Hacker News new | past | comments | ask | show | jobs | submit login

Bad news for https://howtoopenanumberedaccount.com visitors (Host header in plaintext) and people who click on links to http://ponies.net from https://reddit.com/r/LaunderYourCash (Referer header in plaintext)



AFAIK browsers will not provide a referrer if the previous page in case you go from https to http. Firefox has an option to disable https to https referer sharing btw.


Presumably the non-https assets which get pulled in when the main request is fulfilled could also act as a "fingerprint" of the page you are visiting?




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: