Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dissuade <meta name="generator"....> #91

Closed
danwdart opened this issue May 26, 2016 · 10 comments
Closed

Dissuade <meta name="generator"....> #91

danwdart opened this issue May 26, 2016 · 10 comments

Comments

@danwdart
Copy link

I have seen <meta name="generator"...> used before, is it not an anti-recommendation?

@joshbuchea
Copy link
Owner

@dandart could you please elaborate?

@danwdart
Copy link
Author

I've seen generator around before, mainly on old frontpage-related sites. I thought it ought to be featured since it exists, but dissuaded since it's not a standard and/or doesn't add anything.

@filipecatraia
Copy link
Contributor

The W3C lists it as a possibility, and no top-ranking websites speak against it. That said, it's very close to useless.

@joshbuchea
Copy link
Owner

Got this added. Thanks @dandart!

@tomlutzenberger
Copy link
Contributor

I think one reason, to not recommend meta-generator is security related.

Imagine someone running a website based on an old Typo3 or Wordpress Version.
You reveal something like generator="Typo3 4.5" an actually invite hackers to tear down your site.
It's like putting a big sign in your front-yard, saying

"My door locks are from 1874!"

You wouldn't do that, would you?
Of course, there are many ways to find out what your site is based on. But why make it easy for the bad guys?

Conclusion:
It always depends on your site/project, but the less technical data you provide, the better.

@joshbuchea
Copy link
Owner

@tomlutzenberger I generally agree with you. However, generator is actively used by WordPress today, and Hide the Version of WordPress to Improve Security, or NOT?. Also, it is an HTML5 standardized metadata name.

I think @vonrac nailed it with:

The W3C lists it as a possibility, and no top-ranking websites speak against it. That said, it's very close to useless.

@joshbuchea
Copy link
Owner

All that said, that tag makes me cringe a little when I see it 😬

@tomlutzenberger
Copy link
Contributor

Me too.
So... what are you gonna do? Leave it untouched? 😕

I just don't see any benefit using it.

@joshbuchea
Copy link
Owner

Until a top-ranking site speaks against, I think I should leave it where it is. I try to roll with the general web development consensus as much as possible. And there doesn't seem to be a strong consensus either way on this one.

Sorry homie I know this one bothers you. Just pretend it isn't there 😆 Or talk someone prominent into writing about why it shouldn't be used.

@tomlutzenberger
Copy link
Contributor

Alright, I see your point.

calls Sundar Pichai ☎️ 😆

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants