Live data from Hacker News

A URL shortener not shortening the URL but makes it look very dodgy

github.com

51–60 of 104 posts

Re: A URL shortener not shortening the URL but makes it look very dodgy

#51
post #6

Nicely demonstrates why outsourcing link shorteners is risky - they go out of business and your link is dead.

There is an archiveteam project to index all the shorteners and where they direct to. I think it's the default project if you're running the warrior and there's nothing more important going on.

https://wiki.archiveteam.org/index.php?title=URLTeam

Re: A URL shortener not shortening the URL but makes it look very dodgy

#55

I would consider this innovative, but Office365 has had this built in (and as far as I can tell impossible to turn off) for years. What used to be a sensible link turns into a vast "safe link honest, guv" mess. I call it "man in the middle attack as a service"

Same for MS Teams. Before, we used Google Meet, which produced 9-letter meeting IDs, that I would be able to remeber if I really wanted to.

Teams just generates mile long URLs that encode more information than some of the meetings themselves in the worst case.

Re: A URL shortener not shortening the URL but makes it look very dodgy

#56

I would consider this innovative, but Office365 has had this built in (and as far as I can tell impossible to turn off) for years. What used to be a sensible link turns into a vast "safe link honest, guv" mess. I call it "man in the middle attack as a service"

Same with PayPal. I've received perfectly valid emails direct from PayPal that include random sketchy links from third parties that are obvious phishing expeditions. I reported it to PayPal, but the ability still exists.

That's inherent to features that allow user generated content, which is obviously mandatory in the context of PayPals invoicing feature.

The only reason why companies don't care about it in the context of mail is because there is no equivalent to safe browsing for mails, so Domains aren't penalized by Google for sending fraudulent messages at small scale. If this was to change, they'd all pivot to using secondary domains for these mails, like GitHub does for GitHub pages.

It would also be a pretty pointless feature as you'd probably complain anyway, as the email would still come from a Paypal owned domain.

On the same topic: if you've got a Gmail address you're also able to send from @googlemail.com

Is this another security issue in your opinion?

Re: A URL shortener not shortening the URL but makes it look very dodgy

#57

I would consider this innovative, but Office365 has had this built in (and as far as I can tell impossible to turn off) for years. What used to be a sensible link turns into a vast "safe link honest, guv" mess. I call it "man in the middle attack as a service"

[deleted]

Re: A URL shortener not shortening the URL but makes it look very dodgy

#58
post #55

I would consider this innovative, but Office365 has had this built in (and as far as I can tell impossible to turn off) for years. What used to be a sensible link turns into a vast "safe link honest, guv" mess. I call it "man in the middle attack as a service"

Same for MS Teams. Before, we used Google Meet, which produced 9-letter meeting IDs, that I would be able to remeber if I really wanted to. Teams just generates mile long URLs that encode more information than some of the meetings themselves in the worst case.

> URLs that encode more information than some of the meetings themselves in the worst case

Sadly this is also possible with a 9-letter code.

Re: A URL shortener not shortening the URL but makes it look very dodgy

#59
post #8

Earlier quoted context omitted.

Forgive my old-fashioned-ness, but... Why is metered cloud hosting a better choice here than a $5/mo. VPS?

> $5/mo. VPS I think you may even get 256 megs of ram for that these days.

1 GB, and 20 GB disk, at OVH. With unlimited bandwidth.

Here though, that service could be hosted on a static website (free at github/gitlab/cloudfare/etc), with client-side javascript used to decode data encoded in the url fragment.

Re: A URL shortener not shortening the URL but makes it look very dodgy

#60

I would consider this innovative, but Office365 has had this built in (and as far as I can tell impossible to turn off) for years. What used to be a sensible link turns into a vast "safe link honest, guv" mess. I call it "man in the middle attack as a service"

[deleted]

If they claim it’s virus free, then it must be true!
Post reply on HN