Oh, I'll really miss occasionally peeking at AWStats and discovering weird pages pointing at my weird pages :(
This subtle aspect of web had been always strangely appealing for me: people leaving trails in access logs and building real "footpaths" network of synapses between HTML documents, across origins. Sad to watch it dying, however beneficial and understandable it is.
I feel it didn't have to be this way: maybe if GET wasn't so widely misused recently and generally everybody knew what to not put in URL and acted accordingly, we could have preserved such nice things.
Absolutely, I loved seeing spikes in my traffic and going to the reddit/HN thread that caused it. I guess you still can manually figure it out using a search engine maybe, but like you said the smaller weird ones will go under the cover probably.
Exactly. I am torn on this feature. On one hand this is the correct default for privacy, there are a number of websites with somewhat sensitive information in the URL. But relying on a search engine or webmaster tools to crawl the entire web to see where your traffic is coming from is a real shame. Especially because it will have an inevitable delay.
The next step is not knowing where your visitors are coming from and having to only buy google ads rather then creating affiliate relationships. It is too bad FireFox is playing into this, it is not helping anyone's privacy. It only lines Google's pockets.
You’ll still know the site sending traffic your way, but not the exact page or query. For most affiliates that’s fine and sites like HN could set the Referrer-Policy header to allow sending page-level details since they know that they don’t include anything sensitive.
What the changed default does is mean that things fail safely when someone doesn’t think about this at all and builds a site with sensitive info in the URL. In that case, outbound link targets might receive things like usernames or email addresses, information in URL path components, etc. which isn’t intended to be public. Those sites are often poorly supported so the default changing means that the work shifts to a fraction of the web community which is best prepared to deal with the trivial extra work required to set a policy.
It makes total sense that you have a website but have no idea where people are coming from to get to it. Why know what is working for your website so that you can improve upon it?
So then there is no reason to remove most of the referrer. Because you have an ip address, url, and the ability to probably find the rest of the url. I would prefer to have the whole url and no ip address because a users ip address is useless to me while the url with the link on it is valuable. So they are taking away the wrong thing.
It depends on how the site is laid out. Sometimes the url has information that shouldn't be shared, and truncating the url fixes that with very little downside.
And it would be nice if IP addresses could be hidden but that's a very different topic.
You'll still get the source domain name, you just won't be able to see the full path. Of course how useful it is will depend on the source website, if it's "news.ycombinator.com" it won't be too difficult to find the post, if it's "facebook.com" it'll be a tad more complicated.
Totally agree. As almost no one uses anything like webmentions, this was the way to discover who was linking to your site. (And because the Google link tool didn’t seem to return much actual information.)
From a glance at MDN [1] and specs [3] it seems at least we can still opt-in our sites to suggest visitors user agent to pass full referrer address along outgoing links; there seems to be three ways to do so:
# 1. Apache conf
Header set Referrer-Policy "no-referrer-when-downgrade"
<!-- 2. meta HTML head with same effect [2] -->
<meta name="referrer" content="no-referrer-when-downgrade">
<!-- 3. HTML anchor attribute -->
<a href="https://…" referrerpolicy="no-referrer-when-downgrade">
This will pass full path and query when navigating between HTTPS to foreign origin. I guess it will be lost in http: to https: redirects. `unsafe-url` value would do it even for HTTP.
(Funny all three have different spelling, and that in effect they direct value of a single HTTP header with inherently erroneous spelling.)
Note that it only works if it's set on the source page, for obvious reasons. So if you set these headers on your page the browser will send the referrer when browsing away from your page, but not when your page is the target.
Yes, I came to lament AWStats as well. I remember when google started stripping search terms in their referring urls. So then you didn't know what search terms were pointing to your site.
Google's answer was to just get your site verified and use their search console tools. Annoying, but OK. But then other search engines followed suit which left awstats with a lot of missing data. Now with simplified referring urls... it will mostly be a fancy page counter :/
I feel that this could easily be a user toggle-able option near the url bar - and that people could choose to send referrer and search parameters to sites they like - and I could understand certain medical terms and what-not maybe people wanting to keep more hidden.
I'm all for the browser taking control of this and giving the users options - love to be able to have the web site detect this and add a box saying 'hey would you mind sharing referral and or search term with us"
It really helps when trying to figure out if you should be adding more content for 'term-mainly-X-demo' might be searching or for sure should be adding more content for other terms people are definitely searching for.
I would imagine that many people would like to hide referrer for fbook, most of my sites I would think people would be willing to help with providing such info.
as far as webmastering and stats to try to help visitors - it appears google is keeping more and more data to themselves, and now firefox is making it less transparent too.
I see there is a link to the referrer policy for your site, but nothing about begging the user to include the info when visiting - oh well.
awstats and similar have helped troubleshoot and helped expand many sites for many years and now another nudge to install third party slow-ware google-stats.. I just, sigh.
But why have we decided lately to fall for the tyranny of what "ordinary users" want?
Why can't we have a full featured Firefox hidden behind a setting, so this mythical "ordinary user" can have a dumbed down interface and the rest of us can have a real browser?
> But why have we decided lately to fall for the tyranny of what "ordinary users" want?
For the same reason bank robbers rob banks. That's where the money is. The source of the funding that pays for development of these tools is driving this.
I'm not defending that situation, that's just the way it is. "Hackers" working on what they find technically elegant and useful are not driving these sorts of changes.
It's not really important enough to be a visible element on the bar. It would be a good compromise to bury an opt-in somewhere in settings though. Firefox is doing the right thing here by making it default and uncomplicated.
I feel that you are right.
I'd love it to become a right click on the page and 'share all requested info, or selected info with this site" perhaps.
I don't mind right click - save page as.. but feel the secondary menu needed when right clicking on a tab, then hover down to move tab, then another flyout menu for new window is too much. Wish the 'move tab to new window' was just right there one level up.
I feel that people would right click and allow info share right there if requested by some sites. Buried in the about: settings or whatever would never get used.
I suspect this is going to be a huge boon for services like ahrefs that crawls the web and provides information on which URLs on the internet link to which other URLs.
yes, for content-only sites it makes perfect sense. For sites hosting private data requiring login, (especially if there's some sensitive information in the URL) it poses a risk.
This subtle aspect of web had been always strangely appealing for me: people leaving trails in access logs and building real "footpaths" network of synapses between HTML documents, across origins. Sad to watch it dying, however beneficial and understandable it is.
I feel it didn't have to be this way: maybe if GET wasn't so widely misused recently and generally everybody knew what to not put in URL and acted accordingly, we could have preserved such nice things.