Hacker News new | ask | show | jobs
by tiglionabbit 4365 days ago
Yes they are. Cookies are subject to the same origin policy. The Referer header is not.
1 comments

I think you misread. grannyg00se said there is a lot more to worry about than http referers. We don't need a reminder that referer is a problem.