4 ms·
It looks like they're leveraging the safety aspect of AMP here. IIUC, the subset of HTML behavior AMP enables is generally considered to be "safe." If that prop
by fixermark 8y ago
It looks like they're leveraging the safety aspect of AMP here. IIUC, the subset of HTML behavior AMP enables is generally considered to be "safe." If that property can hold, AMP-enabled email can allow for the benefits of live HTML in the client without the drawbacks of the surprises that can occur from arbitrary HTML execution.
- fauigerzigerk 8y agoDoes AMP not allow JavaScript?
- fixermark 8y agoAMP gates the JavaScript it allows and requires asynchronous evaluation. 3rd party JS is also allowed, but it has to be in a sandboxed iframe which, in a browser at least, would guard some of the user's state from exfiltration attacks (it's unclear to me if the iframe feature is available in email AMP). https://www.ampproject.org/learn/about-how/ https://www.ampproject.org/learn/about-how/
- fstanis 8y agoEmails only support a subset of AMP, so iframes and any form of JavaScript (other than the whitelisted AMP components) are not allowed.
- deleted 8y ago[deleted]
- lucasyvas 8y agoGoogle uses increased security as an excuse and tactic to trick you into using something that you would otherwise have zero interest in. They wave the banana to distract, but the gorilla comes with it.