70
edits
| Line 11: | Line 11: | ||
=== Deploy Safe and Rational Defaults === | === Deploy Safe and Rational Defaults === | ||
While I think that improving the referer situation is useful in some cases, it really doesn't do anything to stop bad actors. I think giving sites control over when referer info is sent to third parties should be a higher priority than just restricting it client side, so sites can control the leakage of their PII themselves. Right now it simply is not | While I think that improving the referer situation is useful in some cases, it really doesn't do anything to stop bad actors. I think giving sites control over when referer info is sent to third parties should be a higher priority than just restricting it client side, so sites can control the leakage of their PII themselves. Right now it simply is not possible to restrict referer for many elements. Providing trickle-down restrictions via CSS or via an attribute of the html or body tag would be ideal. | ||
After all, if bad actors really want to pass data to their third parties, they have plenty of options available for this even if referer is restricted/eliminated... | After all, if bad actors really want to pass data to their third parties, they have plenty of options available for this even if referer is restricted/eliminated... | ||
- [[mikeperry]] | - [[mikeperry]] | ||
edits