Can I trust the title bar when using https?

I understand that the abstracting header is trivial to spoof using standard http. But when using https, can you trust the referent or is it potentially faked?

+4
source share
1 answer

No. Using HTTPS does not change anything; the referent can be trivially tampered with; eg:

wget --referer=http://whitehouse.gov/ https://example.com/ 
+6
source

All Articles