Do I need to disable "javascript.enabled"? : OpSec | Torhoo darknet markets
Do I have to disable javascript.enabled in about:config or is it enough to set security level to "safest"? Some say you should do it but I wonder why. Because safest mode says that it disables javascript already.
Safest security level disables javascript, but you can selectively enable it using the NoScript extension.
If you disable it from about:config, you can't enable it using any extensions.
A zero-trust way would be to use about:config, as letting extensions manage javascript could be problematic based on your threat level.
To be sure:
javascript.enabled = false
webgl.disabled = true
webgl.disable-wgl = true
Then re-start the browser.