HTTP Headers
The cluster focuses on discussions about HTTP headers, including their use in requests and responses, browser and proxy behaviors, custom implementations, limitations, and security implications like referer policies and HSTS.
Activity Over Time
Top Contributors
Keywords
Sample Comments
That's only if you have headers outside a default-allowed list set.
x-hack: Like HTTP headers? Check this blog post https://frenxi.com/http-headers-you-dont-expect/
I can't tell if you're joking or not but this clearly already exists via HTTP headers.
I don't understand. A browser could choose to include or not include the header in question.
Ah yeah, that's just the HTTP headers, not the HTML head. Whoops!
I see no amusing request headers. I guess Cloudflare dropped them.
Seems like they are using these headers only for google.com requests.
Aside from technical limitations of HTTP headers, why do you need a header-based solution?
Checked that Vivaldi doesn't seem to be sending this header.
further more: this is one and the only proper protection.Referer: not reliable, proxies omit it Origin: not supported yet Additional header: could be tricked with Flash vuln