Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I tried uBlock origin and I didn't find any advantages over adblock plus besides not having to disable an option to block most ads... but either way, noscript is still necessary


no. noscript is not necessary. ublock can block every javascript until I allow it for a website. I had 3 addons before I started using uBlock: noscript, ABP and request-policy. uBlock replaced them all and is much better. It has a nice clear interface and gives an even biiger amount of control.


How do you get it to block JS by default? I wasn't aware of that option, and I don't see it in the settings. Do you use a custom rule for that?


Turn on the dynamic filtering and set the appropriate global rules:

https://github.com/gorhill/uBlock/wiki/Advanced-user-feature...

https://github.com/gorhill/uBlock/wiki/Dynamic-filtering:-qu...

(I'd be more specific if I was using the dynamic filtering and understood it more clearly)


yes. I enabled "Im an experienced user" option. Then one can see a matrix with two columns in the uBlock menu. Left one is global. I set everything (including javascript) to red (disabled) in the global column. When visiting specific sites I can allow some resources (like javascript) locally (only for that domain) in the right column.


Maybe she meant uMatrix.


that would only make the Application Boundaries Enforcer and ClearClick (anti-clickjacking) missing from uBlock origin, if you don't install noscript [1]

[1] https://github.com/chrisaljoudi/uBlock/issues/1323


I have a question about NoScript. I run Ghostery which blocks all tracking and analytics js files, preventing most of the tracking I'd like to avoid. What does NoScript offer here? Seems like you'd want to block analytics even if you're browsing a "trusted" site.


First of all ghostery is far more beholden to advertisers than ABP. On that basis alone they can't be trusted. It also only screens for known vulnerabilities which leaves you open to js zero days that noscript would have prevented if you are aggressive about what you permit to run.


No disagreement on Ghostery; that got uninstalled real fast when I figured out what they were really up to. While I agree that NoScript helps, it doesn't prevent everything either: https://thehackerblog.com/the-noscript-misnomer-why-should-i...

I used to be a big RequestPolicy believer, but single-page apps (which feels like saying "horseless carriages" in mid-2015) make it a lot of work. https://github.com/gorhill/uMatrix/wiki/Changes-from-HTTP-Sw... is the best thing I've found if you're into granular control over sites. uBlock also has an ~"I'm an advanced user" option which will give you a little more blunt but still useful control over cross-site requests.


> While I agree that NoScript helps, it doesn't prevent everything either: https://thehackerblog.com/the-noscript-misnomer-why-should-i....

This is just a default whitelist that's trivial to remove. Yes, it's dumb, but it doesn't completely compromise NoScript if you're aware of the whitelist.


I think you're expecting it to solve a problem it's not intended to solve.

I'm not expecting it to block all javascript, or all malicious javascript. I'm just expecting it to block most or all of the annoying stuff on the web.

To the extent that this is the job it's being hired for, you don't really need to 'trust' it. You run it and it either does what you want or it doesn't. Personally it suits my needs perfectly.


uBlock Origin is noticably faster, especially on mobile. It also has many more configuration options.





Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: