SSL weakness affecting links from pa

ARTURO GRAPA YSUNZA AGRAPA at banamex.com
Mon Apr 14 13:52:03 PDT 1997



>	GET forms aren't the only thing wrong with referer, btw. An
>associate of mine discovered some prioprietary Netscape information
>from the Referer: headers on hits to his website from Netscape
>employees, even.

Could you elaborate?


 ----------
From: sameer
To: ARTURO GRAPA YSUNZA; Tom Weinstein
Cc: toto at sk.sympatico.ca; cypherpunks at toad.com; stewarts at ix.netcom.com;
markm at voicenet.com; AGRAPA at k2.banamex.com; cryptography at c2.net
Subject: Re: SSL weakness affecting links from pa
Date: Monday, April 14, 1997 2:23PM

Microsoft Mail v3.0 IPM.Microsoft Mail.Note
De: sameer
Para:  ARTURO GRAPA YSUNZA
     Tom Weinstein
Cc:  toto at sk.sympatico.ca
     cypherpunks at toad.com
     stewarts at ix.netcom.com
     markm at voicenet.com
     AGRAPA at k2.banamex.com
     cryptography at c2.net
Asunto:  Re: SSL weakness affecting links from pa
Fecha: 1997-04-14 14:23
Prioridad: 3
Ident. del mensaje: A7705E17CEB1D011AF91006097838CEB

 -----------------------------------------------------------------------
----- --

> information.  This is a security hole in the web site, not in the
> browser.  The browser follows the HTTP specification.  If you have a
[. . .]
>
> In the eyes of some, the referer header is a privacy violation.  It
> allows a site to see what site you visited before coming there.  In the
> case of Navigator, we ONLY send the referer header when you click on a
> link.  Not when you select a bookmark.  Not when you type a URL into the
> location field.  This allows web sites to see who links to them.  I
> think that's something that a web author is entitled to know.

	GET forms aren't the only thing wrong with referer, btw. An
associate of mine discovered some prioprietary Netscape information
from the Referer: headers on hits to his website from Netscape
employees, even.

	I commend Netscape for providing users with the ability to
turn off referers.

 --
Sameer Parekh					Voice:   510-986-8770
President					FAX:     510-986-8777
C2Net
http://www.c2.net/				sameer at c2.net






More information about the cypherpunks-legacy mailing list