11 ms·
Serious question: what are the substantial security considerations? I've been embedding websites in a tiddlywiki instance for todos as a test run, and I was su
by codemac 7y ago
Serious question: what are the substantial security considerations?
I've been embedding websites in a tiddlywiki instance for todos as a test run, and I was surprised how much every website now tries to avoid/stop iframes due to the fact they aren't a "root" element.
This type of HTML element would allow me to build a web application that actually leverages other websites w/o click jacking. This is so powerful, it's what makes emacs and other ubiquitous interfaces so powerful. Leveraging other content
But maybe that's a pipe dream? Maybe that should be an application outside of the browser? Curious if there are any resources on the security implications of < portal >
- tatersolid 7y ago> I was surprised how much every website now tries to avoid/stop iframes due to the fact they aren't a "root" element. JS-based “iframe busters”, then X-Frame-Options, and now Content-Security-Policy should be ubiquitous. We started “busting iframes” in they early 2000s in the banking industry for security reasons. Preventing being an iframe child protects your site from phishing via click-jacking your login screen, and also prevents “stealing” of your content by spammy aggregation sites.