Live data from Hacker News

Firefox 59 to strip path information from referrer values for 3rd parties

blog.mozilla.org

191–200 of 236 posts

Re: Firefox 59 to strip path information from referrer values for 3rd parties

#191

Earlier quoted context omitted.

In all seriousness: why should we care what ad companies want? Mozilla makes a browser, not an ad platform. Advertisers may have to adapt, but that's their problem.

In my opinion Mozilla should be actively hostile to ad companies, and go out of their way to ruin metrics

I don't think that's a good tactic. Google and other ad companies have plenty of money to spread disinformation against Mozilla, if they wanted to.

If Mozilla's users are saying “yes, this is good; please do more”, Mozilla can use that as a defence against any resistance from advertisers.

Re: Firefox 59 to strip path information from referrer values for 3rd parties

#192
post #188

#1 this should be on by default. I might be missing something, but do sites really need the referrer? What would break if the browser sent the same page as referrer, or google.com/ or something similar? Is there any value in the referrer to the client ? The host can use it for a whole range of reasons - but apart from helping the host, what is the immediate benefit to the client? #2 Won't this be possible to bypass s…

You're right about subdomains but they are stripping both query and path, so 123.a.b.tld/foo would become 123.a.b.tld. It's fair to assume most misplaced sensitive data will be in the path or query, rather than the subdomain.

I didn't even think about the subdomain until I saw the image that is in the article here - which literally looks like it added an arbitrary number in the subdomain, duplicating the parameter number! When I saw the image I thought the article was actually about blocking some shady way of leaking that doubleclick had invented.

Re: Firefox 59 to strip path information from referrer values for 3rd parties

#193
post #186

#1 this should be on by default. I might be missing something, but do sites really need the referrer? What would break if the browser sent the same page as referrer, or google.com/ or something similar? Is there any value in the referrer to the client ? The host can use it for a whole range of reasons - but apart from helping the host, what is the immediate benefit to the client? #2 Won't this be possible to bypass s…

To answer #1, the referrer could probably be used to make a link refer to a login page on another domain, and to then let the host redirect to the correct page after login. There are of course ways to do this by following your suggestion #2, but I suspect this might be why we originally had the referrer header.

Third party logins are definitely a use case. But you'd think that they would aim to do it with logins.somewhereelse.com/?u=source instead of relying on the referrer field as the source to go back to! I wonder how common actual use of referrer is?

Re: Firefox 59 to strip path information from referrer values for 3rd parties

#194
post #175
post #121

Earlier quoted context omitted.

If I can go through your underpants drawer then I'll know the right kind of underpants to try and sell you. That means it's OK, right?

(Tangent, but I’ve never found this particular example compelling. All that’s in my underwear drawer is underwear... and I don’t find that particularly embarrassing? I think I’m missing some cultural context for it)

In the US, at least, the underwear drawer is a popular place to hide other things ... eg, your illegal drug stash, or the engagement ring you bought, etc. I think there's also subtextual implications of nosing about in your sex life.

Re: Firefox 59 to strip path information from referrer values for 3rd parties

#195
post #174

Earlier quoted context omitted.

Sites should be penalized for giving preference to one kind of link over another. Why should Google have even more of an upper hand than they already have? To me this is a super good illustration of why we probably should get rid of the 'Referer' (sic) header altogether.

Agreed, but the short-term loser of this change is the non-technical customer who's workflow is suddenly broken, and only in Firefox, and only in version 59. Apparently only in Private Mode though which makes my use case probably less common. Thing is, do you remember the uproar about addons being broken in Firefox 57? It was for good (security) reasons but many non-technical users don't understand or respect the pro…

Even I as a technical user saw my workflow broken and to this day it hasn't been resolved. So point taken. Also: I'm not convinced that the FF57 reasons were as good as stated, it seemed mostly a case of 'we can therefore we do and here are some reasons to make you feel good'. A backwards compatibility switch to override the change would have been the least.

Only Microsoft seems to really understand backwards compatibility.

Re: Firefox 59 to strip path information from referrer values for 3rd parties

#196
post #151

Whoah, TIL that > EFF researchers discovered this leak of personal health data from healthcare.gov to DoubleClick It blows my mind that a site such as healthcare.gov would include 3rd party trackers. You guys in the US really don't care about privacy at all.

