Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

yes, that's right: this is just one arrow out of the quiver. sanitizing the search terms out of the referrer does not fix the full problem.

whether the advertisers are receiving the headers are not depends on how the ads are served. to my knowledge, most of the time, they're not receiving the header directly, they're using JS to access the referrer indirectly (it is exposed via the document object). some adblockers merely hide the ads, which would still allow the advertiser to access the referrer. others prevent the ads from loading which i believe would prevent any access.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: