Backdoor Service Workers

When I was moderating that panel at the Progressive Web App dev Summit, I brought up this point about twenty minutes in:

Alex, in your talk yesterday you were showing the AMP demo there with the Washington Post. You click through and there’s the Washington Post AMP thing, and it was able to install the Service Worker with that custom element. But I was looking at the URL bar …and that wasn’t the Washington Post. It was on the CDN from AMP. So I talked to Paul Backaus from the AMP team, and he explained that it’s an iframe, and using an iframe you can install a Service Worker from somewhere else.

Alex and Emily explained that, duh, that’s the way iframes work. It makes sense when you think about it—an iframe is pretty much the same as any other browser window. Still, it feels like it might violate the principle of least surprise.

Let’s say you followed my tongue-in-cheek advice to build a progressive web app store. Your homepage might have the latest 10 or 20 progressive web apps. You could also include 10 or 20 iframes so that those sites are “pre-installed” for the person viewing your page.

Enough theory. Here’s a practical example…

Suppose you’ve never visited the website for my book, (if you have visited it, and you want to play along with this experiment, go to your browser settings and delete anything stored by that domain).

You happen to visit my website There’s a little blurb buried down on the home page that says “Read my book” with a link through to I’ve added this markup after the link:

<iframe src="" style="width: 0; height: 0; border: 0">

That hidden iframe pulls in an empty page with a script element:

<!DOCTYPE html>
<html lang="en">
<meta charset="utf-8">
<title>HTML5 For Web Designers</title>
if ('serviceWorker' in navigator) {

That registers the Service Worker on my book’s site which then proceeds to install all the assets it needs to render the entire site offline.

There you have it. Without ever visiting the domain, the site has been pre-loaded onto your device because you visited the domain

A few caveats:

  1. I had to relax the Content Security Policy for to allow the iframe to be embedded on

    Header always set Access-Control-Allow-Origin: ""
  2. If your browser’s settings has “Block third-party cookies and site data” selected in the preferences, the iframe-invoked Service Worker won’t install:

    Uncaught (in promise) DOMException: Failed to register a ServiceWorker: The user denied permission to use Service Worker.

The example I’ve put together here is relatively harmless. But it’s possible to imagine more extreme scenarios. Imagine there’s a publishing company that has 50 websites for 50 different publications. Each one of them could have an empty page waiting to be embedded via iframe from the other 49 sites. You only need to visit one page on one of those 50 sites to have 50 Service Workers spun up and caching assets in the background.

There’s the potential here for a tragedy of the commons. I hope we’ll be sensible about how we use this power.

Just don’t tell the advertising industry about this.

Have you published a response to this? :



(…) Just don’t tell the advertising industry about this. (…)

Ouch. Good find, Jeremy.

# Posted by Webrocker on Thursday, July 7th, 2016 at 5:02pm


“There you have it. Without ever visiting the domain, the site has been pre-loaded onto your device”

# Posted by Hidde on Monday, August 8th, 2016 at 10:29am


# Shared by Claudio (aglioeolio) on Thursday, July 7th, 2016 at 4:16pm

# Shared by Jay Wintermeyer on Wednesday, March 6th, 2019 at 6:38pm


# Liked by Jan Skovgaard on Thursday, July 7th, 2016 at 5:03pm

# Liked by Front-End Front on Sunday, July 10th, 2016 at 9:26pm

# Liked by Beth Dean on Wednesday, March 6th, 2019 at 7:08pm

# Liked by Jay Wintermeyer on Wednesday, March 6th, 2019 at 7:08pm

Previously on this day

10 years ago I wrote Misunderstanding markup

The death of XHTML has been greatly exaggerated.

12 years ago I wrote Typing up

Calculating vertical rhythm and horizontal alignment.

12 years ago I wrote Charlie Romeo Alpha Zebra Yankee

Never a dull moment.

14 years ago I wrote I'm okay

Following the attacks in London this morning, I’ve had messages from friends abroad asking if I’m alright. Thank you all for your concern. I’m fine.

17 years ago I wrote Whorechalking

Tom Coates has put together a site detailing the next logical step up from Warchalking.