This is BrainLog, a blog by Dan Sanderson. Older entries, from October 1999 through September 2010, are preserved for posterity, but are no longer maintained. See the front page and newer entries.

April 25, 2002

Internet Explorer's Back button may be dangerous. I've been worried about next-in-line browser security for a long time (security environments of one site and the next site you visit) just because I'm paranoid, but never got around to testing browsers. What got my attention was noticing unusual (but mostly innocuous) behavior with server referer logs in edge cases. Normally, when I link to a site and you click on that link, the site's logs will show that not only did you visit, but you came from my site. At some point I got the impression that there are circumstances where I don't have to link to the site for my site to show up in their referer logs, but I never got around to verifying this...