4 ms·
All these security headers seem like a terrible idea to me, shouldn't security be the default - especially if it breaks insecure websites?
by daxterspeed 8y ago
All these security headers seem like a terrible idea to me, shouldn't security be the default - especially if it breaks insecure websites?
- pixl97 8y agoGood idea, let's break 90% of the internet and see why nobody uses your secure by default browser. You're not wrong, but what you want doesn't work for human reasons.
- Millennium 8y agoThis is true most of the time, but if it's necessary to keep the ads flowing, I think most ad-supported sites will update very quickly.
- daxterspeed 8y agoI understand your sentiment but I do wonder what the extent would actually be. The largest website are more than capable of adapting, and older sites are more likely to either not use any JavaScript or only accept http traffic (which is already a lost cause). I suppose the ones would take the biggest hit would be the people running WordPress blogs with various (already insecure) site plugins. Suppose if these security changes would slowly get imposed over all https traffic in a coordinated fashion among the major browser vendors over a large time span? https requires some periodic maintenance anyway, so it shouldn't add an unreasonable workload. I worry that this isn't happening because the ad industry (including Google) doesn't want to take responsibility over distributing untrustworthy and insecure code.
- move-on-by 8y agoThink of these headers not so much as security. Just because a site doesn't have this or other headers doesn't make it any less secure. The headers are better described as fine-tuned access-control policies. You want to be able to send your users notifications on your site? Well great, now any ads on your site have the same ability. These headers allow you to control that. The primary site has features x,y, and z - but any ads or iframes don't have any features. > distributing untrustworthy and insecure code. So this isn't really how things are, we didn't have the ability to fine-tune these access control features before. Either you accepted a website as a whole to give you notifications or not. On the client side it still appears the same, but on the server side they can limit which scripts/domains actually get those permissions.
- vorpalhex 8y agoI suspect this is to help websites crack down on crappy ad networks without actually having to moderate their ads?
- michaelt 8y agoSome would say the fact websites are unable to control what they serve is why ad blockers are so popular.
- mcintyre1994 8y agoWon't they just add "allow=all,the,crap,they,want" in the embed iframe code they ask site owners to copy/paste? I'm sure there's a reason for the design (allowing deny all at the top and then only allowing what's specifically needed is nice), but I'm not sure what it'll actually do for the case where an iframe is just a copy/paste embed and can use the allow attribute for whatever it wants.