5 ms·
First, there are already multiple Firefox extensions that will let you totally control the Referer header. (In general, if there's something that you want to ch
by briansmith 14y ago
First, there are already multiple Firefox extensions that will let you totally control the Referer header. (In general, if there's something that you want to change about Firefox, you should search https://addons.mozilla.org https://addons.mozilla.org to find a solution, because somebody's probably already created an extension that does what you want.) I think one such extension is called "RefControl."
I also brought up the issue on Mozilla's dev.privacy mailing list [1] recently. See:
https://groups.google.com/d/msg/mozilla.dev.privacy/wmPzPCdzIU8/Vrugn8XquL4J https://groups.google.com/d/msg/mozilla.dev.privacy/wmPzPCdz...
In general, we cannot block the Referer header by default on cross-origin requests because we know that would break too many websites. My proposal is to strip the Referer header down to just the origin + '/', e.g. http://example.org/ http://example.org/ instead of http://example.org/foo?search=whatever+you+searched+for http://example.org/foo?search=whatever+you+searched+for.
I think it will be difficult for us to go further than that in the default configuration any time soon (and, as you can see in that thread, there's even some pushback to my extremely reasonable proposal).
Also, I know there is active work happening to bring extra control over the Referer header to Firefox's built-in prefs. This seems to be a little bit in conflict with our "Checkboxes that kill" project so I'm not sure how it will turn out.
[1] https://lists.mozilla.org/listinfo/dev-privacy https://lists.mozilla.org/listinfo/dev-privacy
- Silhouette 14y agoFWIW, I just followed your advice, searching Firefox Addons for "Referer". The results were not helpful at all for the goal abcd_f mentioned of blocking cross-site referrers. [Edit: Sorry, it looks like I mistyped "Referer". There is at least one promising addon on the first page.] Also FWIW, I agree that this is indeed becoming a significant privacy issue. I too don't see why Google or Typekit or some widely used CDN should be gifted a convenient history of my web browsing just because they host popular JavaScript libraries or web fonts. I'm intrigued by this comment: In general, we cannot block the Referer header by default on cross-origin requests because we know that would break too many websites. Is this because some of the third party resources are only authorised for use by certain sites and rely on Referer to establish whether a given request qualifies? Given that there is no security or verification for Referer headers, that seems like a rather broken model to start with. I can't help thinking that if one of the big browsers forced the issue then those services would have to reconsider and do things a smarter way. That seems likely to inherently reduce the amount of unnecessary information being passed across to those third party services in the first place.
- ubercow13 14y agoIs this not what you want? Third search result: https://addons.mozilla.org/en-US/firefox/addon/smart-referer/?src=search https://addons.mozilla.org/en-US/firefox/addon/smart-referer...
- Silhouette 14y agoSorry, you're right. I think I forgot to misspell "referrer" the first time I searched.
- ubercow13 14y agoAh I didn't even know that was a thing. I think I am so used to the misspelling that I didn't even realise - the only place I regularly come across the word is in reference to HTTP. Here for anyone who didn't know: http://en.wikipedia.org/wiki/HTTP_referer#Origin_of_the_term_referer http://en.wikipedia.org/wiki/HTTP_referer#Origin_of_the_term...
- ben0x539 14y ago> Is this because some of the third party resources are only authorised for use by certain sites and rely on Referer to establish whether a given request qualifies? Given that there is no security or verification for Referer headers, that seems like a rather broken model to start with. It's just a first-order approximation to defend against hotlinking. Disabling referes wholesale has mostly worked out for me (via about:config, not an extension), but very rarely I have to turn them back on or switch to a backup browser profile or whatever.
- Silhouette 14y agoBut if you're linking to an image on your own site from your own site, the proposal not to send Referer headers across domains to third parties wouldn't do any harm. In other words, if your interest is in blocking unauthorised hotlinking, can't you just assume anyone who doesn't include a Referer is equivalent to someone sending a Referer from a malicious site and decline the request?