Re: What constitutes protection [was: About using CORS]

Referer checking has a few problems:
-- the Referer header reveals the full URL of the referring page, so it's a
privacy problem
-- therefore, some firewalls strip it and break sites that depend on it
-- it's harder to deploy than just putting a file on your site, or even
adding a custom HTTP header

Rob
-- 
"He was pierced for our transgressions, he was crushed for our iniquities;
the punishment that brought us peace was upon him, and by his wounds we are
healed. We all, like sheep, have gone astray, each of us has turned to his
own way; and the LORD has laid on him the iniquity of us all." [Isaiah
53:5-6]

Received on Wednesday, 5 May 2010 22:20:54 UTC