You've Been Framed. A survey of iframes and the sandbox attribute
debug.is
debug.is
Userify just removed all third party inclusions except CDN from the app itself. I wish more companies would do this.
What's the point of strong TLS if you're potentially leaking every click and keystroke to a third party?
Use Privacy Badger where you can: https://www.eff.org/privacybadger
https://developer.mozilla.org/en-US/docs/Web/HTML/Element/if...
If nothing else, what happens if someone visits the site without support for `sandbox`? You best option (not displaying it if the browser doesn't support it) breaks the site for users without JS, or that don't have support `sandbox`.
JS is nowhere near as secure as it is often toted as being. You don't want to find yourself being host to a zero-day attack.
If nothing else, what happens if someone visits the site without support for `sandbox`? You best option (not displaying it if the browser doesn't support it) breaks the site for users without JS, or that don't have support `sandbox`.
And I'd be one of those users who would be cut out by JS requirements. Just so you know, that number is not zero.