using a referrer header for security is totally fucking batshit crazy stupid.
True, but we're not really talking about using it for security, are we? It stops stupid people from using bandwidth I don't want them to use. It doesn't stop clever people, but there are so few of them that I can afford to let them use the bandwidth.
If I had something on my server which would cost more than just bandwidth if it were accessed by somebody I didn't want to see it, I'd use a different method of sorting the authorised from the unauthorised.
True, but we're not really talking about using it for security, are we? It stops stupid people from using bandwidth I don't want them to use. It doesn't stop clever people, but there are so few of them that I can afford to let them use the bandwidth.
If I had something on my server which would cost more than just bandwidth if it were accessed by somebody I didn't want to see it, I'd use a different method of sorting the authorised from the unauthorised.