Comment 9 for bug 560246

Revision history for this message
William Grant (wgrant) wrote : Re: Requiring REFERER makes user privacy more difficult and CSRF could be prevented more robustly

Redirects are not a problem. They can only result in GET requests, which cannot perform modifications in any correct Web application. The cited paper appears to be ignorant of that fact.