5 ms·
I'm consistently surprised that nobody ever talks about HTTP referrers, which are the most egregious of all privacy-invading functionalities -- and are enabled
by bryans 5y ago
I'm consistently surprised that nobody ever talks about HTTP referrers, which are the most egregious of all privacy-invading functionalities -- and are enabled by default in EVERY browser, including the privacy-centric ones. If you're not blocking referrers, you don't have a sliver of privacy online.
- thinkingemote 5y agoPerhaps you have a fix for this which you could share?
- 8bitsrule 5y agoIn about:config, you can set the value of 'network.http.sendRefererHeader' to 0 (default is 2.) As usual, some websites may object to this.
- bryans 5y agoThe Referer Control plugin is probably still the best option, even though it hasn't been updated in a long time. There are a few newer ones that supposedly deal with the issue of sites breaking, but I haven't tried them. https://addons.mozilla.org/en-US/firefox/addon/referercontrol/ https://addons.mozilla.org/en-US/firefox/addon/referercontro...
- SAI_Peregrinus 5y agouBlock Origin can block them. Some poorly coded sites will break with them blocked, so you'll have to whitelist them. Anything from Atlassian is notable, so Jira/Confluence/Bitbucket.
- morelisp 5y agoPeople talk about Referer constantly in privacy-related fora, the problem is that there's also still an enormous numbers of sites which will break if it's disabled. Browsers have gradually stripped it down to just the origin, and I expect we'll see it disappear entirely in non-same-origin non-TLS situations eventually, but there's not much more they can do by default.
- bryans 5y ago> Browsers have gradually stripped it down to just the origin The big caveat is that the new browser policies will only default to origin if the website didn't specify the header, which means the website owner is still in control of whether it gets shared with the third party.
- morelisp 5y agoIf you mean the originating website, it could send its own URL in any header or parameter, so masking its ability to set Referer would be useless without also some complex supporting feature like ITP / Privacy Budget.