Checking the referrer (errr, "referer") header seems obvious to me, I wonder why they're not doing it.<p>Sure, the referrer can be spoofed <i>if</i> you can set arbitrary headers, but you can't set headers on iframe requests anyway (and even XHR explicitly disallows setting Referer)