five users and what if a few of those users have more than one SeaMonkey profile?

  • I had trouble installing Flashblock from addons.mozilla.org, so I had to add flashblock.mozdev.org to the whitelist and install from there. No trouble installing NoScript from addons.mozilla.org.

  • As it usually is with SeaMonkey browsers, the Flashblock toolbar button will not show automatically. Instead of opening the Preferences window, click on any free space in the SeaMonkey toolbar, then on Customize... A Firefox-like toolbar customization dialog should show up and the Flashblock toolbar item can be added wherever a user chooses in the toolbar (the standard location was next to the Home button in the Personal Toolbar). Because the computer where I installed SeaMonkey 2.0 does not have a printer, I dragged the printer button off the toolbar.

  • Server whitelists for Flashblock and NoScript do not migrate automatically. I had to manually type in server names into the new Flashblock whitelist, but I think its file can be migrated (haven't checked how to do it). NoScript allows exporting the whitelist, so I did that from SeaMonkey 1.1 and imported the whitelist in SeaMonkey 2.0 after installing NoScript.

It has always been the developers' intention for Mozilla (later SeaMonkey, which became Mozilla's successor; and a branched-off Mozilla Firefox) to have global and per-user extensions.

Mozilla 1.0 finally came out on 05.06.2002. Seeing what Mozilla 1.0's (minimum) system requirements were (modest by nowadays' standards) can give a helpful glimpse into what kind of hardware and software people were using at that time.

This was an era when single-user operating systems in computers were still a norm: four years after the release of Windows 98 and two years after Windows Me was released. Hard disk capacity then (2001–2002) — well, roughly ten years back — was about 10% of what it is now (2010) and there wasn't any lack of people who used much older computers. It's duly possible that hard disk capacity was seen as a premium back then, because after Mozilla 1.0 was released, it was criticized for its bloat.

Mozilla 1.0's full installer for Windows was 9.8 Mb, releases for Linux were between 11.6–13.9 Mb, and release sizes for exotic operating systems ranged between 16–26 Mb. The size of the Windows installer was actually normal, because the installers for Netscape Communicator 4.x and Internet Explorer 5 weren't all that much more smaller, as both included bundled software.

I guess the bloat factor was two-pronged:

Those who lived through those times, can remember how Internet Explorer reigned supreme.

Actual software bloat

IE users eager to try out something new would probably perform a 'normal' install of Mozilla (or Netscape 6.X) and only thereafter discover that Mozilla wasn't only a browser, but an application suite with an extensive feature set, while Internet Explorer was duly perceived as a stand-alone program. And that the typical installs of Netscape 6.X would also bundle a number of other tag-along apps, like RealPlayer and AOL Instant Messenger.

In all actual fact, Outlook Express, Windows Media Player, Microsoft NetMeeting and various other bits were just as well bundled with large ('Normal'/'Typical') Internet Explorer installations, only that Internet Explorer was marketed by Microsoft as an inalienable part of the Windows operating system; other said programs were bundled as parts of Windows 95OSR2.x, Windows 98/Me and newer. Yet people launching Internet Explorer both on Windows and Mac knew and saw that they were only launching a browser and not a whole suite of applications (e-mail, newsgroups, chat/IM) they probably didn't have any need for.

Slow user interface responsiveness

Much of Mozilla's user-facing behaviour was based on Netscape Communicator 4.x, but its cross-platform user interface toolkit was completely new.

Netscape 6.X and newer were subsequently based on Mozilla's underlying code base. People used to Internet Explorer or even Netscape 4.x found Mozilla 1.0 as not particularly responsive compared to IE and Netscape 4.x and I know I can attest to that when seeing SeaMonkey 1.1.xx work on older hardware.

In terms of system resource usage, Mozilla 1.0 would run more-or-less properly on the kind of metal specified in its system requirements. Nevertheless, the new cross-platform user interface toolkit (intended to ease development, which I believe it did) was not native to any existing operating system and thus imposed a performance penalty on any hardware that wasn't top-of-the line. Hence the talk of bloat.

All this gave plenty of impetus for Mozilla developers to create a separate browser which eventually came to be Mozilla Firefox. And lo and behold, Mozilla Firefox 1.0 ran well and faster on even older hardware (CPU considerations aside).

To continue soon?


What is so great about SeaMonkey, is that the underlying technology didn't change much throughout the great ten years between Mozilla 1.0 and SeaMonkey 1.1.19, which really is proof of the package's superiour design considerations.

Friday, August 13, 2010

SeaMonkey 2.0 periodic slowdowns

After I migrated a Windows XP computer from SeaMonkey 1.1.19 to SeaMonkey 2.0.6, it turned out that the program experienced short, yet periodic slowdowns which were also evident in Process Explorer with CPU spikes that were related to the process.

The particular profile of SeaMonkey has the following extensions:
Flashblock 1.3.16, NoScript 2.0.1 and three spelling dictionaries.

As I surfed around to look for any kind of resolution, I stumbled upon the two most relevant forum threads, one in MozillaZine and the other on NoScript.

The best hint was given in this InformAction posting, where the workaround is to disable ABE (Application Boundaries Enforcer), which also disabled the holdups, but I hope for a better solution without sacrificing some on security.

Where to disable ABE:
NoScript Options > Advanced tab > ABE subtab > Remove checkbox at "Enable ABE (Application Boundaries Enforcer)"