IIRC, there are issues with leaking URLs just as with OCSP lookups. So it's more privacy related than security. I was in a hurry when I typed that earlier. But if you think about it, there's still a chance of sending company internal URLs to a third party which given enough data would start to build up a view of the intranet. We have no idea if google then feeds this into their crawler to get more of the hidden web and if there is a misconfiguration elsewhere would then cause results to be publicly visible. See posts about visible printers etc. in the last couple of days.