Tighter Control Over Your Referrers
blog.mozilla.org
blog.mozilla.org
> Enabled by default in desktop Chrome 21
It means it is likely to be supported by all the major browsers eventually. It means I can assume the implementation in the other major browsers will be fairly close to what I'm seeing right now. And most importantly, I can confidently recommend to my team that we add <meta name="referrer"> starting today.
Some websites require the referrer to work; RefControl allows you whitelist exceptions, and also configure a few different options.
As far as sites which require a referrer header, it has been my experience that these are very few and far between. I get one occasionally and if the content is worthy, I'll briefly disable then re-enable my setting.
Not for everyone, I know, but it works well for me.
https://addons.mozilla.org/firefox/addon/headercontrolrevive...
I run a small forum which hosts photos uploaded by its users, and some guy (not even a member) decided to use one of them as his signature on another forum (orders of magnitude larger). He killed half of our monthly traffic cap in a couple of days, until I mod-rewrited hotlinked URLs to a disturbing image :D
EDIT: That said, a better anti-hotlinking mechanism, which wouldn't violate the user's privacy, would be to have a response header whitelisting the domains in which the resource could be embedded from. If someone were to hotlink an image, the browser would simply refuse to show it.
But that tells me that a browser with a certain IP, user-agent and possibly even cookie ID is accessing a certain third-party site. I shouldn't have that information just because my image was hotlinked in that site.
And while my solution does still consume traffic, the idea would be discouraging the hotlinking in the first place. Why would anyone keep my image hotlinked if it didn't work?
And also let me enforce my own setting.