Feedback Add 'noreferrer' to hyperlinks

  • 🐕 I am attempting to get the site runnning as fast as possible. If you are experiencing slow page load times, please report it.

Homocull

kiwifarms.net
Joined
Jun 21, 2018
It's not exactly a common occurrence (I've only seen it done twice) but site admins that have beef with KF can exploit the referer header to fuck with anyone coming to their site from this one.
Fresh off the oven example courtesy of TCRF: if you click on a link to their site from the thread, your cookies will be pozzed, IP blacklisted and if logged in your account will be banned

lol (3).webp

Imo they shouldn't even be given the chance to do this, the fix would simply be to add noreferrer to rel=
 
There is already a site header that instructs your browser to not provide referer information
If it's not working, it could be a "referer" vs. "referrer" problem.

Alternatively, this could be added to every HTML page:
HTML:
<meta name="referrer" content="no-referrer">
 
This cutting room floor website seems like it's hitting the stage of eating its own face. Odds on that place completely imploding due to gay infighting and tranny janny dictators throwing their girl dicks around?
More things ruined by trannies. I look shit up on tcrf all the time, I've even made a few contributions. Never interacted with anyone from the site but when it comes to retro game stuff like this it's always infested with these fuckers.
Just know that not every retro game enthusiast is a flaming faggot.
 
  • Informative
  • Feels
Reactions: Anonitolia and Xev
Referrers are even more sketchy, as they would allow le phonebooking under some very specific circumstances. If you're logged in to non-anonymous account on the target side, and click a link to it on a subpage that is unique to your user, the target site admin could deanonymize you.

Hypothetical example: Image I were a tranny LinkedIn employee. Now I sign up to the Kiwifarms and send a random LinkedIn link separately to all KF users of interest saying "is that you, bro?". Every private message thread will have its own ID number in the URL.
Then I would just need to check the referrers of the people clicking the links to know exactly which LinkedIn user is which KF user.

Fringe attack vector requiring some specific conditions to pull off, but technically quite simple and something trannies would definitely abuse their positions to do.
I know that Imgur will break your connection if you open a link from here through the same mechanism, just as an example of how it was abused against the site in the past.
I was wondering why the fuck my Imgur session was throwing errors, that explains that. Clearing cookies solves the issue for Imgur btw.
No, you did not store my referrer, stalker child.

actually we should make our referer NIGGER so that when a tranny wants to blacklist the site they have to type and save the word NIGGER every time.
You cannot do this on a website basis unfortunately, you could write a browser extension though.
 
Back