logoalt Hacker News

RobotToasterlast Tuesday at 8:07 AM3 repliesview on HN

anything loaded from a third party domain shouldn't be allowed to run scripts.


Replies

paslast Tuesday at 8:24 AM

facebook.com does this as a first party site, shit sites trying to squeeze eyeball time from visitors should be put on Google's malware sites list, but apparently those are the best sites nowadays... :/

lxgrlast Tuesday at 11:45 AM

That restriction would both be trivial to circumvent by malicious advertisers and annoying for many legitimate web concepts.

bell-cotlast Tuesday at 9:21 AM

Maybe it's not quite your meaning - but there are browser plugins which allow per-domain blocking of js. I use one, with the default set to deny js.