4 ms·
So much for CORS policies. If browsers restricted cross-origin sharing of image resources to same domain only, bazillions of dollars in tracking pixel revenue
by gurneyHaleck 10y ago
So much for CORS policies.
If browsers restricted cross-origin sharing of image resources to same domain only, bazillions of dollars in tracking pixel revenue would evaporate.
Deep inspection of image rasters by script execution isn't going to get locked down anytime soon, I surmise.
- vortico 10y agoActually this is a good idea. Is there a way to make Firefox behave like this? I'm interested how broken the web would become, or if it would actually make the web faster and more usable by only loading content relevant to the website.
- shakna 10y agoMy guess would be a lot, with s3 providing so much of static content, or via 3rd party CDNs.
- mtgx 10y agoMore or less than if browsers had blocked Flash say 3 years ago? Because I think that's the standard. If they can do it for Flash, then they can do it for anything else, too. They just need to set a deadline with a reasonable amount of time before it's reached so that all developers can adhere to the new specs. I really hate the attitude of "well, too many websites/apps would be broken so I guess we'll never do it, or we'll just wait for the web to collapse first so that everyone agrees we should do it" from "platform" (in this case browser) vendors. If it's that bad, then just set a 2 year, 3 year, or even 5 year deadline for the change (perhaps with some intermediary progressive blocking, like it's happening for Flash). It pisses me off because it seems the same is happening with ASLR on Linux [1]. We've had it for 15 years, but nobody is willing to force developers to use it "because it would break things". Screw that. Set a deadline and do it already. If their apps can't make such a change in 3 years, then I could care less that their apps will stop working. Critical vulnerabilities that allow dangerous exploits to happen also "break a lot of things", and not just themselves either, but the firefighting patches that come after them, too. [1] https://lwn.net/SubscriberLink/708196/845f9287f1936dcf/ https://lwn.net/SubscriberLink/708196/845f9287f1936dcf/
- shakna 10y agoI have no problems breaking the existing web for a more secure web tomorrow. None whatsoever. I've been highly irritated by people freaking out that Flash is started to get blocked - despite it being deprecated in those browsers for years. It wasn't exactly a surprise. But I guess that's the crap that hits us. No one will make a damned change till they're forced to do it right now. I'm somewhat sick of advertising networks serving malware. JavaScript is Turing Complete, and leaky as hell. There is no safe way to use it for ads, so don't let you clients use it! The modern web relying on huge megabytes worth of data has led to us needing CDNs and other 3rd party providers. Anytime a websites uses a 3rd party provider, it opens a hole in itself, and with the insane complexity of a modern browser... That's just asking for trouble. But asking Google to give up the practices they use to forward their own agendas, like advertising, and their walled garden of AMP, won't happen. Chrome has the usage that it can exhibit considerable force on the other browsers, and the reverse isn't true. EDIT: In other words, I completely agree with you, but cry when I see that state of things. Just want that to be clear.
- calgoo 10y agoI have been using uMatrix in both FF and Chrome for this purpose. Works great once you have some basic rules saved. There are so many web pages that break because they are loading their content from 4 or 5 different sources (not counting ad networks).
- TekMol 10y agoJS cannot read the pixels of images loaded from other domains. It's surprising and annoying for many legit use cases. But it can't.
- mnw21cam 10y agoI don't have a problem with cross-origin sharing of things like images, and I believe blocking these would break a lot of web pages. However, I would quite like cross-origin blocking of things like flash and scripts. After all, that flash program that kicked the whole thing off probably wasn't loaded from the host web site. That seems much more sensible and low-impact to me. It also has a side-benefit of forcing ad networks to fall back to static images, which has to be a good thing.
- jdavis703 10y agoMost ads are served in iframes, which get their own origin independent of the parent window. Unless you want to block cross origin frames, then this is still a problem.