Firefox 87 trims HTTP Referrers by default to protect user privacy
blog.mozilla.org
blog.mozilla.org
https://developers.google.com/web/updates/2020/07/referrer-p...
So if this breaks something people probably already noticed. And Mozilla is merely aligning with the browser with the largest market share on this. (Also everyone who wants something different for their sites, it's configurable: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Re... )
But overall I'm all for getting rid of it. It's a remnant of the early web that doesn't make a lot of sense these days, and creates more problems than it solves.
EDIT: Although I just realized that strict-origin-when-cross-origin (the new policy) would still let the hotlinking detection use case work, since you typically only need domain information for that. I initially thought that they would use same-origin or something like that. It'll teach me to comment before I read the linked story.
Using the referrer header as a security and privacy measure is prevalent among service providers. Vimeo even hilariously charges for this feature which is trivially bypassed; and I'd reckon their paying customers aren't even aware of it: https://vimeo.zendesk.com/hc/en-us/articles/224819527-Changi...
Talk about smoke and mirrors.
If so then please mark your link up as NSFW/NSFL.
I hate sharing Amazon shopping links because Amazon packs much referrer as possible in the link. Amazon uses the referrer to track who am I sharing to and use it for data for them to sells.
How can you tell it's Monday morning on HN?
Someone starts pontificating, "I don't use this, so there is no conceivable reason that anyone else on the planet should ever need this ever!"
See also: Half of StackOverflow questions.
Which very well might be true, but that was exactly the question: who?
I don't know how commonly it would break that flow, but it certainly could depending on implementation details that are not narrowly prescribed by the OAuth2 spec.
How? Referrer can be easily spoofed.
For example you might not know that important site X linked to you and is driving Y% of your audience. You are not necessarily interested in the individuals following the links when you discover that.
I thought, wait, but how is this feature in my own app still working with chrome then! Aha, Chrome only trims referrer for cross-origin requests.
Is FF the same?
Looks like... yes! "…will also trim path and query information for all cross-origin requests."
Whataboutism re: corporate control of web standards.
Does this mean Gmail can stop rewriting links in emails (ostensibly to derefer)?
The only reason I can see Google still doing rewriting is to protect very old browsers and laziness.
/s ?
/s ?
Given that Firefox improving privacy generally doesn't draw antitrust scrutiny, where is the problem with that statement?
>The questions from Justice Department investigators have touched on how Chrome policies, including those related to cookies, affect the ad and news industries, four people said.
Investigators are asking whether Google is using Chrome, which has 60% global market share, to reduce competition by preventing rival ad companies from tracking users through cookies while leaving loopholes for it to gather data with cookies, analytics tools and other sources, the sources added.
https://www.reuters.com/article/us-tech-antitrust-google-exc...
If Google were truly improving privacy, one would expect their changes to decrease their own ability to track users, not just their competitors.
(not that firefox doesn't have lots of phone-home behavior you can't turn off like firefox.settings.services.mozilla.com)
1. Chrome, as the dominant browser, drives developer behaviour (devs need to change their websites when Chrome breaks compat). Firefox doesn't have this luxury, so some features like this must necessarily be lead by Chrome in the monopolistic browser world we live in.
2. Referers allow websites to individually track users better, which is bad for user privacy if you are concerned about entities such as Facebook, etc. tracking you. However, those entities are Google's competitors; for Google, Chrome does the tracking, so they have no need of the Referer.
Removing it is "good" for user privacy w.r.t. Google's competitors, and simultaneously good for Google (disadvantaging such competitors).
It's a web browser.
I myself religiously use Firefox by default and only use Chrome if I bump into some websites don’t work in Firefox. But my kid’s teachers often send links that my kid needs to use for school work. And a lot of them are educational websites that don’t work in Firefox. I can’t be home all day to provide tech support. So having Firefox as the default browser is simply a no-go. Guess what wins, between Chrome and Firefox?
