The broader context is that I'm trying to picture what a principled project to make privacy work on the web would look like.
One aspect is that you might need controls over what leaves the origin (maybe like CORS for data), to gain commitment to some rules.
Thread · 3 tweets · 20 Apr 2021
But that will lead to resources being blocked, which leads to "OK, so what most breaks?"
If people are encouraged to move scripts to 1P that's already a win just for the injection improvement. But are there things that such an approach wouldn't fix? Totally.
But listing them once the parts that can be handled are done makes for a great bridge to policy.
♥ 1