I know Google would never agree to do something like that - unless Mozilla, Apple (the new "privacy" company) and Microsoft (another one pretending to defend user privacy) would put pressure on Google by adopting such a system, together.
> Resources can still be included from a variety of domains, but the data they use is exclusive to this sandbox. A script from google.com on youtube.com would be completely isolated from the same script running at blogger.com.
1. How would that work exactly? There's nothing stopping the script from sending data back to a server for later association with another site.
2. How would a site (or the user) authorize specific 3rd-parties to operate within a given site? This problem is seen by anyone running NoScript today, observing how sites break/work as a subset of 3rd-party scripts is incrementally enabled.
3. If servers are sharing data in real time with commercial 3rd-parties, would they be required to disclose this to users? Publishers don't disclose this today. NoScript allows users to identify 3rd-parties and block them. If this is done on the server, is there a loss in transparency?
4. In general, systems which implement strong isolation are immediately met with user requests to relax this isolation in specific contexts. E.g. Apple added inter-app communication in iOS8. How can "contextual whitelists" be maintained for cross-domain risk management? Should these be determined by the browser vendor, user, or server? Do we need a multi-stakeholder model like CSS, with user preferences negotiated at runtime with publisher preferences? What happens when proprietary DRM is running in the client?
http://mortoray.com/2014/09/30/a-secure-and-private-browser-...
I know Google would never agree to do something like that - unless Mozilla, Apple (the new "privacy" company) and Microsoft (another one pretending to defend user privacy) would put pressure on Google by adopting such a system, together.