I read a lot of people saying this, but I use Firefox and I don't run on this issues, except when I land by accident on some weird dark pages (mainly porn pages)
As developer, I develop on Firefox, and sometimes do a quick test on Chromiun/Edge/Chrome to see if something it's break or bugged on Chromiun/Edge/Chrome web engines.
I'm a happy Firefox user too, but I don't want to believe that Firefox is the only browser that cares about user privacy.
I don't either, but I don't believe HN users praising Chrome is going to help with that situation...
I'll happily celebrate Google making a privacy-oriented change that's actually intended and not a bi-product, but this isn't such a case.
And how does Mozilla make money?
Out of Chrome and Firefox, one is one big level of indirection further away from Google's influence than the other.
Mozilla Foundation is purely a donation-fed nonprofit, and most things you associate with "Mozilla" are made by the Mozilla Foundation. In fact, even Firefox itself — the open source project — is made by the Mozilla Foundation.
Mozilla Corp is just a company that employs engineers to work on Firefox. (I.e. their job is to be ordinary FOSS contributors to the project.) Those engineers might have a profit motive to do things Mozilla Corp investors/shareholders like, but that's fine, because those engineers mostly aren't part of the Firefox steering committee. The Firefox steering committee (along with all other Mozilla projects) is composed of people who are employed by the nonprofit Mozilla Foundation; and/or FOSS people external to Mozilla as a whole.
(ETA: fixed the names. I originally called Mozilla Corp "Firefox Corp" — and it really basically is, as Mozilla Corp doesn't employ people to work on anything other than Firefox. IMHO "Firefox Corp" would be a strictly-better name for it.)
From Wikipedia: "Mozilla [...] is a free software community founded in 1998 by members of Netscape. [...] The community is supported institutionally by the not-for-profit Mozilla Foundation and its tax-paying subsidiary, the Mozilla Corporation."
There's three entities:
- Mozilla Foundation: accepts donations and spends them on web initiatives, does not spend them on Firefox
- Mozilla Corporation: is owned by Mozilla Foundation, employs Firefox devs, has search deals with Google
- Firefox software: is developed by Mozilla Corporation, is funded by search deals
[0] https://www.investopedia.com/articles/investing/041315/how-m...
Many people are a bit shocked to learn Mozilla Foundation does not fund Firefox. Firefox is funded by search deals (mostly by Google); Mozilla spends donations elsewhere.
Source?
In the event that such behavior would occur, it can be detected by sniffing your packets, and people would very soon speak about it.
1. https://www.forbes.com/sites/zakdoffman/2021/03/20/stop-usin...
2. https://specials-images.forbesimg.com/imageserve/6055073241c...
It's accessible even afterwards on chrome://settings/security
However there are many many many sources out there documenting Chrome's comprehensive tracking:
- Google's own ToS is probably too long to read, but it lists ways in which you consent to be tracked by the browser
- Google's proposals to the W3C for adding new ad-tracking tech to web standards go into detail on Chrome's own mechanisms for doing this tracking as a PoC example [0]
- Chrome isn't technically available on iOS; they are forced to use Safari's engine under the hood of iOS Chrome, which restricts in some ways the amount of tracking the browser can do. Despite this, the list of data tracked by iOS Chrome is listed on the AppStore download page and IT IS LONG.
Finally, you mention packet sniffing. In actual fact, direct packet sniffing has been made non-trivial by cert-pinning. This doesn't however prevent checking the frequency and destination of app phone-home requests, and yes, Chrome does it a lot. You can see this yourself if you use common user firewall tools such as LittleSnitch/LuLu/OpenSnitch/etc.
[0] https://github.com/WICG/floc#qualifying-users-for-whom-a-coh...
However the link you provided shows that in "Google Activity Controls" and "Google Ad Settings" the user has the possibility to completely opt-out of this tracking.
If privacy-minded users are fully aware of all of these options, that may be fine for them? (spoiler: I was NOT aware of all!)
There are other options in Chrome's settings that may allow you to further opt out of other types of tracking, if you can discover them.
These settings aren't documented simply or centrally by Google and can change with each release (releases are extremely frequent).
