logoalt Hacker News

rackcrunch • today at 9:58 PM • 1 reply • view on HN

Referrer-Policy shows it can work. When the header is missing, browsers fall back to strict-origin-when-cross-origin. 86.6% of the sites we scanned don't send it, and we didn't count that as a failure for that reason. The other headers don't have a safe default like that yet.


Replies

axospaxos • today at 10:08 PM

That sounds more like it is a condemnation of all these other headers that can't work for 86.6% of sites by requiring nothing.

➕ show 1 reply