Hacker News new | ask | show | jobs
by oefrha 2342 days ago
Easier for you to assess the technical competency, however nice for you = larger attack surface for the site. Why would anyone in their right mind expose unnecessary info for hackers (whether whitehat or blackhat) to assess whether they’re an easy target? This is like asking people to turn on nginx server_tokens. Also, unnecessary headers -> more bytes transferred -> more bandwidth cost, especially for very short responses (but probably doesn’t matter for Cloudflare.)