Then there are types of tracking that can't be disabled as Google classifies them as "legitimate interest" or required for certain functions of the browser (one particular example here that comes up often is the collection of wifi ssid data for geo apis).
Anything that's on by default will always be unmanageable even by most technical users. We need a browser that doesn't track by default. Otherwise, you must typically assume you are being tracked (this goes for Firefox as well, though I think we can at least assume less data is tracked in firefox and is slightly easier to opt out)
At the time I'm writing this, there are 740 upvotes and 187 comments on this story vs. 12 upvotes and 0 comments for the top submission when Chrome made the same change [1]. Without the FYI, I would have assumed this was Firefox leading the way in privacy because I was simply unaware that Chrome had done it.
For example, I clicked a link on old reddit and saw the full referer being sent to another origin.
This subtle aspect of web had been always strangely appealing for me: people leaving trails in access logs and building real "footpaths" network of synapses between HTML documents, across origins. Sad to watch it dying, however beneficial and understandable it is.
I feel it didn't have to be this way: maybe if GET wasn't so widely misused recently and generally everybody knew what to not put in URL and acted accordingly, we could have preserved such nice things.
# 1. Apache conf
Header set Referrer-Policy "no-referrer-when-downgrade"
<!-- 2. meta HTML head with same effect [2] -->
<meta name="referrer" content="no-referrer-when-downgrade">
<!-- 3. HTML anchor attribute -->
<a href="https://…" referrerpolicy="no-referrer-when-downgrade">
This will pass full path and query when navigating between HTTPS to foreign origin. I guess it will be lost in http: to https: redirects. `unsafe-url` value would do it even for HTTP.(Funny all three have different spelling, and that in effect they direct value of a single HTTP header with inherently erroneous spelling.)
[1] https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Re... [2] my guess using `<meta http-equiv="Referrer-Policy" content="no-referrer-when-downgrade">` should do the same, but is not explicitly mentioned anywhere. [3] https://w3c.github.io/webappsec-referrer-policy/
And I don't know how you can say it doesn't help privacy with a straight face.
And it would be nice if IP addresses could be hidden but that's a very different topic.
What the changed default does is mean that things fail safely when someone doesn’t think about this at all and builds a site with sensitive info in the URL. In that case, outbound link targets might receive things like usernames or email addresses, information in URL path components, etc. which isn’t intended to be public. Those sites are often poorly supported so the default changing means that the work shifts to a fraction of the web community which is best prepared to deal with the trivial extra work required to set a policy.
I feel that this could easily be a user toggle-able option near the url bar - and that people could choose to send referrer and search parameters to sites they like - and I could understand certain medical terms and what-not maybe people wanting to keep more hidden.
I'm all for the browser taking control of this and giving the users options - love to be able to have the web site detect this and add a box saying 'hey would you mind sharing referral and or search term with us"
It really helps when trying to figure out if you should be adding more content for 'term-mainly-X-demo' might be searching or for sure should be adding more content for other terms people are definitely searching for.
I would imagine that many people would like to hide referrer for fbook, most of my sites I would think people would be willing to help with providing such info.
as far as webmastering and stats to try to help visitors - it appears google is keeping more and more data to themselves, and now firefox is making it less transparent too.
I see there is a link to the referrer policy for your site, but nothing about begging the user to include the info when visiting - oh well.
awstats and similar have helped troubleshoot and helped expand many sites for many years and now another nudge to install third party slow-ware google-stats.. I just, sigh.
No ordinary user wants to deal with that much complexity.
Why can't we have a full featured Firefox hidden behind a setting, so this mythical "ordinary user" can have a dumbed down interface and the rest of us can have a real browser?
For the same reason bank robbers rob banks. That's where the money is. The source of the funding that pays for development of these tools is driving this.
I'm not defending that situation, that's just the way it is. "Hackers" working on what they find technically elegant and useful are not driving these sorts of changes.
Even worked a lot on the help desk, taught in vocational education and held a couple of training courses.
At least around here my evaluation is that ordinary users are a lot more capable than we give them credit for.
Or maybe I'm just insanely good at helping people, or I misunderstand or something else, you choose ;-)
I don't mind right click - save page as.. but feel the secondary menu needed when right clicking on a tab, then hover down to move tab, then another flyout menu for new window is too much. Wish the 'move tab to new window' was just right there one level up.
I feel that people would right click and allow info share right there if requested by some sites. Buried in the about: settings or whatever would never get used.
Google's answer was to just get your site verified and use their search console tools. Annoying, but OK. But then other search engines followed suit which left awstats with a lot of missing data. Now with simplified referring urls... it will mostly be a fancy page counter :/
https://shkspr.mobi/blog/2018/01/mailchimp-leaks-your-email-...
A few years ago, I discovered that referrers from MailChimp let you unsubscribe people from lists, and see their email addresses.
It should be added that the eventual elimination of referers won’t make URLs safe. There are countless other ways they can leak.
> this new stricter referrer policy will not only trim information for requests going from HTTPS to HTTP, but will also trim path and query information for all cross-origin requests.
Seems like a fairly balanced way to protect privacy along with preserving utility?
I remember when my dad studied to become a teacher. As one of their assignments they had to create a webside. As someone who had recently given up farming I think he wrote about farm animals and linked to some other pages about small scale poultry and similar topics.
One day he got a mail from the "webmaster" of one of the sites he linked to that he would have to update his links soon. I remember being really surprised that someone knew my dad had linked to them.
Being only 16 or 17 or something I only knew simple html, basic and vb but I knew that html links were one way.
I don't think I realized until later what had really happened: this person had looked at their server logs to see where their customers came from, looked up the page and found the email address.
Of course this also highlights why the referer is so problematic.
These days 100% of such emails I receive are from spammers trying to steal some google juice.
So we started looking for those more seriously in my company, and got quite a bit of interesting Intel from potential investors, competitors we knew about, and some we weren’t even aware of.
It was just the subject and user, but was often surprisingly informative.
I can't sniff it (Wireshark) as I don't have that sort of access to a network with Outlook on. I've googled but didn't find anything useful.
If I walk into a shop, the shopkeeper doesn't know if something in the window caught my eye, if my friend recommended the helpful staff, if I saw the advert they placed on a billboard, or if I just came in because it's raining.
Except that's already here, or in the making, i.e. with those advertising eye-tracking stories that make the rounds every 6 months or so.
A lot of places will attach unique discount codes to advertisements to get an idea on where you came from.
For example, on a TV commercial it might say use promo code COOL123 to save 10% or if you saw that billboard it might say to use NICE123 instead. Then there's radio, newspapers and so on each with their own unique code that offer the same 10% discount.
And since a discount is applied chances are you'll use it because not too many folks would purposely avoid the discount to hide where you discovered the shopkeeper from.
You often see this being done online too, but there's also things like UTM tags or unique URLs that let you do the same thing without discount codes. It's not to make more money as a shopkeeper (avoiding the discount), it's just easier to set up. Using a UTM tag is a matter of creating a link with a few query parameters. Creating a specific discount code or a unique URL for a specific promotion takes a bit of extra leg work.
I'm not sure where I stand on the movement to remove all forms of referral tracking. Both referral headers and UTM tags can be spoofed or removed through extensions so using them as any type of source of truth was a bad idea anyways.
However, as someone who sells digital products I like knowing which specific video or blog post helped someone discover some of my paid content. But at the same time, the end game is really "is the needle moving forward?" so the specifics kind of don't matter. But in the short term while you're figuring things out, the extra info does help you focus on where to spend your time. Not just for more profit, but to provide better and more free content because it's what folks want.
Bur given the unique personal searches/browsing I could have just been doing, I sure the heck don't want my recent activity advertised to the next site I go to. Happy as a clam to shut down all the Referrer uses, even whatever login flows that might have to re-engineer themselves.
But the shopkeeper knows if you came in through the street entrance (maybe saw the window display), through the mall entrance (maybe saw the sandwich board), or through the communicating door to the next shop (maybe saw the merchandise).
