Thread · 3 tweets · 20 Apr 2021

Replying to @RickByers and @kdzwinel

The broader context is that I'm trying to picture what a principled project to make privacy work on the web would look like. One aspect is that you might need controls over what leaves the origin (maybe like CORS for data), to gain commitment to some rules.
But that will lead to resources being blocked, which leads to "OK, so what most breaks?" If people are encouraged to move scripts to 1P that's already a win just for the injection improvement. But are there things that such an approach wouldn't fix? Totally.