HTTP Referer Security Considerations

Dec 24

HTTP Referer Security Considerations

HTTP/1.1: Security Considerations: Regarding my earlier post about the Outlook Web Access privacy issue, here’s what I found about HTTP Referer headers in the HTTP 1.1 spec (RFC 2616):

Because the source of a link might be private information or might reveal an otherwise private information source, it is strongly recommended that the user be able to select whether or not the Referer field is sent. For example, a browser client could have a toggle switch for browsing openly/anonymously, which would respectively enable/disable the sending of Referer and From information.

That would be a great feature, but as far as I know, no browser offers this.

Clients SHOULD NOT include a Referer header field in a (non-secure) HTTP request if the referring page was transferred with a secure protocol.

This may mitigate some of the problem with Outlook Web Access, because a lot of those systems will be using SSL.

Authors of services which use the HTTP protocol SHOULD NOT use GET based forms for the submission of sensitive data, because this will cause this data to be encoded in the Request-URI. Many existing servers, proxies, and user agents will log the request URI in some place where it might be visible to third parties. Servers can use POST-based form submission instead.

Another good point, which I mentioned in my earlier post.


Comments

by ,   December 25, 2003 1:02 AM  

The Opera browser can toggle referrer logging very easily.


by Trond,   February 20, 2004 12:31 PM  

"That would be a great feature, but as far as I know, no browser offers this."

The Opera browser has exactly this kind of feature. You can download a free version at http://www.opera.no and choose to disable referer logging (file -> preferences or file -> quick preferences) ;)


by Pink,   December 28, 2006 8:25 AM  

Hi, people!! Great new site about shaved teen! The youngest, freshest and hardest porn for FREE! Updates Everyday! girls shaved sleeping Best porno pics and video !!! All category, millions movies and photos !!!


by ,   February 15, 2007 8:59 PM  

Pity Opera is a generally shitty browser...



Add Comment


Want to advertise on this site? Contact FM.
Laser Toner Cartridges UK laser toner, toner cartridges, hp toner, lexmark toner, samsung toner, canon, toner, epson toner, oki toner, kyocera toner, xerox toner, remanufactured toner, compatible toner
Direct TV Deals Free 4 room direct tv deals. no equipment to buy. free fast professional direct tv installation. this is the best direct tv deal available anywhere.
SEO Article Learn from the experts with our SEO article.
rope light Shopping with birddog distributing, inc., gives you access to the lowest prices, the best customer service and the quickest delivery times possible.
Laptop AC Adapter We offer genuine factory direct replacement AC adapters.
Direct TV Best satellite TV deals.
Direct TV Deals Direct TV programming deals are varied and include packages containing from 50 channels up to over 250 channels.
8mm film to DVD Retain family memories with the only frame by frame digital restoration service in the United States for your 8mm film to DVD today
Rubber Stamp Shop for custom self-inking stamps, hand stamps, address stamps, label stamps, check endorsement stamps, check deposit stamps, date stamps, pre inks, pocket stamps, ink and much more!