The most important security add-on to firefox if you want to lock down the browser is NoScript. Not only does it have built-in XSS protection, but it will also sanitize Flash, Java, /and/ Javascript on a per-domain basis. That's much more secure than trying to live without javascript on all sites (which will just drive you to enable it dozens of times a day to use sites that require it).
http://noscript.net/
Discussion on:
Message 2 of 1
The best of ZDNet, delivered
ZDNet Newsletters
Get the best of ZDNet delivered straight to your inbox



