Thread · 2 tweets · 2 Apr 2021

Security decisions like SafeFrame shouldn't be publisher decisions, because publishers can be pressured away from them if they need the money. We should have an <ad> element with strict security and get rid of iframes and code injection.