Thread · 2 tweets · 11 Jan 2023

Replying to @BrendanEich and @dietrich, @boscolochris, @darrello, @csuwildcat, @gordonbrander, @brave, @shivan_kaul, @fmarier, @lidelOrg

Just to make sure we're on the same page: you're considering eg. the <script src="ipfs://deadbeef/jquery.js"> case, right? That wouldn't hit an SOP wall over HTTP so I don't think that it needs to be treated differently over IPFS?
We need to specify the cases in which it should/shouldn't trigger mixed content issues. And we need an in-depth look at the privacy properties of such a load — the notion of "third-party" is pretty meaningless on IPFS!