Re: [CSP] Clarifications on nonces

> The general thrust is "Don't run third-party JavaScript in your site's context." and "Don't serve ads that require DOM access"

Mike, this shuts down the vast majority of the internet advertising
industry and doesn't seem realistic, especially for media-centric
endeavors. What is the endgame here, sandboxing or forcing the ad
industry to fundamentally change?

--
Jim Manico
@Manicode
(808) 652-3805

> On Feb 9, 2015, at 10:32 AM, Mike West <mkwst@google.com> wrote:
>
> The general thrust is "Don't run third-party JavaScript in your site's context." and "Don't serve ads that require DOM access

Received on Monday, 9 February 2015 10:08:36 UTC