4 ms·
Could we, like, do away with iframes?
by pshc 3y ago
Could we, like, do away with iframes?
- bradleybuda 3y agoPortals were (are?) an attempt to do this. Haven't heard much about them in a while: https://github.com/WICG/portals#summary-of-differences-between-portals-and-iframes https://github.com/WICG/portals#summary-of-differences-betwe...
- bqmjjx0kac 3y agoPlease delete JavaScript while we're at it.
- mjevans 3y agoJavaScript tends to be fine in specific allow-listed circumstances: * User preference (E.G. plugins/extensions) * Native to the site, when a user is logged in * Trivial and sandboxed to page local data I recall how I used to use Flash, with a plugin that delayed the loading until AFTER I hit 'play' on the plugin frame. I suspect that's the sort of security framework that will solve a lot of the problems. Do not run untrusted code by default. Have the user to enable a site (often during account creation / sign in on a new device). Have the user 'click play' if they expect something to work. Make sites that just work without client side code again.
- jefftk 3y agoDo away with iFrames and we'll have ads running same-origin to content. So much XSS...
- asddubs 3y agoit would be enough to disallow/containerize third party cookies, like pretty much every browser besides chrome does