Skip to content
This repository has been archived by the owner on Dec 23, 2018. It is now read-only.
This repository has been archived by the owner on Dec 23, 2018. It is now read-only.

Privacy threat in default whitelist? #50

Closed
rlow0 opened this issue Jan 19, 2017 · 3 comments
Closed

Privacy threat in default whitelist? #50

rlow0 opened this issue Jan 19, 2017 · 3 comments

Comments

@rlow0
Copy link

rlow0 commented Jan 19, 2017

The default whitelist (http://meh.schizofreni.co/smart-referer/whitelist.txt) contains many strange looking domains composed of random words. As far as I can tell, these appear to be ad servers. I'm surprised because I imagine people want to use smart-referer to protect their privacy, and sending referer headers to ad servers does the exact opposite. Can you tell me why these servers are whitelisted by default? Thanks

@meh
Copy link
Owner

meh commented Jan 19, 2017

You can check the whitelist with comments for their reason here, and check the commit history for more info.

@ntninja
Copy link
Collaborator

ntninja commented Apr 17, 2017

I just completed a quick survey of all of our current whitelist entries and removed several that do not appear to be used anymore – including the mentioned ad server domains. It should be noted however that the point of the default whitelist is to minimize the impact of this extension on everyday web surfing for our users while still providing the maximum referer privacy possible under these circumstances. As such trade-offs have to be made.

Also please remember that the contents of the Smart Referer whitelist are completely irrelevant if your browser never attempts to establish a connection to the given server in the first place. In particular I expect most of our users to simply use an ad blocker for preventing connections to ad servers and only disable that if they really have to. We do not want to get in their way in that case.

We do try to keep the whitelist as small as possible through.

@ntninja ntninja closed this as completed Apr 17, 2017
@grenzor
Copy link

grenzor commented Dec 12, 2017

Could the whitelist be hosted and grabbed from Github since it supports HTTPS?

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants