3 ms·
At this point of time, I give it 10min before we get a magic_proxy nginx module, then your script src will be /magic_proxy/www.evilthirdpary.com/slow_multi_mega
by cryptonym 5y ago
At this point of time, I give it 10min before we get a magic_proxy nginx module, then your script src will be /magic_proxy/www.evilthirdpary.com/slow_multi_megabyte_script.js
You can still import all nasty third parties required by marketing department, bypassing first party protections and leading to even worse security. Or maybe maintain allow lists, basically that's a Content Security Policy.
Future is now old man.
- Pxtl 5y agoAt least then the server has to deal with the security implications of talking directly to the advertiser, instead of pushing the risk wholly to the client.
- cryptonym 5y agoIn the end the script is running on client, dealing with user data, not server data. Client is still taking the risk. On moral/legal issues, integrating script from third or first party hostname sounds like technical detail. If you select partner to run their code on your pages, you should be responsible checking user consent when applicable and taking responsibility. British Airways has been fined £20m even if that script was not on their servers.
- Xelbair 5y agosure, but as other person stated -servers deals with that, and all legal implications about data protection apply to them - it's harder to weasel out of it that way.
- MarkSweep 5y agoThis already here, but made with a subdomain that CNAMEs to a tracker domain: https://arxiv.org/abs/2102.09301 https://arxiv.org/abs/2102.09301