.@mozsec It's time for Firefox to treat ad iframe as if they had the “sandbox” attribute, and ad script tags as XSS attacks.
2
8
11
Meanwhile, the ad industry wants to extend <iframe> so it can cover the page and read everything other than your pw: iab.net/safeframe
8
38
28
Replying to @jruderman
@jruderman It must be safe, it has "safe" in the name.

Aug 17, 2015 · 10:25 PM UTC