Hacker News new | ask | show | jobs
by anfilt 1893 days ago
This is insane. So all sites with publicly routable IP addresses that a user visits are used for this cohort calculation! WTF

Every http server project should include the header by default to disable this, and even back port it for older versions as a critical security vulnerability update, since old sites with sensitive information will clearly be still serving content, and the DEVs may not even be working on the site anymore, and basically an IT guy is just updating software (hopefully...).