3 ms·
What is the big deal with sending the referrer header? It's been common practice for many years. Why the upheaval now? And shouldn't this type of thing be a bro
by wesley 16y ago
What is the big deal with sending the referrer header? It's been common practice for many years. Why the upheaval now? And shouldn't this type of thing be a browser setting instead of a website hack?
- jacquesm 16y agoIt's no 'big deal', it's just that people that are not technically oriented don't even realize that it exists. The problem here is - or rather was - that duckduckgo is differentiating itself from other search engines in a number of ways, and one of the more important ways in which this is done is that at duckduckgo.com you can search for things in the knowledge that they take your privacy seriously and that they will not sell your soul to their highest bidder. On top of that they try to limit inadvertent exposure of your private information to third parties. And that's where the problem came from, if you state loud and clear that you are secure, and then you're found to be insecure you have an immediate problem. So, since duckduckgo.com is setting itself apart from the 'pack' by providing this useful feature and because it is part of their image of being trustworthy they had to address it. If browser manufacturers would think a bit they would drop the 'Referer' header on https requests, but since it's been there for years now you can expect it to be there for years to come, to step forward and fix it was the right thing to do, and I'm very impressed with the way Gabriel responded to the publicity around the issue and how quick and thoroughly he fixed it. I wished all companies would be that professional in their dealings with the public.