Pale Moon team disables NoScript by default, faces backlash, blocks discussion


Recommended Posts

Within the past couple days the Pale Moon team have flagged the popular script-block extension NoScript as being "known to cause stability or security problems."

 

Related Pale Moon forum topics include this and this.

 

Many users are upset at the decision, that the default setting is to disable it (which is extremely dangerous, as any malicious scripts on open tabs.. originally opened under the assumption NoScript would be running...  would run), and by the rudeness and "arrogance" of the admins.

 

Posts from the team indicate that they don't like spending time supporting issues that were ultimately caused by scripts being disabled. They also claim that NoScript can cause issues with some sites even if the extension is completely disabled in the browser options. However, despite repeated requests for more information/examples of the latter, they have yet to provide any. Instead, admins have threatened users that even discussing the subject will not be allowed.

 

Personally, I've never once encountered the claimed issues with NoScript in all my years of running it. But more importantly, it's hard to believe that developers who treat users so poorly on their forum wouldn't continue to do so behind the scenes as they develop the software and security/privacy policies related to it. I don't think I'll be recommending Pale Moon to anyone going forward.

The original Mozilla phrasing for a "softblocked" item at level 1 severity has been revised to better reflect how we are using the blocklist and to soften the obviously paranoid string. It will now simply read "X is known to cause issues". Expect to see the revised string in the next version of the software.

 

Also, do note that level 1 severity will not prevent your use of the extension. It is meant only as a warning that.. It is known to cause issues.

Reading through the thread it doesn't seem like the devs are being particularly rude or arrogant. I absolutely sympathize with them about getting false bug reports from users that don't understand what they're doing with NoScript, even as a web dev the amount of "bug reports" I've had in the past from people who have misconfigured their browsers is frustrating. It's not like they're silently disabling it without notifying you, it shows a box and you only have to untick a single checkbox one-time to keep it enabled forever. If you're not happy with the way an open source project is being run you're more than welcome to fork it.

 

One thing does concern me though...

Quote

Switching NoScript to "allow all", disabling NoScript in the add-on manager, or any other attempt at fixing these issues without performing a full uninstall of the extension are, on top, usually met with failure.

Why is the browser allowing an add-on that has been disabled in the add-on manager to in any way influence anything? Surely that's a security issue in itself.

Edited by ZakO
On 5/11/2018 at 9:53 PM, ShadeOfBlue said:

Within the past couple days the Pale Moon team have flagged the popular script-block extension NoScript as being "known to cause stability or security problems."

 

Related Pale Moon forum topics include this and this.

 

Many users are upset at the decision, that the default setting is to disable it (which is extremely dangerous, as any malicious scripts on open tabs.. originally opened under the assumption NoScript would be running...  would run), and by the rudeness and "arrogance" of the admins.

 

Posts from the team indicate that they don't like spending time supporting issues that were ultimately caused by scripts being disabled. They also claim that NoScript can cause issues with some sites even if the extension is completely disabled in the browser options. However, despite repeated requests for more information/examples of the latter, they have yet to provide any. Instead, admins have threatened users that even discussing the subject will not be allowed.

 

Personally, I've never once encountered the claimed issues with NoScript in all my years of running it. But more importantly, it's hard to believe that developers who treat users so poorly on their forum wouldn't continue to do so behind the scenes as they develop the software and security/privacy policies related to it. I don't think I'll be recommending Pale Moon to anyone going forward.

I haven't used no script in years. Sometimes it is about just paying attention to what you click on.

On 5/15/2018 at 5:02 AM, Matt A. Tobin of BinOC said:

The original Mozilla phrasing for a "softblocked" item at level 1 severity has been revised to better reflect how we are using the blocklist and to soften the obviously paranoid string. It will now simply read "X is known to cause issues". Expect to see the revised string in the next version of the software. 

 

Also, do note that level 1 severity will not prevent your use of the extension. It is meant only as a warning that.. It is known to cause issues.

From the release notes:  "We changed the language strings for softblocked items so people will cry less when we do our job."

 

Well, the tone certainly does match the juvenile one in the forum, so at least it's consistent. But the reason given in the quote has nothing to do with the recognition that it was an "obviously paranoid string". The official Pale Moon team position appears to be that there was nothing wrong with the original text and that anyone who thinks so is, well.. worth insulting. Again.

 

For an extension that supposedly causes problems on "a large (and growing) number of websites", you'd think the devs could offer up more details to the people asking questions. Instead, it's all personal attacks. How is anyone supposed to gauge whether they should disable it, if the devs refuse to explain any particulars of the problem?

 

And this whole thing about not supporting the browser if NoScript is installed is just so farcical. What does that even mean? Let's think this through...

 

If it were still supported, a reasonable person would first provide a link to instructions that request the user to perform some simple tasks (e.g. clear cookies and cache, remove newly-installed extensions, remove NoScript or other similar invasive extensions, change certain settings to defaults, etc.), and then tell them to report back if the problem persists. But, now that it's not supported, the users are going to be turned away until they.. umm.. do the exact same thing. So please do explain how this changes the support situation one iota. Because it shouldn't. Not unless support is being done in a haphazard manner in the first place.

 

And yes, everyone knows you can untick the box. That's irrelevant. The problem is both the wording of the warning (supposedly now changed), as well as the initial state of the checkbox. In adware-esque fashion, the box is checked by default, in hopes that most people will leave it checked whether they truly wanted to or not. That's the power of defaults. Specifically, this is a massive security issue for existing installs. One slip of the enter key or a mouse button on that window and scripts will run in open tabs after a browser restart.... tabs that were opened under the assumption NoScript was running. I cannot stress enough how bad this is.

 

I can understand people making mistakes. But good devs fix problems once they are made aware of them. And then there's the Pale Moon team... who are completely irresponsible and unprofessional, I don't know if there's some bad blood between the Pale Moon devs and the NoScript dev, or what the problem is. But nothing makes sense here. And devs who are this clueless about security issues either need to clean their act up, or maybe think about not being devs.

 

On 5/15/2018 at 5:54 AM, ZakO said:

Reading through the thread it doesn't seem like the devs are being particularly rude or arrogant. I absolutely sympathize with them about getting false bug reports from users that don't understand what they're doing with NoScript, even as a web dev the amount of "bug reports" I've had in the past from people who have misconfigured their browsers is frustrating. It's not like they're silently disabling it without notifying you, it shows a box and you only have to untick a single checkbox one-time to keep it enabled forever. [...]

We must have very different definitions of rude and arrogant. Or perhaps you read a different thread. The devs have repeatedly insulted people (now even in the official release notes.. which just boggles my mind) instead of answering simple questions/suggestions, as well as refusing to allow users to even dare discuss the issue amongst themselves (which they have, in the days since, graciously allowed in the single unlocked and undeleted thread that remains).

 

Imagine if a site prompted users with a box that space was running out for new photos, below that it had a box checked next to "Delete all photos", and the "Accept" button had the focus. That is terrible design (how terrible depends on how good your legal team is I suppose). Defaults should never be destructive or dangerous. My example involves user data. The real issue involves security (and user data as well). But, the rule is the same in all cases.

 

And, being personally familiar with writing and supporting software, it's even worse than what you say. Outside of major new bugs, the vast majority of all reports are user error. That's why you are supposed to consider that when providing support (as I detailed above). This excuse does not hold water in the slightest.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Save up to 87% on ChatPlayground AI lifetime subscriptions by Steven Parker Today's highlighted deal comes via our Apps + Software section of the Neowin Deals store, where for only a limited time, you can save up to 87% on ChatPlayground AI: lifetime subscriptions. ChatPlayground AI puts the world’s top AI models in one powerful interface, letting you enter a single prompt and instantly compare outputs from multiple models to choose the perfect response for your needs. Boost productivity and creativity with access to the latest AI giants like GPT-4o, Claude Sonnet 4, Gemini 1.5 Flash, DeepSeek V3, and dozens more — all in one window. Whether you’re chatting, coding, generating images, or refining prompts, ChatPlayground AI equips you with advanced tools like prompt engineering, image/PDF chat, saved conversations, and AI image creation, plus priority support to keep your workflow seamless. Access the world’s best AI models Side-by-Side Comparisons: Enter one prompt & instantly view results from multiple AI models to find the best output for your needs 40+ AI Models: Includes GPT-4o, Claude Sonnet 4, Gemini 1.5 Flash, DeepSeek V3, Llama, Perplexity, and many more Multi-Function Platform: Access AI for chat, image generation & coding all within a single interface Web Browser Extension: Offers a Chrome extension to seamlessly integrate the platform into your browsing workflow Boost productivity with powerful features ChatPlayground Interface: Designed for seamless AI model comparison in one window Prompt Engineering: Refine & optimize your prompts for better, more accurate responses Chat with Images & PDFs: Upload visuals and documents to get context-aware answers Saved Chat History: Keep track of past conversations for reference & ongoing projects AI Image Generation: Create high-quality visuals powered by top AI image models Priority Customer Support: Get faster assistance whenever you need it What you'll get with the Unlimited Plan Includes unlimited messages/month Built for prompt engineers, startups, and teams who run experiments nonstop Includes priority access to new features and future models Good to know Length of access: lifetime Redemption deadline: redeem your code within 30 days of purchase Access options: Desktop Max number of device(s): Unlimited Available to both NEW & Existing users Updates included A lifetime subscription to ChatPlayground AI (Unlimited Plan) normally costs $619, but you can pick it up for just $79 for a limited time - that represents a saving of $530 (87% off). Click the link below for more details, always check terms and specifications before making a purchase. Get this ChatPlayground AI (Unlimited) for $79 (was $619) There are also two other discounted plans to choose from. Although priced in U.S. dollars, this deal is available for digital purchase worldwide. Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
    • I like Tidal, but it still does not control devices from the mobile/app and still no surround support. And yeah re: above comment I still get a lot of network errors and I am on a 4/4 Gbit Fiber connection.
    • Aren`t "security features" and "AI model that can see your screen" a tad diametric!
    • Samsung, Amazon extend 990 PRO 2TB NVMe SSD deal beyond Prime Day 2026 by Sayan Sen Recently, we had Amazon's Prime Day 2026 sales wherein there were several great deals including on SSDs. One of those discounted components was the Samsung 990 PRO SSD as the 2TB variant of it was selling for $370, a very good price after a long time. Although that deal was supposed to expire today, Amazon has now extended that sale further (purchase link under the specs table down below). The 990 PRO is a PCIe Gen4 NVMe SSD and still one of the fastest drives available today for under $400. Speaking of fast, sequential reads and writes are rated at 7450 MB/s and 6900 MB/s, respectively. The random throughputs for reads and writes are 1400K IOPS and 1550K IOPS, respectively. The 990 PRO is based on Samsung's 7th Gen V-NAND flash, and it too is TLC. It packs 2 gigs of LPDDR4 DRAM cache, which helps the random performance. The endurance rating for this is 1200 TBW (terabytes written), which should be sufficient for most users. The Samsung 990 PRO is compatible with the PlayStation 5, but if you are going to use the 990 PRO on a PC, check out the Samsung Magician app that lets you track your drive's health, update its firmware, customize various settings, and more. The technical specs of the Samsung 990 PRO 2TB are given in the table below: Specification Value Form Factor M.2 2280 Interface PCIe Gen 4.0 x4, NVMe 2.0 NAND Flash Samsung V-NAND TLC Controller Samsung In-house Controller Cache Memory Samsung 2GB Low Power DDR4 SDRAM Sequential Read Speed Up to 7,450 MB/s Sequential Write Speed Up to 6,900 MB/s Random Read (4KB, QD32) Up to 1,400,000 IOPS Random Write (4KB, QD32) Up to 1,550,000 IOPS Random Read (4KB, QD1) Up to 22,000 IOPS Random Write (4KB, QD1) Up to 80,000 IOPS Operating Temperature 0°C to 70°C Reliability (MTBF) 1.5 Million Hours Endurance 1,200 TBW (Total Bytes Written) Get it at the link below: Samsung 990 PRO SSD 2TB NVMe SSD (MZ-V9P2T0B/AM): $369.99 (Sold and Shipped by Amazon US) Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases
  • Recent Achievements

    • Reacting Well
      NovaEdgeX earned a badge
      Reacting Well
    • Week One Done
      NovaEdgeX earned a badge
      Week One Done
    • One Year In
      BA the Curmudgeon earned a badge
      One Year In
    • Conversation Starter
      rosiecharles earned a badge
      Conversation Starter
    • First Post
      KMilenkoski1202 earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      543
    2. 2
      +Edouard
      271
    3. 3
      PsYcHoKiLLa
      153
    4. 4
      Steven P.
      99
    5. 5
      macoman
      66
  • Tell a friend

    Love Neowin? Tell a friend!