Thread · 2 tweets · 18 Dec 2017

Do you reckon we could get to a point at which any loading of script from a third-party domain would flag the page as insecure (unless it's in a sufficiently sandboxed iframe), and what do you believe we need to get there?