Hacker News new | ask | show | jobs
by berkes 1894 days ago
> ... and that websites don't honor DNT...

This is the important part regarding "security". Websites choose to not honor "DNT" headers.

Clients can just as easy choose not to honor no-floc headers.

Which is why I'm saying that this is not a security-thing. If people can just choose to ignore your security-headers, they are not a security-feature. At most they are a suggestion that, when followed, make the client honor privacy concerns from servers.