#HTTP #FeaturePolicy is a new way for websites to practice #LeastAuthority and build trust with users by disabling access to #browser APIs that are not used. Browsers already include it but the spec isn't final: it is missing a way to set the default to none. Join the discussion here https://github.com/w3c/webappsec-feature-policy/issues/189 #w3c