See a site's own rules protect you, and what it was never told
Three privacy defenses you can now see working, all decided and kept on your device. When a site publishes its own security rules - a list of which scripts it is willing to run - Floati honours them and refuses the rest, including scripts injected into the page that the site never intended, the main way cross-site scripting attacks are stopped. Each script refused this way now appears to you as a checkable record rather than happening invisibly. The panel also counts, for the first time, the background connections a page made that were told nothing at all about where you came from, where a normal browser would have handed over your address. And the everyday details every site can read about you - your clock, your language, your device's basic specs - are held to the same standard values for everyone, so they cannot be combined to single you out, now guaranteed against slipping. The security architecture aspect moves 59 to 61; the overall platform score stays at 70.