Otherwise you need video cameras and AI... or perhaps spray every incoming customer with a source-identifying powder or smell - hmm, maybe that explains Abercrombie & Fitch!
People are usually happy to tell us; but then we only use that information to run our business better, we don't sell it.
Another technique is referral bonus, "recommend a friend" type offers.
Google has had a dereferral process in place for many years anyway, which prevents you from seeing the specific search engine results page the user is coming from. So this really doesn't change anything for those websites such as Google that already had these security features in place.
Is this really a security feature though? Or is it Google keeping the important information for themselves?
If you want keyword information from Google search results, the best way to get it is actually buying ads for those keywords. And in fact some marketers allocate ad budget to keywords they already rank for, specifically for that purpose.
Besides it's up to a user whether they want to tell you where they came from, you aren't supposed to know anything, you are allowed to.
https://addons.mozilla.org/en-GB/firefox/addon/clearurls/ in case anyone else has also not seen it.
Kindly, and non-intrusively, ask them? You know, just like in other aspects of life?
Now the website has to do something explicit to share information (beyond the hostname) to outbound cross-origin outbound links. It is much more likely that the website will pay attention to what information they are sharing in this case.
TL;DR about:config --> Network.http.sendRefererHeader --> change value from 2 to 0
In my testing, all recent versions of Safari on iOS were the worst offenders here. I talked more about this here: https://twitter.com/arbuge/status/1354805900268105743
You would think that Safari would jump at the chance to show no referrer, given Apple's attempts to position themselves as champions of user privacy, but for some reason the opposite is in fact true.
But the web was a much smaller place/time back then.
Oh, and seeing people search for my uncommon name...
Commenting in support of Chrome's proposal to freeze the user agent and provide UACH instead.
The server shouldn't get information about the client.
Unsurprisingly, UACH is spearheaded by an ad tracking company that benefits from a moat caused by minimally viable/workable browsers costing millions of dollars and dozens of developers to implement.
It's not. The header gives up all information by default. UA-CH works by request-only, and allows the browser to determine how much to send. This is easily controlled via native settings or browser extensions.
The API also requires a secure connection, and specifically forces the server to admit to any fingerprinting (or legitimate use-case of data otherwise).
[Referer]... allows the client to specify, for
the server's benefit, the address (URI) of the resource from which
the Request-URI was obtained. This allows a server to generate lists
of back-links to resources for interest, logging, optimized caching,
etc. It also allows obsolete or mistyped links to be traced for
maintenance.
The idea of how a user benefits from sharing it was that it would help the webmasters upon whom they were reliant to do a better job of curating their websites. It clearly expects a benevolent relationship between the owner of the linked site, the host of the link, and the user. Idealistic, sure, but understandable in a collaborative, academic context.But why don't thet kill the referer header entirely? Mozilla's attempts at protecting user privacy seem very half-hearted.
Compatibility, probably. There are some sites which fail to load or end up in redirect loops if the Referer header is missing. It's not just minor sites, either. The last time I tried blocking Referer headers—just the third-party ones—it broke Google Hangouts (both the Chrome extension and the web version). That was earlier this year.
That is because they are. Mozilla cannot survive without internet advertising, and they sacrifice the privacy of Firefox users in exchange for funding from an advertising company, Google.
Anyone who is serious about internet privacy knows it requires some amount of vigilance. It necessitates some amount of inconvenience. It is not simply a matter of software selection. AFAIK, no third party today is going to take on full responisibility for any user's privacy. You never see Mozilla advocating for user vigilance, yet the fight for internet privacy is the user's, not Mozilla's. The message from Mozilla is something like "If you use Firefox, we have you covered." This encourages inaction more than action. That's good for companies like Google.
If Google paid a group of users the millions it pays the group working at Mozilla, I doubt those users would care one iota about "privacy". Their own, or anybody else's. Why bite the hand that feeds you.
