3 ms·
For those interested in security - AMP basically forces the iframe javascript sandbox security model. https://www.html5rocks.com/en/tutorials/security/sandboxe
by privateSFacct 7y ago
For those interested in security - AMP basically forces the iframe javascript sandbox security model.
https://www.html5rocks.com/en/tutorials/security/sandboxed-iframes/ https://www.html5rocks.com/en/tutorials/security/sandboxed-i...
Even reputable web pages tend to have a metric TON of non-sandboxed javascript from third parties. If you care about your security this is a risk.
If you stick with AMP - this is - by spec - prohibited.
Something to think about as you browse the web gobbling down javascript and all the other third party javascript being pumped at you.
- ogre_codes 7y agoWhich conveniently ensures that the only way you can effectively monetize AMP articles is via Google's own advertising networks which don't have constraints on running javascript.
- gregable 7y agoSee the list of natively supported Ad networks in AMP: https://amp.dev/documentation/components/amp-ad/#supported-ad-networks https://amp.dev/documentation/components/amp-ad/#supported-a... There are about 200 in that list and any network can submit a config to be added, it's just a pull request away.
- JohnFen 7y ago> For those interested in security - AMP basically forces the iframe javascript sandbox security model. AMP is the wrong way to address this. Using a good browser is the right way.
- privateSFacct 7y agoMy parents use IE, my friends use Safari - both have high market share - are these good browsers? Should users of these browsers be forced to fight through flyover ads that autoplay audio, repainting pages that jump around like crazy, huge sets of third party javascript with total access to their page / session?
- rpmisms 7y agoNow that we finally can run JS in AMP. That's been a big no since we can't run our normal funnel using AMP.