21 ms·
Firefox 87 trims HTTP Referrers by default to protect user privacy
- tomaszs 6y agoI don't understand what Mozilla does to Firefox anymore. What does it mean a page "can" leak private data? Is there any story about anyone affected by the issue? Does this issue even exist? It is just breaking another piece of the open web. It just seems like Mozilla not only surrendered in gaining browser market but also actively acts against open web. I thought website creators and website users should be in charge of what they want to do. But it seems no. Now Mozilla decides what web standards can be broken. I'd maybe applaud changes by Mozilla, but with all of these efforts it is not aimed in gaining more users. Firefox does not gain users with such actions. It does not make any sense what is the aim of Mozilla anymore with Firefox.
- Ayesh 6y ago> Is there any story about anyone affected by the issue? Does this issue even exist Yes. Yes it does. Imagine, a web site that has a query parameter with a secret (password reset pages, email unsubscribe, custom feeds, etc). Any images or other assets used in the page will receive the full URL as the referrer, so they can see those secrets. GitHub fixed this very issue a few years ago. They have a feature to get custom RSS feeds for user activity. There is a secret worry parameter in the URL, and any third party images were receiving that full URL. Referrer-Policy header is already supported in many browsers.
- fvv 6y agoIf it's a page that contain or receive secret should be using https where referrer is already stripped off
- jefftk 6y agoFirefox was using no-referrer-when-downgrade, which only strips refers when navigating from HTTPS to HTTP. They are switching to strict-origin-when-cross-origin, which cuts the referrer down to just the origin when navigating to a different origin.
- tomaszs 6y agoSo where is a real life example?
- iso1631 6y agoRFC-1945: Because the source of a link may be private information or may reveal an otherwise private information source, it is strongly recommended that the user be able to select whether or not the Referer field is sent. For example, a browser client could have a toggle switch for browsing openly/anonymously, which would respectively enable/disable the sending of Referer and From information. So not sending referrer has always been fine, and I suspect that firefox will have an option to enable the sending somewhere in it.
- pjmlp 6y agoNormal people are going to switch browser instead of trying to find the said option, because Firefox is "broken".
- wccrawford 6y agoI would say that most "normal people" don't even know the browser sends a referrer header, and it doesn't actually do anything for them. This is useful for site owners, and they have little control over what browser their users use. And as someone else already pointed out, the other big browser (Chrome) has already done this.
- fogihujy 6y agoWhy would this break anything? Which sites would break just because the referrer policy default setting changed? And why wouldn't sites have fixed that before, since Chrome pushed the same change last year?
- RHSeeger 6y agoSwitch to what, exactly? Chrome already does this, according to another poster.
- Mordisquitos 6y agoNormal websites are going to be unaffected in terms of user-facing functionality, regardless of whether they use the data gathered from HTTP Referer internally. On the other hand, badly designed websites that do depend on the HTTP Referer to provide functional user experience are going to lose their users in favour of normal websites, because they are "broken"—and always have been.
- darkwater 6y agoAccording to Wikipedia [1] the "Referer" (sic) HTTP header is an optional one so I don't see how they are breaking the open web by sending less data in it under some circumstances. [1] https://en.wikipedia.org/wiki/HTTP_referer https://en.wikipedia.org/wiki/HTTP_referer
- selykg 6y agoIf the referrer header contains the full URL from which the user came from it could contain something the user deems private. Imagine that the URL contains a search string that contains something the user might deem private, or the article is about something a state may deem to be illegal, etc. This may not be PII but it could be deemed private by the user. The user should be in control of what information could be given to a website. Imagine a scenario where a person is a member of a group that is looking for equal rights in a country that is very much opposed to this. The group uses a tool that happens to make it clear who this group is. The group then links to an article about their cause or similar. Now that country could potentially link things together and demand information about everyone in that group. It's amazing how little bits of information about you can get you in hot water. This is a good move imo, and I'm glad that Mozilla is trying to plug these types of things. It's better for everyone. As an aside, moving to a privacy oriented browser could very well get Firefox more users. Just like Apple's play to being a private and secure mobile OS is getting them users.
- tomaszs 6y agoSo where is the example?
