Does ttrss send referral when clicked on a link within?

Support requests, bug reports, etc. go here. Dedicated servers / VDS hosting only
kurahan
Bear Rating Trainee
Bear Rating Trainee
Posts: 22
Joined: 03 Feb 2014, 09:48

Does ttrss send referral when clicked on a link within?

Postby kurahan » 07 Jul 2014, 07:43

Hi

Forgive me if this is a dumb question. This is a rather privacy related issue. Does ttrss send any link/click referral when I click on a link in ttrss?

thanks

User avatar
fox
^ me reading your posts ^
Posts: 6318
Joined: 27 Aug 2005, 22:53
Location: Saint-Petersburg, Russia
Contact:

Re: Does ttrss send referral when clicked on a link within?

Postby fox » 07 Jul 2014, 08:49

that's not how http referrer works.

jakob42
Bear Rating Trainee
Bear Rating Trainee
Posts: 15
Joined: 20 Mar 2013, 16:43

Re: Does ttrss send referral when clicked on a link within?

Postby jakob42 » 07 Jul 2014, 12:12

Your browser sends the referer (http://en.wikipedia.org/wiki/HTTP_referer), all you could do is use an anonymizer service. I guess that could be done by a plugin if you wanted to write one.

zeiram
Bear Rating Trainee
Bear Rating Trainee
Posts: 12
Joined: 29 Apr 2013, 17:04

Re: Does ttrss send referral when clicked on a link within?

Postby zeiram » 07 Jul 2014, 13:27

Or "simply" access your tt-rss installation via https only. (Browsers don't send referrers when the hosted page is on https and the destination is http.)

kurahan
Bear Rating Trainee
Bear Rating Trainee
Posts: 22
Joined: 03 Feb 2014, 09:48

Re: Does ttrss send referral when clicked on a link within?

Postby kurahan » 07 Jul 2014, 18:28

Hi

Thanks for all the replies. This is very helpful. I am already using https for my ttrss server. That seems like it takes care of the issue.

undefined
Bear Rating Trainee
Bear Rating Trainee
Posts: 4
Joined: 24 Oct 2013, 17:06

Re: Does ttrss send referral when clicked on a link within?

Postby undefined » 08 Jul 2014, 03:06

kurahan wrote:Hi

Thanks for all the replies. This is very helpful. I am already using https for my ttrss server. That seems like it takes care of the issue.


not quite.

for firefox whether the "Referer" header is sent when an HTTPS website refers the browser to another HTTPS website is dependent upon the network.http.sendSecureXSiteReferrer setting.

RFC 2616 only says that the Referer header should not be sent HTTPS->HTTP, but doesn't address HTTPS->HTTPS, so firefox sends the Referer header when navigating HTTPS->HTTPS and network.http.sendSecureXSiteReferrer is set true (the default). last time i checked (ie years ago) chrome sent the Referer header for HTTPS->HTTPS. not a big deal years ago even for the conspiracy theorists, but now a lot of websites are going HTTPS (google, facebook, twitter) and are known to be tracking users.

so if you are really paranoid then make sure your tt-rss installation is HTTPS and you use firefox with network.http.sendSecureXSiteReferrer set false. the only websites i've had break are extranet/internet portals linked to by corporate intranets which are authorizing users using the Referer.

mrc0mmand
Bear Rating Trainee
Bear Rating Trainee
Posts: 16
Joined: 06 Feb 2014, 21:49

Re: Does ttrss send referral when clicked on a link within?

Postby mrc0mmand » 08 Jul 2014, 03:59

undefined wrote:
kurahan wrote:Hi

Thanks for all the replies. This is very helpful. I am already using https for my ttrss server. That seems like it takes care of the issue.


not quite.

for firefox whether the "Referer" header is sent when an HTTPS website refers the browser to another HTTPS website is dependent upon the network.http.sendSecureXSiteReferrer setting.

RFC 2616 only says that the Referer header should not be sent HTTPS->HTTP, but doesn't address HTTPS->HTTPS, so firefox sends the Referer header when navigating HTTPS->HTTPS and network.http.sendSecureXSiteReferrer is set true (the default). last time i checked (ie years ago) chrome sent the Referer header for HTTPS->HTTPS. not a big deal years ago even for the conspiracy theorists, but now a lot of websites are going HTTPS (google, facebook, twitter) and are known to be tracking users.

so if you are really paranoid then make sure your tt-rss installation is HTTPS and you use firefox with network.http.sendSecureXSiteReferrer set false. the only websites i've had break are extranet/internet portals linked to by corporate intranets which are authorizing users using the Referer.


I'd just like to add that if you use Google Chrome and you want to disable referrer headers, you can launch Chrome with --no-referrers parameter. Or for quick access (on Windows) just modify your Chrome shortcut to something like this: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-referrers

User avatar
dxbi
Bear Rating Disaster
Bear Rating Disaster
Posts: 62
Joined: 16 Mar 2013, 13:44

Re: Does ttrss send referral when clicked on a link within?

Postby dxbi » 08 Jul 2014, 10:51

There actually is a way to tell your browser never to send Referrer-Headers to links originating from a page:

Code: Select all

<meta name="referrer" content="never">

(see http://wiki.whatwg.org/wiki/Meta_referrer)

This has been implemented at least in Chrome/Chromium for a while.
Somebody please write a pull request because honestly I just don't care enough at the moment :)

User avatar
fox
^ me reading your posts ^
Posts: 6318
Joined: 27 Aug 2005, 22:53
Location: Saint-Petersburg, Russia
Contact:

Re: Does ttrss send referral when clicked on a link within?

Postby fox » 08 Jul 2014, 11:09

yes adding a browser-specific hack implemented in chrome only because of privacy freaks? sounds like an excellent idea

don't bother


Return to “Support”

Who is online

Users browsing this forum: No registered users and 7 guests