>and yes, they have to be all set one by one, because there is no deny-all in the spec. No doubt this spec was designed with end-users' privacy and security in mind.
I can understand that, actually. deny all would be a forward compatibility nightmare
the problem comes when you decide to make a rule for something that was already possible before. let's say you have your deny-all set up becuase you want none of those. and then they add a rule for right clicking (just a silly example) and suddenly stuff breaks
Why would it be a compatibility issue? Every time one gets added it will presumably be added to this list. In fact once you get your embed working with some set of directives you want to say "I will never need more than this, deny anything new."
Is it not possible that they decide to add something as configurable that is currently allowed everywhere? As an analogy, when Apple decided to make the ID of a user opt-in.
I can understand that, actually. deny all would be a forward compatibility nightmare