- selykg 6y agoI think you've been given plenty. You should try to come into these conversations with a lot less attitude. Perhaps I'm reading your tone wrong, and if I am I'm sorry about that. I always come into these discussions assuming I'm not the smartest person in the room because that means I have more to learn. Maybe give that a try?
- deleted 6y ago[deleted]
- ing33k 6y agoany chance that a few CORS implementations will break due to this ?
- capableweb 6y agoNo.... ? Not as far as I could gather. Why would CORS break because of this change? AFAIK, CORS has nothing with the referrer header.
- gruez 6y agohe's probably talking about referrer checks which are used as a mitigation against csrf
- gruez 6y agoIt only trims path and query information so it should be fine unless the site is overzealous and checks those.
- qertoip 6y agoGood.
- hn_throwaway_99 6y agoAnd just a reminder that it's always a good idea to set Referrer-Policy regardless on sites you own.
- arbuge 6y agoIt's good advice, but bizarrely some browsers ignore Referrer-Policy, even when it requests "no-referrer", which basically increases the privacy level to the maximum possible - beyond for example the origin-only settings which the browser defaults are now tending towards (such as with this Firefox update). In my testing, all recent versions of Safari on iOS were the worst offenders here. I talked more about this here: https://twitter.com/arbuge/status/1354805900268105743 https://twitter.com/arbuge/status/1354805900268105743 You would think that Safari would jump at the chance to show no referrer, given Apple's attempts to position themselves as champions of user privacy, but for some reason the opposite is in fact true.
- edent 6y agoHere's a practical reason for doing this. https://shkspr.mobi/blog/2018/01/mailchimp-leaks-your-email-address/ https://shkspr.mobi/blog/2018/01/mailchimp-leaks-your-email-... A few years ago, I discovered that referrers from MailChimp let you unsubscribe people from lists, and see their email addresses.
- maddyboo 6y agoVery cool discovery. This is an excellent example of why putting sensitive data inside URLs can be problematic and should be done with great caution. It should be added that the eventual elimination of referers won’t make URLs safe. There are countless other ways they can leak.
- avsteele 6y agoDoesn't this just push people to more tracking cookies? How are sites supposed to know what sources are driving their traffic? Whether visitors are coming via email campaigns, google, etc?
- Symbiote 6y agoWhy should they know this? I am keen that they don't know this. If I walk into a shop, the shopkeeper doesn't know if something in the window caught my eye, if my friend recommended the helpful staff, if I saw the advert they placed on a billboard, or if I just came in because it's raining.
- slater 6y ago"the shopkeeper doesn't know if something in the window caught my eye" Except that's already here, or in the making, i.e. with those advertising eye-tracking stories that make the rounds every 6 months or so.
- nickjj 6y ago> If I walk into a shop, the shopkeeper doesn't know if something in the window caught my eye, if my friend recommended the helpful staff, if I saw the advert they placed on a billboard, or if I just came in because it's raining. A lot of places will attach unique discount codes to advertisements to get an idea on where you came from. For example, on a TV commercial it might say use promo code COOL123 to save 10% or if you saw that billboard it might say to use NICE123 instead. Then there's radio, newspapers and so on each with their own unique code that offer the same 10% discount. And since a discount is applied chances are you'll use it because not too many folks would purposely avoid the discount to hide where you discovered the shopkeeper from. You often see this being done online too, but there's also things like UTM tags or unique URLs that let you do the same thing without discount codes. It's not to make more money as a shopkeeper (avoiding the discount), it's just easier to set up. Using a UTM tag is a matter of creating a link with a few query parameters. Creating a specific discount code or a unique URL for a specific promotion takes a bit of extra leg work. I'm not sure where I stand on the movement to remove all forms of referral tracking. Both referral headers and UTM tags can be spoofed or removed through extensions so using them as any type of source of truth was a bad idea anyways. However, as someone who sells digital products I like knowing which specific video or blog post helped someone discover some of my paid content. But at the same time, the end game is really "is the needle moving forward?" so the specifics kind of don't matter. But in the short term while you're figuring things out, the extra info does help you focus on where to spend your time. Not just for more profit, but to provide better and more free content because it's what folks want.
- sneak 6y agoI hope they do User-Agent next.
- jefftk 6y agoThey've indicated they may: https://github.com/mozilla/standards-positions/issues/202#issuecomment-558294095 https://github.com/mozilla/standards-positions/issues/202#is... Commenting in support of Chrome's proposal to freeze the user agent and provide UACH instead.
- sneak 6y agoUACH is worse than a header. The server shouldn't get information about the client. Unsurprisingly, UACH is spearheaded by an ad tracking company that benefits from a moat caused by minimally viable/workable browsers costing millions of dollars and dozens of developers to implement.
- SquareWheel 6y ago> UACH is worse than a header. It's not. The header gives up all information by default. UA-CH works by request-only, and allows the browser to determine how much to send. This is easily controlled via native settings or browser extensions. The API also requires a secure connection, and specifically forces the server to admit to any fingerprinting (or legitimate use-case of data otherwise).
- oneeyedpigeon 6y agoAt least that might stop Twitter refusing to serve User-Agents it doesn't recognise.
- deepstack 6y agoGood for firefox. although I can see how this may break vimeo kind of service that only allow embedding video from certain web site.
- simias 6y agoThey still send the domain name on cross-origin requests, so the type of filtering Vimeo does will be unaffected as far as I can tell. It's only when the target website needs the full source URL (with path and GET parameters) that you may encounter issues.
- hannob 6y agoJust a FYI because some people are complaining that Mozilla is doing something evil or will break all of the web or something. Chrome made the same change a while back: https://developers.google.com/web/updates/2020/07/referrer-policy-new-chrome-default https://developers.google.com/web/updates/2020/07/referrer-p... So if this breaks something people probably already noticed. And Mozilla is merely aligning with the browser with the largest market share on this. (Also everyone who wants something different for their sites, it's configurable: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Re... )
- merb 6y agowhy tf should removing Referer break sites? who uses Referer?! the only thing that Referer brought were privacy leaks.
- npteljes 6y agoI recently had to enable it for some login to work, unfortunately can't remember which website.
- roywiggins 6y agoI've had to enable it for Atlassian's login to work.
- prussian 6y agoI turned it off once and the most common breakages were usually authentication that involves some kind of OpenID delegation.
- hirsin 6y agoYeah, we (Azure AD) got a couple of "login is broken" escalations when Chrome made this change. A couple vendors use it to validate a request is coming from the upstream IDP, to block drive by attacks I assume.
- professor_v 6y agoI just realized the 'Referer' header is actually a misspelling in the http protocol.
- themoose8 6y agoYup, here's an article you may enjoy https://httptoolkit.tech/blog/http-wtf/ https://httptoolkit.tech/blog/http-wtf/ and related HN discussion https://news.ycombinator.com/item?id=26343577 https://news.ycombinator.com/item?id=26343577
- SilasX 6y agoAnd I made up the HTTP status code "397 Tolerating" so that if you spell it "Referrer", browsers can correct you while still giving you the response you wanted :-p (see section 3 example): https://pastebin.com/TPj9RwuZ https://pastebin.com/TPj9RwuZ
- sjwright 6y agoI am genuinely unsure whether your RFC was intended to be serious or not.
- SilasX 6y agoSo am I! I did it as an April Fool’s joke (see the date and the author, Ben Dover). But I also think it would be legitimately useful and have long wished for a standard protocol for expressing that you’re “tolerating” a standards violation while still pointing it out.
- SilasX 6y agoLate correction: sorry, that should be "if your browser spells it 'Referrer', webservers can correct you...".
- tannhaeuser 6y agoThat's going to break lots of older sites using Referrer for navi state. These will now either have to use query params, cookies, or JS instead. Not to mention easy affiliation links.
- ExcavateGrandMa 6y agocuriously it always protected user privacy through ages :D but which end of the use :D
- gianfrid 6y agoNice, I'm using SmartReferer (https://addons.mozilla.org/en-US/firefox/addon/smart-referer/ https://addons.mozilla.org/en-US/firefox/addon/smart-referer...), I'm always happy to drop an extension when Mozilla natively implements the same feature
- ChrisGranger 6y agoSmart Referer is even stricter than this new policy if you don't use the recommended 'Lax' setting. It will block referers even on the same domain but to different subdomains, if you want it to.
