Live data from Hacker News

Wondering what to do (if anything) about hotlinking

kryogenix.org

21–30 of 49 posts

Re: Wondering what to do (if anything) about hotlinking

#21

I would just add some console.log message explaining the issue you have with hotlinking the script. This will not disrupt users, but anyone who fires up their devtools will see that the site is getting shamed. And if their devs care just a little bit, I think they will find it embarrassing enough to host the script themselves. Correct me if I simply have missed it, but is there an official NPM package available? I ha…

Clever idea. Unfortunately the real hotlinking bandwidth bandit hog is images.

Re: Wondering what to do (if anything) about hotlinking

#22
I would modify the script to display a notice:

"Thank you for using SortTable from https://www.kryogenix.org/code/browser/sorttable/. If you, the site owner, would like to use SortTable without this notice, please download the script from [here](URL link) and add it to your server."

If you want to get fancy you can serve the modified script only if it's being hot linked and the original script if it's being used on www.kryogenix.org - or another website that has permission to use the script.

Re: Wondering what to do (if anything) about hotlinking

#23
Another solution: when the script is hotlinked, add a new row in the sorted table, saying "You're using a hotlinked version of sorttable.js - please host on your own webserver or purchase a license here". This way, the sorttable.js is not broken for any users, it's still usable, but there's an "ad" that's both a deterrent and an upsell.

Re: Wondering what to do (if anything) about hotlinking

#25
post #22

I would modify the script to display a notice: "Thank you for using SortTable from https://www.kryogenix.org/code/browser/sorttable/ . If you, the site owner, would like to use SortTable without this notice, please download the script from [here](URL link) and add it to your server." If you want to get fancy you can serve the modified script only if it's being hot linked and the original script if it's being used on…

I think this is a brilliant solution - you can also make it the second row in the table that's being sorted (right after the table header). That way there's no breakage and it's a good enough deterrent.

I would go on further and make a link to a Stripe Checkout page that allows you to purchase a license subscription to remove the notice.

Re: Wondering what to do (if anything) about hotlinking

#27

Instead of a nasty console message or popup, modify the script to ping back more detailed and useful information about where its being used. Then contact the developers. Edit: you don't even need to write anything dynamic to receive the ping back, just have the script load an image from yoursite.com/specialprefix/the useresencodedbrowserurl/anythingelseinteresting/1.png then look in your server logs for any 404 error…

And you are now in violation of GDPR

if that's true, how is every single tracking pixel on the web not in violation of the GDPR?

Re: Wondering what to do (if anything) about hotlinking

#28

I would just add some console.log message explaining the issue you have with hotlinking the script. This will not disrupt users, but anyone who fires up their devtools will see that the site is getting shamed. And if their devs care just a little bit, I think they will find it embarrassing enough to host the script themselves. Correct me if I simply have missed it, but is there an official NPM package available? I ha…

I've found that companies where they've done this (hotlinked) often have incompetent or overburdened people, and this shaming wouldn't even register.

Hotlinking code like that though is just plain stupid from the liability perspective. If they are a business, they should be worried about 3rd-party liability.

The fact that they are doing this makes the website hosting the script, a nice juicy target for watering hole/supply chain attacks.

What are they going to do if that happens? Its not like business insurance will cover that.

Re: Wondering what to do (if anything) about hotlinking

#29

The article proposes one solution as being to essentially serve up different content to whoever is hotlinking the script, but then says "Obviously, I don't wanna do this." It seems like the clearest solution to me, so I don't know why it's a bad option. The replacement solution worked for 3D Realms many years ago after a bunch of journalists, fansites, and forums would link to their game screenshots. When someone did…

Except they'd claim you maliciously did it and caused economic damages by breaking their system and then bring the lawyers in.

Pretty much the same narrative as what that Liberty Liberty Liberty guy did when he upped the semver noting a breaking change and pushed it.

Re: Wondering what to do (if anything) about hotlinking

#30
post #3

Can't you disallow external links that will redirect to a dynamic error page? Things like HTTP Referrer, coupled with a set of rolling dynamic headers so actual site visitors aren't impacted, or significant rate limiting, or a simple non-malicious HTTP widget injection that sends a simple message, stop the unauthorized hotlinking. You could even take it a step further by evaluating at the packet header level but that…

Isn’t there a way to do this by looking at the Origin header or something? What you want is for the download link to work, but when the page is hot linked, the origin header won’t match and the link will be broken. That should be doable with a simple nginx rule.

You might not want to break the existing web link (if you don’t want to break existing sites). But you could move the link to the javascript code somewhere else which has this origin guarding behaviour.

Edit: There’s a better suggestion down thread. Put the javascript file in a zip file and let people download that. Brilliant.

Post reply on HN