Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's still being abused by people registering expired domains.




Exactly, there is no guarantee that what a shortened url pointed to 10 years ago is the same as today, or even the same owner or administrator.

OK but the same vulnerability exists if short URLs weren't used -- in that case the link source would link directly to the now-hijacked domain. So why does Google have to care about this?

Is it because they're worried that the domain name goo.gl in the link implies a Google endorsement? Seems like they should have thought of that before launching the service in the first place?

Still, the frequency of actual abuse must be low and going down over time (due to the data set being read-only since 2019 and actual traffic to these links surely decreasing as time goes on)...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: