How is defacing a page not "malicious"?

I think they meant there was no malware being delivered from visiting the page.

The parent comment covered this very point:

>1. You're not subjecting HN readers to a site under the control of a malicious party who may have done more than just deface it. Even if you verify that you only receive plain boring text with no scripts, iframes, plugins, etc. it's impossible to verify that someone else won't get served different content. For example, malware that only gets served to people in Israel.

