RFC 3986 section 7.5: "URI producers should not provide a URI that contains a username or password that is intended to be secret. URIs are frequently displayed by browsers, stored in clear text bookmarks, and logged by user agent history and intermediary applications (proxies)."
Tell that to half of the big internet companies who use signed URIs, e.g. I can copy the URI to a private photo in Google Photos and fetch it without any cookies and without sharing by URI enabled. There are perfectly good engineering reasons to do stuff like this.
-
-
And my point is I may not even want you to *know* what URI I downloaded something from! The mere association of a public URI with a file is a personal information leak! Why should you know where I got a file from?
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.