3 ms·
Same experience here. But why don't thet kill the referer header entirely? Mozilla's attempts at protecting user privacy seem very half-hearted.
by wronex 6y ago
Same experience here.
But why don't thet kill the referer header entirely? Mozilla's attempts at protecting user privacy seem very half-hearted.
- nybble41 6y ago> But why don't thet kill the referer header entirely? Compatibility, probably. There are some sites which fail to load or end up in redirect loops if the Referer header is missing. It's not just minor sites, either. The last time I tried blocking Referer headers—just the third-party ones—it broke Google Hangouts (both the Chrome extension and the web version). That was earlier this year.
- 1vuio0pswjnm7 6y ago"Mozilla's attempts at protecting user privacy seem very half-hearted." That is because they are. Mozilla cannot survive without internet advertising, and they sacrifice the privacy of Firefox users in exchange for funding from an advertising company, Google. Anyone who is serious about internet privacy knows it requires some amount of vigilance. It necessitates some amount of inconvenience. It is not simply a matter of software selection. AFAIK, no third party today is going to take on full responisibility for any user's privacy. You never see Mozilla advocating for user vigilance, yet the fight for internet privacy is the user's, not Mozilla's. The message from Mozilla is something like "If you use Firefox, we have you covered." This encourages inaction more than action. That's good for companies like Google. If Google paid a group of users the millions it pays the group working at Mozilla, I doubt those users would care one iota about "privacy". Their own, or anybody else's. Why bite the hand that feeds you. I only send Host and Connection headers for GET and Host, Connection, Content-Length and Content-Type for POST. For me, this works beautifully for 100% of websites posted to HN, and elsewhere on the www. I can easily create exceptions in the forward proxy configs to send Referer to sites that require it. This never happens, IME.