Every script tag that points at someone else's server is a promise you cannot keep. You are telling your visitors that whatever arrives from that URL, today and every day after, deserves to run inside their browser with the full trust of your page. That is a large promise to make on behalf of a stranger.
Most teams make it casually. A font here, an analytics snippet there, a chat widget the marketing team liked. Each one feels small. Together they form a supply chain, and a supply chain is only as strong as its weakest maintainer at three in the morning.
The failure modes are well known by now. A CDN gets compromised and ships malware to every site that trusts it. A popular library changes hands and the new owner quietly adds a miner. A tag manager becomes a side door for whoever controls the account. None of these require your own server to be touched at all. Your page simply invites the attacker in.
We took a plain position when we built this site: if we do not host it, it does not load. Fonts are subset and embedded. Icons are inline vectors we drew ourselves. The one map we wanted became a simple link instead of an embedded frame. Our content security policy now reads like a locked door, everything from self, no exceptions to remember, nothing to re-audit every quarter.
What that buys:
- No third party can change what runs on our pages, because no third party runs anything on our pages.
- The browser enforces the policy even if a mistake slips into our own markup.
- Visitors are not tracked by anyone as a side effect of fonts or maps.
- The site works offline and on hostile networks, because nothing external is ever fetched.
There is a cost, and it is honest work. Self hosting fonts means subsetting them. Replacing a widget means building a small thing yourself. But that work is done once, while a third party dependency is a risk you carry every single day it stays in the page.
When you cannot remove a dependency, contain it. Pin exact versions with subresource integrity. Grant it the narrowest possible policy allowance. Load it only on the one page that needs it. And write down why it is there, so the next engineer is free to question it.
The web rewards convenience, and attackers know it. Treat every external script as what it is: code you did not write, running with authority you granted, on a schedule you do not control. Then decide whether it has earned that.
Written by the Cypherslash team, from the build notes of this very site.