After running tests on a few browsers on browserscope.org, I noted that neither Firefox or IE have adopted the "Origin" HTTP header.
This header is a useful and valid way of helping prevent CSRF attacks, in my opinion.
Why has it not been universally adopted?
 
    