- surajs 6y agoyour privacy will become the joke
- e12e 6y agoI think there'd be a bit less panic in the comments if the title/headline reflected that the change (as I understand it) applies cross-origin and cross-scheme (http > tls). So if you're preventing hot-linking of assets, this should not affect you (or; you have some control over it via policy): > this new stricter referrer policy will not only trim information for requests going from HTTPS to HTTP, but will also trim path and query information for all cross-origin requests. Seems like a fairly balanced way to protect privacy along with preserving utility?
- myfonj 6y agoOh, I'll really miss occasionally peeking at AWStats and discovering weird pages pointing at my weird pages :( This subtle aspect of web had been always strangely appealing for me: people leaving trails in access logs and building real "footpaths" network of synapses between HTML documents, across origins. Sad to watch it dying, however beneficial and understandable it is. I feel it didn't have to be this way: maybe if GET wasn't so widely misused recently and generally everybody knew what to not put in URL and acted accordingly, we could have preserved such nice things.
- leephillips 6y agoTotally agree. As almost no one uses anything like webmentions, this was the way to discover who was linking to your site. (And because the Google link tool didn’t seem to return much actual information.)
- nerdponx 6y agoBring it back! https://news.ycombinator.com/item?id=26401955 https://news.ycombinator.com/item?id=26401955
- myfonj 6y agoFrom a glance at MDN [1] and specs [3] it seems at least we can still opt-in our sites to suggest visitors user agent to pass full referrer address along outgoing links; there seems to be three ways to do so: # 1. Apache conf Header set Referrer-Policy "no-referrer-when-downgrade" <!-- 2. meta HTML head with same effect [2] --> <meta name="referrer" content="no-referrer-when-downgrade"> <!-- 3. HTML anchor attribute --> <a href="https://…" referrerpolicy="no-referrer-when-downgrade"> This will pass full path and query when navigating between HTTPS to foreign origin. I guess it will be lost in http: to https: redirects. `unsafe-url` value would do it even for HTTP. (Funny all three have different spelling, and that in effect they direct value of a single HTTP header with inherently erroneous spelling.) [1] https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Re... [2] my guess using `<meta http-equiv="Referrer-Policy" content="no-referrer-when-downgrade">` should do the same, but is not explicitly mentioned anywhere. [3] https://w3c.github.io/webappsec-referrer-policy/ https://w3c.github.io/webappsec-referrer-policy/
- ape4 6y agoI've noticed recently the <Back button is sometimes disabled in Firefox. Related?
- chrisjc 6y agoNot sure if it's related, but the > Back button is sometimes disabled in Firefox for me when I click on a Medium (or similar) link. However I think this is related to containers. It's really annoying, but I'd rather just avoid Medium that abandon Firefox.
- nofinator 6y agoThis made me wonder how to do it now, in Firefox 86. I found this helpful page: https://askubuntu.com/questions/797135/how-to-disable-http-referrer-in-firefox https://askubuntu.com/questions/797135/how-to-disable-http-r... TL;DR about:config --> Network.http.sendRefererHeader --> change value from 2 to 0
- jefftk 6y agoThat fully removes the header, instead of stripping it down to just the origin as they're going to be doing.
- floatboth 6y agonetwork.http.referer.defaultPolicy is the correct one
- deleted 6y ago[deleted]
- mmphosis 6y agohttps://wiki.mozilla.org/Security/Referrer https://wiki.mozilla.org/Security/Referrer
- jakub_g 6y agoAs a user I love stricter privacy. As a developer working for a platform company whose content (video) is embedded by thousands of websites, I hate this particular change: - more difficult to analyze weird / fraudulent embedders - more difficult to debug issues ("what's the sample URL to repro? no sample URL in logs, only top-level of the domain, but I don't find our embed anywhere ¯\_(ツ)_/¯") Funny thing: you can't just tell your embedding partners to change the embed code and use `referrerpolicy=...` on the iframe, to expose the full URL, because it's not GDPR-compliant apparently. So you need user's consent first. But how do you obtain user's consent before you render HTML on the server? :) ("GDPR wall" is not compliant either) Life sucks, I guess. But it's for greater good, and I guess the companies will somehow survive.
