KBD

Keith Devens .com

Tuesday, December 2, 2008 Flag waving
whether or not it is clear to you, no doubt the universe is unfolding as it should.... – Max Ehrmann (Desiderata)
← RenamingArnold gets it done →

Daily link icon Wednesday, March 3, 2004

Mozilla sidebar sends referrer header

I was annoyed recently when I discovered that the Mozilla/Firebird/Firefox sidebars send referrer headers when you click on links in them. In fact, they don't send the referrer as the page loaded in the sidebar, but as the page loaded in the main browser window! That seems to me to be a pretty big privacy problem, since other sites you visit can see whatever page you're browsing if you happen to click on a link in your sidebar. It can even be a security hole if session ids are in the URL (as they never should be, but that's another issue).

There's a bug filed for this exact issue, bug 226548. Bug 122668 is a semi-related bug. Judging by this original bug, bug 137342, it seems that this has been a known bug for almost two years, at least, with no sign of getting fixed soon. I'd like to poke around in the source code, but I have no clue where to even start looking.

It seems there's a preference to turn off referrers altogether, so I may just use that. But it's a shame to have to go that far to fix this one broken feature.

user_pref("network.http.sendRefererHeader", 0);

0 = do not send header information
1 = send only clicks
2 = enabled

(about:config is your friend.) Though, I'm not sure what the difference between 1 and 2 are. Ahh, 2 sends on image requests and such.

Hmm... also see http://refspoof.mozdev.org/

Update: The nice side-effect of this is that now I stop getting annoying referrers when I use my javascript bookmarklet to post to my bookmarks collection (which I'll be making public in a few days once I get a few more features -- such as renaming -- into it).

← RenamingArnold gets it done →

Comments XML gif

John Witchel (http://www.browsercam.com) wrote:

Hi,
I'm trying to find a user_pref to disable the sidebar altogether so that when the browser launches, it's always closed.

Your httpreferr problem seems to lurk close, so perhaps you know something. Any ideas?

Thanks
john

∴ John Witchel | 22-Mar-2004 6:03pm est | http://www.browsercam.com | #4204

Keith (http://keithdevens.com/) wrote:

John, just hit the X in the upper right-hand corner of the sidebar. If you close the sidebar and close the browser with the sidebar closed, the next time you open the browser the sidebar will remain closed.

Keith | 22-Mar-2004 10:32pm est | http://keithdevens.com/ | #4205

Feel free to post a comment below. Please see my comment policy.

Formatting Rules (No HTML):

  • **bold**, *italic*, _underlined_, --strikeout--
  • "text"="url" creates a link, and URLs are auto-highlighted
  • Blockquote: Like e-mail, begin paragraph with > (greater-than sign)
  • Lists: begin paragraph with *,-, or + (unordered), or # (ordered)
  • Code block: ?!code:language=perl|php|sql|javascript|etc.{\n}...{\n}?!/code

:
(will be your IP address if blank)
: (optional)
(Will not be shown on site)

: (optional)
:

December 2008
SunMonTueWedThuFriSat
 123456
78910111213
14151617181920
21222324252627
28293031 



RSS feed RSS feed for Keith's Weblog
Atom feed Atom feed for Keith's Weblog
Weblog archive
Recent comments
  on 6 posts

Recent comments XML

new⇒Perl 6 1.0 in March?

Doh, my mistake. I'm aware of the​relation between Parrot and Rakudo​but I'...

Keith: Dec 2, 1:03am

Free image hosting sites

Well, TinyPic has this in its​FAQ:

> Images and videos is in​your accoun...

Keith: Dec 1, 1:13am

Join a NameValueCollection into a querystring in C#

Well with a lamba expression, this​is what I came up​with:

?!code:csharp...

Gustaf Lindqvist: Nov 30, 4:38pm

Why no generic OrderedDictionary?

Check​http://www.codeproject.com/KB/recip​es/GenericOrderedDictionary.aspx?d...

Gabrielk: Nov 27, 6:57am

WhatIsMyIP.com

http://www.thesysteminfo.com is​another good alternate to​whatismp.com... I...

Kripz: Nov 26, 8:51pm

Girls, please don't get breast implants

Actually I think it's sweet when a​man loves a woman whether she's big​or n...

218.186.12.228: Nov 26, 9:40am

Generated in about 0.308s.

(Used 8 db queries)

mobile phone