• 0

Alternative Options to Referer in HTAccess


Question

Hey Guys,

 

While cruising a few IRC channels over the weekend, I suggested someone use htaccess to block other websites from hotlinking. I was chastised up the ying-yang for that suggestion. They said that referrer information isn't transferred through TLS, and that it can cause issues for the end user. I wasn't aware of this, nor has anyone ever told me of this.

 

So my question is; what's an alternative? They said to just let it happen, it's not a big deal. Sorry, but I don't want someone else linking stuff from my services to someone elses site.

3 answers to this question

Recommended Posts

  • 0

If I am reading this correctly from the article - http://alistapart.com/article/hotlinking , even if the referrer is not passing, if you configure it properly then TLS pages (as mentioned) will still be able to access the images.

 

Also, I tried to google about 'neowin' and then open the news page, which is in HTTPS as shown in the below image but it was still having referrer information. (If I not mixing stuff up)

 

Correctly.PNG

  • 0

where did you read that referrer is not in a tls connection?  Are you talking a link from a https site to a http?  If so then yeah browsers do not send the referrer, this is in this rfc https://www.w3.org/Protocols/rfc2616/rfc2616-sec15.html#sec15.1.3

 

Clients SHOULD NOT include a Referer header field in a (non-secure) HTTP request if the referring page was transferred with a secure protocol.

 

You can use the newer Meta Referrer which modern browsers support.  A browser can be set not to send referrer info, so its always possible to bypass such a block if your saying that access to your stuff can not be a referred link, etc.

 

What exactly are you trying to prevent?  If you put up say an image, and you want to stop other pages from linking to it?  Why did you put up the image?  Why do you not require auth to access the image if you don't want others using it, etc.  if you put it up on the public net your kind of saying hey use this, etc ;)

 

Don't provide http to your images another thing you can do.  https to https should send referrer info, etc.  If your page is not available http then then you shouldn't be seeing the https to http issue where referrer is missing, etc.  But again this does not stop access, this really just stops idiot webpages from linking to your ###### and not sending you referrer info.  If they send you referrer info then sure you can use .htaccess to block if that is what you desire.

 

What exactly did they say it would break.. Who gives a ###### what it breaks as long as it works how you want it to, ie users on your site accessing your stuff directly via your site, etc.

 

If you do not want the use of the image from anything other than your site, then you can block if the referrer is blank.  This could cause you issues if your using http links in your own site when your site is https..  But that would be just shooting yourself in your own foot ;)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Looks like the 7.1 is fake effects, can it at least do real 5.1? It says 'virtual 7.1' in all descriptions.
    • You can't, if you didn't notice, it doesn't support surround at all, it's right in the spec list.
    • Hi — I’m always interested in soundcards. Like displays, I just want to know I’m getting as much clean “sonic juice” into my brain as possible as the years take their toll. I’m not entirely sure what to take away from this review, though. It doesn’t really tell me whether the AE‑X is a good product or who it’s actually for. Most of what I’m getting is: there’s a driver to install, here’s what it looks like, and here’s what’s in the box. There’s a lot of emphasis on the SPDIF input. When you mention not needing to switch headphones between console and PC — does that mean the PC has to be powered on just to pass audio through? That seems like a fairly big waste of energy. Is this more something a streamer would use alongside a capture card? How are you testing the sound? (Also, you might want to clarify that you’re using the headphones in wired mode when you mention they’re wireless.) You mention the lack of EMI shielding — how much real‑world difference does that make compared with typical motherboard audio? On multi‑channel: what exactly isn’t supported? Does this mean Windows spatial audio (Dolby Atmos for Headphones, DTS Headphone:X, etc.) won’t work, or just that the card itself doesn’t decode surround formats? And are there any true multi‑driver “surround” headphones left that would even use that? You also highlight support for high‑impedance headphones — but what does that translate to in practice? How does it compare to driving the same headphones from a normal device, and does it make any difference for everyday, lower‑impedance models? In short, who is this card actually targeted at?
    • Yes, THIS is wordart, not the styling that can now be done. Wordart was all about those curvy words, that you could change the path of, like making words go around a circle. I don't think it can be done now, right?
    • Just saw a news report of a Waymo driving into a flooded road.
  • Recent Achievements

    • Dedicated
      Almohandis earned a badge
      Dedicated
    • Dedicated
      JuvenileDelinquent earned a badge
      Dedicated
    • First Post
      DrWankel earned a badge
      First Post
    • Reacting Well
      DrWankel earned a badge
      Reacting Well
    • Week One Done
      Supreme Spray LV earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      503
    2. 2
      +Edouard
      170
    3. 3
      PsYcHoKiLLa
      88
    4. 4
      Steven P.
      76
    5. 5
      Michael Scrip
      74
  • Tell a friend

    Love Neowin? Tell a friend!