Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Worth considering Tor browser's stance on this (and a plethora of other issues). See A.1. Deprecation Wishlist

https://www.torproject.org/projects/torbrowser/design/

I happen to disagree with Tor on this though (they worry about breaking sites). I've found that setting referrer to target site's host has pretty good results (this can be done with various plugins).

In general, browser maintainers seem to prioritize compatibility over security. I think a new browser or fork that prioritizes security, possibly Tor, will eventually become dominant. And I'm excited for Servo, the renderer to replace Gecko, which is written in Rust (memory safe).



The Tor project is not in the position to change or deprecate such things. On the contrary, if Chrome or Firefox would deprecate the referer, we could get rid of it, gradually.

The same is true for the worrisome behaviour of `window.name`.

As I said, mechanisms that rely on the referer for "authentication", such as image requests, are broken.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: