Hacker News new | past | comments | ask | show | jobs | submit login

> The actual solution is to never send Referer headers for cross-site requests from an HTTPS page.

That should be on someone's todo list at the major browser vendors. You're right, there really is no point in sending that header along, and sending it can cause all kinds of trouble.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: