Excellent. Now we need to block third party javascript and then we have a chance at a more secure web. After all, any third party javascript could be done by an underwater call between the server and the provider of the service.
There is plenty of third party javascript that is not at all predatory. Pretty much all analytics services, Olark and other similar customer outreach services, A/B testing suites. There is far more of a push to create new more secure avenues for third party js (namely cors and websockets) to exist than there are efforts to eliminate it. I'm curious how this change will effect services like optimizely that rely on thi…
Big deal.