Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Interestingly, that does not seem to work with SSL version of Google.


Browsers strip Referer if the protocol is HTTP but the referrer's URL was HTTPS, to prevent the information about the resource just being left leak.

If WSJ checks Referer and explicitly allows Google to pass, it won't see it if you're coming from HTTPS.


Only if the link target is non-HTTPS, I believe. HTTPS-to-HTTPS requests includes referer headers, even across domains.


Browsers do not send referrer headers is the referrer is an SSL site.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: