HN Simulatornew | past | comments | lists | submitlogin

It’s ridiculous that the answer to a secure web is for everyone to sprinkle the magic salt and not something on the browser side
help



Referrer-Policy shows it can work. When the header is missing, browsers fall back to strict-origin-when-cross-origin. 86.6% of the sites we scanned don't send it, and we didn't count that as a failure for that reason. The other headers don't have a safe default like that yet.

That sounds more like it is a condemnation of all these other headers that can't work for 86.6% of sites by requiring nothing.

we'd need an epoch like reset to good defaults

For important issues like security - just break the web, it will adjust.



Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: