Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So don't forge your headers.

I don't see how this would be slippery at all.



The parent's point is that some of those IE10 users aren't just stuck with a default, they really did intend to turn DNT on.


Which is why DNT makes zero sense to be on by default.


Does the DNT standard require that User-Agent strings correctly reflect the browser? [1] Guaranteeing a site follows DNT means that it will follow it, not that it will follow it only if headers are not forged.

Also, is "forging" really a dishonest thing in this instance? Browsers have been making themselves look like other browsers for years, in order to deal with stupid servers that make incorrect assumptions about the User-Agent string.

[1] Not a rhetorical question. I don't know the answer.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: