<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security on Apuntes de root</title>
    <link>https://blog.099c.org/categories/security/</link>
    <description>Recent content in Security on Apuntes de root</description>
    <generator>Hugo</generator>
    <language>en-US</language>
    <managingEditor>jorti@pm.me (Juan Orti Alcaine)</managingEditor>
    <webMaster>jorti@pm.me (Juan Orti Alcaine)</webMaster>
    <lastBuildDate>Wed, 19 Aug 2020 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://blog.099c.org/categories/security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Block non-https scripts with uBlock Origin</title>
      <link>https://blog.099c.org/posts/block-non-https-scripts-with-ublock-origin/</link>
      <pubDate>Wed, 19 Aug 2020 00:00:00 +0000</pubDate><author>jorti@pm.me (Juan Orti Alcaine)</author>
      <guid>https://blog.099c.org/posts/block-non-https-scripts-with-ublock-origin/</guid>
      <description>&lt;p&gt;Inspired in the default NoScript setup of the Tor Browser, I&amp;rsquo;ve added this rule to my list of static filters in uBlock Origin to block any script or other objects served by http. Some pages load 3rd party scripts over a http connection, posing a risk of a man-in-the-middle attack.&lt;/p&gt;&#xA;&lt;p&gt;I&amp;rsquo;ve explicitly excluded the .onion domain as the communication with a hidden service is always encrypted.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;|http:$script,inline-script,subdocument,object,font,inline-font,domain=~onion&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;To see the list of objects available to filter, you can consult the uBlock Origin wiki and the Adblock Plus documentation:&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