- codegeek 6y agoSo if someone does want to use http referrer for any reason (e.g. only load a certain asset if coming from internal URL/specific referrer), what needs to be done ?
- jefftk 6y agoChecking for a specific internal URL will still work: they're changing the default cross-origin behavior.
- dbg31415 6y agoDoes Firefox 87 still make my MBP a toaster when I turn on a Zoom call through Firefox? Power usage for same streaming video call on Safari vs. Firefox. https://i.imgur.com/I7T19d0.png https://i.imgur.com/I7T19d0.png
- bouncycastle 6y agoThe HTTP referer (a misspelling of referrer) was broken for a while, ever since spammers figured out they can abuse it.
- Mauricebranagh 6y agoIsn't this going to break campaign tracking for Adwords etc. Not exactly what the actual risk is to privacy here does seem there is a lot of bandwagon jumping going on - a bit like "Elf & Safety" or the Data protection act is trotted out when an organisation wants an excuse not to do something.
- ratww 6y agoReferrers can leak information about which pages the user was navigating before, which linked websites have no business of knowing. If you want to do tracking and have control over both pages, just use a different URL, a query string, or something like that.
- collsni 6y agoI have sending the referrer header for years in firefox, if a site doesn't accept it I just go somewhere else.
- TriNetra 6y agoWe chose not to add referrer to ASPSecurityKit main site [0]. It's a static content site and I think it'd be useful to let other sites know which page (docs/guides/blog) on our site got them a visitor because the content is public anyway. We've applied it on the dashboard though, this same origin-when-cross-origin policy. 0: https://ASPSecurityKit.net https://ASPSecurityKit.net
- deleted 6y ago[deleted]
- aimor 6y agoI'm surprised it took this long, and it's still not completely gone. I've never understood the history of why http referer exists (original intent) or why the user would benefit from sharing it.
- jameshart 6y agoThe original HTTP specification really didn’t think of the web as an adversarial environment. The RFC that specified the ‘referer’ header [1] described it as having the following purpose: [Referer]... allows the client to specify, for the server's benefit, the address (URI) of the resource from which the Request-URI was obtained. This allows a server to generate lists of back-links to resources for interest, logging, optimized caching, etc. It also allows obsolete or mistyped links to be traced for maintenance. The idea of how a user benefits from sharing it was that it would help the webmasters upon whom they were reliant to do a better job of curating their websites. It clearly expects a benevolent relationship between the owner of the linked site, the host of the link, and the user. Idealistic, sure, but understandable in a collaborative, academic context. [1] https://tools.ietf.org/html/rfc1945#section-10.13 https://tools.ietf.org/html/rfc1945#section-10.13
- beagle3 6y agoThat reminds me that in 1999, looking through the referrer logs, I realized that if the link came in from an Outlook email, Outlook+IE would report the subject of the referring email as the referrer (iirc with user name, something like “mailbox://user@site/subject-of-the-email”). So we started looking for those more seriously in my company, and got quite a bit of interesting Intel from potential investors, competitors we knew about, and some we weren’t even aware of. It was just the subject and user, but was often surprisingly informative.
- pbhjpbhj 6y agoDo you, or anyone, have [links to] more information about exactly what Outlook does when requesting a tracking pixel to display in an email. I can't sniff it (Wireshark) as I don't have that sort of access to a network with Outlook on. I've googled but didn't find anything useful.
- beagle3 6y agoIt was surely fixed in Outlook 2007, perhaps even 2003 and maybe even 2000.
- AdmiralAsshat 6y agoWill Firefox trim their own header additions when searching? e.g. here's the page that Firefox generates when I try to search "Dragon Quest XI" in a Private Window on Amazon via the address bar: https://www.amazon.com/s?k=dragon+quest+xi&link_code=qs&sourceid=Mozilla-search&tag=mozilla-20 https://www.amazon.com/s?k=dragon+quest+xi&link_code=qs&sour... Note the 'mozilla-20' tag at the end.
- inigoesdr 6y agoThat's not the same as the referrer header; it's mostly invisible to the end user without inspecting the raw request data.
- SquareWheel 6y agoThat's an affiliate link. It seems then Mozilla is injecting affiliate codes on Amazon searches.
