Fix #4913 Fix #4885 Auditors: @bbondy Test Plan: 1. go to homestarrunner.com and verify that the flash placeholder appears 2. go to http://web.mit.edu/zyan/Public/xframe.html and verify that the iframe is blank 3. open page devtools, load about:preferences, and verify in the Network tab that the `Access-Control-Allow-Origin` response header is not present on about-preferences.html