4 ms·
Isn't this sent by the user's browser, and not by DDG? It's a client-side configuration issue -- turn off referrers in your browser. Your browser would send the
by dzohrob 16y ago
Isn't this sent by the user's browser, and not by DDG? It's a client-side configuration issue -- turn off referrers in your browser. Your browser would send the same header if you clicked through a DDG search result.
- jacquesm 16y agoIt is a duckduckgo issues because they should not be loading third party graphics. The referrer will be on in almost all cases. People just look at the 'lock' item and will assume they're safe. Whatever happened to that 'mixed content' security warning, I thought that was pretty effective against stuff like this?
- epi0Bauqu 16y agoAlso in response to this original suggestion (months ago on reddit), I started serving all images over https. I do not think the referer is sent in plain text, e.g. http://stackoverflow.com/questions/499591/are-https-urls-encrypted http://stackoverflow.com/questions/499591/are-https-urls-enc...
- jacquesm 16y agoI think the combination of a POST instead of a GET and the images via https should be pretty much bullet proof. If someone is stupid enough to re-enable GET requests for their https connections they have only themselves to blame if there is any leakage to the target sites.
- blasdel 16y agoBecause complaining about "mixed content" was completely pointless in the general case -- you could mix content across multiple https sites, but the certificates were never correlated, and the second site would still get all the headers just the same. It's extraordinarily user-hostile, and would just add to the pile of pointless wankery that keeps people from using https (see also: shitting all over self-signed certs when in reality the CAs don't do shit for their rent and identity is useless anyway). The actual solution is to never send Referer headers for cross-site requests from an HTTPS page.
- jacquesm 16y ago> The actual solution is to never send Referer headers for cross-site requests from an HTTPS page. That should be on someone's todo list at the major browser vendors. You're right, there really is no point in sending that header along, and sending it can cause all kinds of trouble.