Sourcebuster.js
sbjs.rocks
sbjs.rocks
We have to stop this non-sense, and stop calling this « innovation »
Profiling visitors based on their referrer to —quoting TFA— "show relevant content" is exactly this sort of creepy nonsense that leads to you (store owner) knowing where I do my research and being able to infer more about me than I've explicitly told you.
We're arguing slightly different things. Sure, guns don't kill people. Referrer as an aggregate statistic, on its own is pretty harmless. This script doesn't even phone home on its own.
But it's what you do with that data. How you collect it. What you collect with it. How you aggregate, or infer from it. Modern sales funnelling and marketing is all sold around targeting users. That's what this all feeds into.
Also, I don't think you can equate this with guns.
Try equating it with metal. Yes, you can make it into a gun, but you need to have lot of different things in place before you can use it to do harm.
Referrer data is completely anonymous. If you want to combine it into a profile, you need layers and layers of complexity and other data before you have something you can use it to target users based on their interests. With GDPR, this is illegal without consent anyway so I think you're overreacting.
Nobody has yet died due to some programmer carelessly not having 'noreferrer' set in the 'rel' attribute of a link that opens in another tab but, if you want to get 100% on Google's Lighthouse audit tool, then it really does matter.
The Google article is worth the read as it makes it clear that the oft-cited rel="noopener noreferrer" is wrong. The thing is that 'noreferrer' is a superset of 'noopener' so you only actually need rel="noreferrer" without the 'noopener' bit.
The 'opener' said no to is 'window.opener' in Javascript. This probably was brilliant in the days of frames and has lurked in the specs ever since.
https://developers.google.com/web/tools/lighthouse/audits/no...
See: https://en.wikipedia.org/wiki/HTTP_referer#Referer_hiding
<meta name="referrer" content="origin">> Your source is news.ycombinator.com
Though it is noted in the usage:
> When a visitor come from https web-site to http, a request doesn’t have a referer.
Or is this just Firefox kicking ass?
No, I clicked a link from 2 different domains (my rss reader and here) - so that means my browser privacy addons work? :)