Hacker News new | ask | show | jobs
by mrgreenfur 2412 days ago
I agree with this, but we already have this problem for full-fledged browers: each page can usually make requests to any/all 3rd party domains (for any reason). Often I see even javascript from raw cloudfront domains, how the hell should I trust this? (visible via umatrix plugin)

I think default behavior has to be block all 3rd party domains from all sites, but it's a ways away.