Tweet · 19 Apr 2021, 19:02 UTC

Replying to @kdzwinel

Well, I'm trying to think about how to slice this into stages that could be shared and agreed-upon as standard. Remove cookies, proxy requests, fence all the 3P frames, then start blocking but with an allowlist. Then chip away from the allowlist (eg. SSO), etc.