How to Configure NoScript Settings in Tor Browser
Tor Browser comes with the NoScript extension pre-installed to protect your privacy and anonymity by blocking potentially malicious JavaScript, Flash, and other executable content. This guide explains how to manage NoScript effectively, both by utilizing Tor Browser’s built-in security levels and by accessing advanced, site-specific permissions directly within the NoScript interface.
Method 1: Using Tor Browser Security Levels (Recommended)
Tor Browser manages NoScript rules automatically through its unified security slider. Adjusting this setting is the safest way to configure script blocking without creating a unique browser fingerprint.
- Open Tor Browser.
- Click the Shield icon located to the right of the address bar.
- Select Settings (or Change… depending on your version) to open the Security Level settings.
- Choose from the three available levels:
- Standard: All browser and website features are enabled by default. JavaScript runs normally.
- Safer: Disables JavaScript on non-HTTPS sites and turns off some fonts and math symbols. HTML5 media must be clicked to play.
- Safest: Disables JavaScript entirely on all sites by default. Media and fonts are heavily restricted.
Method 2: Accessing the NoScript Toolbar Button
To manually control permissions on a per-site or per-script basis, you must make the NoScript interface visible in the browser toolbar.
- Click the Extensions puzzle piece icon on the top-right toolbar.
- Locate NoScript in the list.
- Click the Pin to Toolbar (or gear icon) next to NoScript so the blue “S” icon stays visible on your main navigation bar.
Method 3: Customizing Per-Site Permissions
Once the NoScript icon is visible, you can configure granular permissions for any active webpage.
- Navigate to the website you want to configure.
- Click the NoScript icon in the toolbar to display the permissions menu.
- You will see a list of domains attempting to run scripts on the
current page. Click the icon next to any domain to change its status:
- Default: Inherits the global baseline rule.
- Trusted (Green): Allows all active content and scripts for that specific domain.
- Untrusted (Red): Permanently blocks all active content from that domain.
- Custom (Gear icon): Lets you individually toggle
specific elements, such as
script,object,media,frame,font,webgl, andfetch.
- Use the Temporarily Allow option (represented by an icon with a clock or outline) to grant permissions that expire automatically when you close the browser.
Method 4: Configuring Global NoScript Options
For advanced global settings that apply across all sessions:
- Click the NoScript icon on the toolbar.
- Click the Gear/Options icon in the top-right corner of the NoScript drop-down window.
- Under the General tab, you can define the default permissions for the Default, Trusted, and Untrusted categories.
- Under the Per-site Permissions tab, you can search, add, or remove domains from your permanent whitelist or blacklist.
- Under the Advanced tab, you can adjust protections against Cross-Site Scripting (XSS) and DNS rebinding attacks.
Important Security Considerations
- Fingerprinting Risk: Modifying advanced NoScript settings manually can make your browser configuration unique, potentially making it easier for third parties to track you across different websites.
- Temporary Permissions: If a site breaks and requires JavaScript to function, prefer using Temporarily Allow rather than permanently whitelisting the domain.
- Third-Party Scripts: Avoid trusting third-party tracking or advertising domains listed in the NoScript menu; only enable the primary domain necessary for site functionality.