I only send Host and Connection headers for GET and Host, Connection, Content-Length and Content-Type for POST. For me, this works beautifully for 100% of websites posted to HN, and elsewhere on the www. I can easily create exceptions in the forward proxy configs to send Referer to sites that require it. This never happens, IME.
- more difficult to analyze weird / fraudulent embedders
- more difficult to debug issues ("what's the sample URL to repro? no sample URL in logs, only top-level of the domain, but I don't find our embed anywhere ¯\_(ツ)_/¯")
Funny thing: you can't just tell your embedding partners to change the embed code and use `referrerpolicy=...` on the iframe, to expose the full URL, because it's not GDPR-compliant apparently. So you need user's consent first. But how do you obtain user's consent before you render HTML on the server? :) ("GDPR wall" is not compliant either)
Life sucks, I guess. But it's for greater good, and I guess the companies will somehow survive.
> Back button is sometimes disabled in Firefox
for me when I click on a Medium (or similar) link. However I think this is related to containers. It's really annoying, but I'd rather just avoid Medium that abandon Firefox.
It's only when the target website needs the full source URL (with path and GET parameters) that you may encounter issues.
Power usage for same streaming video call on Safari vs. Firefox.
I guess I'll ask a colleague at work.
Not exactly what the actual risk is to privacy here does seem there is a lot of bandwagon jumping going on - a bit like "Elf & Safety" or the Data protection act is trotted out when an organisation wants an excuse not to do something.
If you want to do tracking and have control over both pages, just use a different URL, a query string, or something like that.
e.g. here's the page that Firefox generates when I try to search "Dragon Quest XI" in a Private Window on Amazon via the address bar:
https://www.amazon.com/s?k=dragon+quest+xi&link_code=qs&sour...
Note the 'mozilla-20' tag at the end.
Is there any story about anyone affected by the issue? Does this issue even exist?
It is just breaking another piece of the open web.
It just seems like Mozilla not only surrendered in gaining browser market but also actively acts against open web.
I thought website creators and website users should be in charge of what they want to do. But it seems no. Now Mozilla decides what web standards can be broken.
I'd maybe applaud changes by Mozilla, but with all of these efforts it is not aimed in gaining more users. Firefox does not gain users with such actions. It does not make any sense what is the aim of Mozilla anymore with Firefox.
Yes. Yes it does.
Imagine, a web site that has a query parameter with a secret (password reset pages, email unsubscribe, custom feeds, etc). Any images or other assets used in the page will receive the full URL as the referrer, so they can see those secrets.
GitHub fixed this very issue a few years ago. They have a feature to get custom RSS feeds for user activity. There is a secret worry parameter in the URL, and any third party images were receiving that full URL.
Referrer-Policy header is already supported in many browsers.
They are switching to strict-origin-when-cross-origin, which cuts the referrer down to just the origin when navigating to a different origin.
So not sending referrer has always been fine, and I suspect that firefox will have an option to enable the sending somewhere in it.
This is useful for site owners, and they have little control over what browser their users use.
And as someone else already pointed out, the other big browser (Chrome) has already done this.
Imagine that the URL contains a search string that contains something the user might deem private, or the article is about something a state may deem to be illegal, etc.
This may not be PII but it could be deemed private by the user. The user should be in control of what information could be given to a website. Imagine a scenario where a person is a member of a group that is looking for equal rights in a country that is very much opposed to this. The group uses a tool that happens to make it clear who this group is. The group then links to an article about their cause or similar. Now that country could potentially link things together and demand information about everyone in that group.
It's amazing how little bits of information about you can get you in hot water.
This is a good move imo, and I'm glad that Mozilla is trying to plug these types of things. It's better for everyone.
As an aside, moving to a privacy oriented browser could very well get Firefox more users. Just like Apple's play to being a private and secure mobile OS is getting them users.
You should try to come into these conversations with a lot less attitude. Perhaps I'm reading your tone wrong, and if I am I'm sorry about that.
I always come into these discussions assuming I'm not the smartest person in the room because that means I have more to learn. Maybe give that a try?