3 ms·
So this will totally break any deeplink protection. Where deeplink protection by referer checking (where an empty referer will allow the resource to be download
by rgj 12y ago
So this will totally break any deeplink protection.
Where deeplink protection by referer checking (where an empty referer will allow the resource to be downloaded as well) was always effective enough since the web page author had no way to control the browser’s or users choice of sending a Referer header or not, now the author of a web page that is deeplinking resources is simply able to prevent a Referer header being sent, circumventing the protection mechanism.
- hyperpape 12y agoIs there a reason why deep linking protection is good? I know there are arguably reasons why a site owner might want it, but any that make it so I should care?
- icebraining 12y agoNot sure about deep linking, but hotlinking protection is quite important if we want to enable people to self-host their content (pictures, videos, etc) instead of centralizing everything on Youtube and such. I run a small forum which hosts photos uploaded by its users, and some guy (not even a member) decided to use one of them as his signature on another forum (orders of magnitude larger). He killed half of our monthly traffic cap in a couple of days, until I mod-rewrited hotlinked URLs to a disturbing image :D EDIT: That said, a better anti-hotlinking mechanism, which wouldn't violate the user's privacy, would be to have a response header whitelisting the domains in which the resource could be embedded from. If someone were to hotlink an image, the browser would simply refuse to show it.
- IgorPartola 12y agoYour solution wouldn't help: my browser would still request the image from your server, and you'd have to send me at least the headers. That in itself could kill your traffic cap. Instead, my request should send you the domain on which I want to display the image, and then you can give me a 400 error.
- icebraining 12y agoInstead, my request should send you the domain on which I want to display the image, and then you can give me a 400 error. But that tells me that a browser with a certain IP, user-agent and possibly even cookie ID is accessing a certain third-party site. I shouldn't have that information just because my image was hotlinked in that site. And while my solution does still consume traffic, the idea would be discouraging the hotlinking in the first place. Why would anyone keep my image hotlinked if it didn't work?
- mbrubeck 12y agoNote that this is already broken in various cases, like when navigating from an HTTPS page to an HTTP page.