This is largely the part of independent contractors and subcontractors. Contracts go to the companies good at winning contracts, not necessarily the best company to do the job. The contractor takes an obscene profit for providing no value and then subcontracts the project to various subcontractors who may or may not employ actually qualified and skilled engineers. The government employees managing the contract typica…

What of the story that there was later a good team who turned it all around (https://www.theatlantic.com/technology/archive/2015/07/the-s...). It just one article, but I had heard something about the team also working successfully on other government projects. Doesn't rule out mistakes/lack of incentives going forward, but I'm certainly left with a good impression of them.

Re: Firefox 59 to strip path information from referrer values for 3rd parties

#197

This one of the reasons I tend to flip completely whenever I see healthcare providers and their suppliers run google analytics tags inside their logged in areas (yes, this really happens). Besides the questionable value of having such tracking inside the logged in areas (it's healthcare, they are not going to worry about their conversion rates) such information should simply never leave the premises. Better still if…

> it's healthcare, they are not going to worry about their conversion rates

Monitoring conversion rates can be used to find out whether people are actually able to use your web service. The goal of a “conversion” doesn't have to be a sale.

But I agree that if you're going to do this sort of tracking, it definitely needs to be private.

I hope there's a court case soon where the court rules that sending a whole load of business-sensitive data to Google, Microsoft and Apple actually does breach a non-disclosure agreement.

Re: Firefox 59 to strip path information from referrer values for 3rd parties

#198
post #151

Whoah, TIL that > EFF researchers discovered this leak of personal health data from healthcare.gov to DoubleClick It blows my mind that a site such as healthcare.gov would include 3rd party trackers. You guys in the US really don't care about privacy at all.

This is largely the part of independent contractors and subcontractors. Contracts go to the companies good at winning contracts, not necessarily the best company to do the job. The contractor takes an obscene profit for providing no value and then subcontracts the project to various subcontractors who may or may not employ actually qualified and skilled engineers. The government employees managing the contract typica…

TL DR of what you wrote is basically Government doesn't know what it is doing and can't be bothered to change. If that is the case I doubt if there is anything you do can change that unless you held Government accountable for it.

Re: Firefox 59 to strip path information from referrer values for 3rd parties

#199
post #151

Whoah, TIL that > EFF researchers discovered this leak of personal health data from healthcare.gov to DoubleClick It blows my mind that a site such as healthcare.gov would include 3rd party trackers. You guys in the US really don't care about privacy at all.

This is largely the part of independent contractors and subcontractors. Contracts go to the companies good at winning contracts, not necessarily the best company to do the job. The contractor takes an obscene profit for providing no value and then subcontracts the project to various subcontractors who may or may not employ actually qualified and skilled engineers. The government employees managing the contract typica…

You're not wrong - there are a lot of crappy contractor teams out there working for the government... just like in the private sector.

But I've never seen a gov. contractor purposefully add analytics code.

It's far more likely that one of those free frameworks, ui-kits, or fonts, benevolently provided by one of the privacy-invading Silicon Valley behemoths, ended up in the code base.

Anyway, there's a good reason that the government doesn't hire their own developers. Hiring a GS14 (at least), who writes code all day, is going to end up being far more expensive than a contractor after paying the lavish benefits, pensions, etc. which federal employees receive.

Furthermore, most government projects are only a few years long. The government uses contractors because they can get rid of the dev teams when they're finished with the project. Can't do that with gov workers.

Every decade or so, there is a push to use less contracts and hire more in-house Federal workers. And then the payrolls become bloated, and the next administration goes back to less feds, more contractors.

Re: Firefox 59 to strip path information from referrer values for 3rd parties

#200
post #84
post #65

Earlier quoted context omitted.

As a user I don't want you to know that information. I wish there was a way to click on links with the referer field removed entirely from the request(maybe via context menu)

I use RefControl in Firefox. I've set the default to be the root of the destination site. That is, for example, clicking a link to https://foo.com sends https://foo.com as the referrer.

RefControl is a great add-on, but it isn't compatible with the new Firefox Quantum (57+). https://addons.mozilla.org/en-US/firefox/addon/refcontrol/
Post reply on HN