Any ETA for allowing to block Referer header from being included in cross-origin requests? If I'm on the page that pulls down something from Google Fonts, I see no reason why I should be sharing with Google the URL of the page I'm visiting.
Any ETA for allowing to block Referer header from being included in cross-origin requests? If I'm on the page that pulls down something from Google Fonts, I see no reason why I should be sharing with Google the URL of the page I'm visiting.
I also brought up the issue on Mozilla's dev.privacy mailing list [1] recently. See:
https://groups.google.com/d/msg/mozilla.dev.privacy/wmPzPCdz...
In general, we cannot block the Referer header by default on cross-origin requests because we know that would break too many websites. My proposal is to strip the Referer header down to just the origin + '/', e.g. http://example.org/ instead of http://example.org/foo?search=whatever+you+searched+for.
I think it will be difficult for us to go further than that in the default configuration any time soon (and, as you can see in that thread, there's even some pushback to my extremely reasonable proposal).
Also, I know there is active work happening to bring extra control over the Referer header to Firefox's built-in prefs. This seems to be a little bit in conflict with our "Checkboxes that kill" project so I'm not sure how it will turn out.
Also FWIW, I agree that this is indeed becoming a significant privacy issue. I too don't see why Google or Typekit or some widely used CDN should be gifted a convenient history of my web browsing just because they host popular JavaScript libraries or web fonts.
I'm intrigued by this comment:
In general, we cannot block the Referer header by default on cross-origin requests because we know that would break too many websites.
Is this because some of the third party resources are only authorised for use by certain sites and rely on Referer to establish whether a given request qualifies? Given that there is no security or verification for Referer headers, that seems like a rather broken model to start with.
I can't help thinking that if one of the big browsers forced the issue then those services would have to reconsider and do things a smarter way. That seems likely to inherently reduce the amount of unnecessary information being passed across to those third party services in the first place.
https://addons.mozilla.org/en-US/firefox/addon/smart-referer...
Here for anyone who didn't know: http://en.wikipedia.org/wiki/HTTP_referer#Origin_of_the_term...
It's just a first-order approximation to defend against hotlinking. Disabling referes wholesale has mostly worked out for me (via about:config, not an extension), but very rarely I have to turn them back on or switch to a backup browser profile or whatever.
In other words, if your interest is in blocking unauthorised hotlinking, can't you just assume anyone who doesn't include a Referer is equivalent to someone sending a Referer from a malicious site and decline the request?
Considering it requires whitelisting to avoid weird and hard to diagnose issues, it seems unlikely to be added to Firefox.
1. https://addons.mozilla.org/en-US/firefox/addon/smart-referer...
This feature has been supported in Firefox for a long time, but you have to set it in about:config via the "network.http.sendRefererHeader" integer.
2 = always send
1 = send only to same FQDN (what you seem to want)
0 = never send
IMO this is one of the best bang-for-your-buck privacy configurations. I would love it if Mozilla changed the default from 2 to 1, and at the least, it SHOULD be an option under the Preferences -> Privacy tab.There are no such cases, period. Also, with an exception of dumb content protection schemes (anti-hot-linking), Referrers are used exclusively for tracking purposes and carry zero positive benefits for the users. If Mozilla is in fact "passionate about putting its users first", these headers must go. It is as simple as this.
Referrers are used exclusively for tracking purposes
and carry zero positive benefits for the users.
This is short sighted. Sites can respond to referrers by improving themselves and better adapting to what users are looking for.I run a small site, and we would occasionally get hotlinked by random people searching for images on Google, which would kill our bandwidth caps. If it weren't for referer filters, we'd have to hide any image for unregistered users.
That said, keep just first-party referers would be fine - we'd just block any image request without referer.
1) If you came from a social media site, maybe I'd highlight that particular social sharing option in a share bar, or hide others.
2) In an e-commerce store, maybe Google sent you to some page on my site that isn't really the best for your search term (product discontinued, other better matching product), I can give you a link to that other page. Google isn't necessarily magical in its ability to pick the best page on a site for a specific term. Maybe if you come from a competitor I can highlight some content that compares my product to the competitor's.
3) I've never derived a ton of benefit from it, but some sites will highlight your search term for you on a page. It could possibly also automatically scroll you to a relevant section if it's a long page and what you searched for is an exact match for some subsection.
In general it can be a valuable data point sites can use to improve the end-user experience. That being said, I can't think of anything where the value really outweighs the potential for abuse, but I think saying that it has no value to the user is short-sighted.
You may disagree that is a better experience for you, but you may not make blanket statements that "there are no such cases, period".