- kaba0 6y agoWhat does the browser has to do with how amazon implements their search? Amazon probably parses the User Agent and puts mozilla there for some reason.
- SquareWheel 6y agoThat seems rather unlikely. If it's not the browser itself, then it's more likely to be an extension inserting it.
- Black101 6y agoIt's about time...
- bitmapbrother 6y agoKind of amusing that Chrome did it first (and the Firefox implementation was likely copied), yet Firefox gets the fanfare. Just an observation.
- eitland 6y agoFor anyone who wonders how http referer could ever be a good idea consider the following: I remember when my dad studied to become a teacher. As one of their assignments they had to create a webside. As someone who had recently given up farming I think he wrote about farm animals and linked to some other pages about small scale poultry and similar topics. One day he got a mail from the "webmaster" of one of the sites he linked to that he would have to update his links soon. I remember being really surprised that someone knew my dad had linked to them. Being only 16 or 17 or something I only knew simple html, basic and vb but I knew that html links were one way. I don't think I realized until later what had really happened: this person had looked at their server logs to see where their customers came from, looked up the page and found the email address. Of course this also highlights why the referer is so problematic.
- jacques_chester 6y ago> One day he got a mail from the "webmaster" of one of the sites he linked to that he would have to update his links soon. I remember being really surprised that someone knew my dad had linked to them. These days 100% of such emails I receive are from spammers trying to steal some google juice.
- antonvs 6y agoYou'll still be able to see which site visitors came from, just not the specific page.
- idclip 6y agoWish i was able enough to help Web servers cull http and be https per default rather than offer complex alternatives that are often hard and multi step to implement.
- NelsonMinar 6y agoAnd so the dream of bidirectional hyperlinks finally dies. Turns out not only do we not need them, in most cases you really don't want them.
- superkuh 6y agoYes. This makes surfing the web harder and will result in more centralization within proprietary walled gardens instead of federation via protocol mechanisms.
- Scoundreller 6y agoGoogle largely killed this when they moved to https by default, but I missed reviewing what search terms visitors used to visit my site and then creating content to answer their actual questions, instead of guessing. But the web was a much smaller place/time back then. Oh, and seeing people search for my uncommon name...
- 1vuio0pswjnm7 6y agoI never send a referer header. This has zero effect on my "user experience".
- wronex 6y agoSame experience here. But why don't thet kill the referer header entirely? Mozilla's attempts at protecting user privacy seem very half-hearted.
- nybble41 6y ago> But why don't thet kill the referer header entirely? Compatibility, probably. There are some sites which fail to load or end up in redirect loops if the Referer header is missing. It's not just minor sites, either. The last time I tried blocking Referer headers—just the third-party ones—it broke Google Hangouts (both the Chrome extension and the web version). That was earlier this year.
- 1vuio0pswjnm7 6y ago"Mozilla's attempts at protecting user privacy seem very half-hearted." That is because they are. Mozilla cannot survive without internet advertising, and they sacrifice the privacy of Firefox users in exchange for funding from an advertising company, Google. Anyone who is serious about internet privacy knows it requires some amount of vigilance. It necessitates some amount of inconvenience. It is not simply a matter of software selection. AFAIK, no third party today is going to take on full responisibility for any user's privacy. You never see Mozilla advocating for user vigilance, yet the fight for internet privacy is the user's, not Mozilla's. The message from Mozilla is something like "If you use Firefox, we have you covered." This encourages inaction more than action. That's good for companies like Google. If Google paid a group of users the millions it pays the group working at Mozilla, I doubt those users would care one iota about "privacy". Their own, or anybody else's. Why bite the hand that feeds you. I only send Host and Connection headers for GET and Host, Connection, Content-Length and Content-Type for POST. For me, this works beautifully for 100% of websites posted to HN, and elsewhere on the www. I can easily create exceptions in the forward proxy configs to send Referer to sites that require it. This never happens, IME.
- wheybags 6y agoWould it really break that much to just get rid of referrer altogether? I would miss it on my personal site (self hosted, Foss analytics, no google analytics there), but it wouldn't actually break anything.
- burtonator 6y agoThis is going to suck... now 2% of my users won't have HTTPS referrers.