[0] http://www.stardrifter.org/refcontrol/
The web wasn't built with privacy in mind. 3rd party cookies and HTTP Referers are just the low hanging fruit.
[0] http://www.stardrifter.org/refcontrol/
The web wasn't built with privacy in mind. 3rd party cookies and HTTP Referers are just the low hanging fruit.
I suppose one might consider their previous url private information, but if that's the case you've go a lot more to worry about than http referers.
URLs aren't protected any less than cookies are, and cookies are the standard way of securing login tokens.
Heck with URLs you get the 'secure flag' cookie option for free!
The general default behaviour has always been to let an http server know where you're coming from so that it can take whatever actions appropriate. I don't see how or why there is a fundamental violation of some "browsing privacy" rule here.
As for why it's still that way... I'm sure no one has bothered to really think about it since.
> Clients SHOULD NOT include a Referer header field in a (non-secure) HTTP request if the referring page was transferred with a secure protocol.
FWIW, the web would survive without Referer, but it is genuinely useful to site owners, especially in aggregate. Maybe a compromise would be to trim it to just domain rather than full path?