Hacker News new | ask | show | jobs
by tallanvor 2878 days ago
Permissive by default also means you have to worry about making sure that every time a new feature comes out that you have to go back and update your code to disallow it rather than updating it to be allowed only if and when you actually want to use it.

I also wonder if this will lead bad actors to scan for this header and start targeting their ads at sites that don't have this policy configured.

It really does seem incredibly poorly thought out.