Hacker News new | past | comments | ask | show | jobs | submit login

Actually... the browser won't send a referer to a HTTP site if coming from HTTPS. From the RFC: http://www.w3.org/Protocols/rfc2616/rfc2616-sec15.html#sec15...

"Clients SHOULD NOT include a Referer header field in a (non-secure) HTTP request if the referring page was transferred with a secure protocol."

I wonder if Google will implement POST forms instead of GET to prevent caching of request-uri data by the browser as well as proper Cache-Control/Pragma/Expires headers to prevent caching of search results.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: