5 ms·
PG is absolutely right re: treating publishers as servers: this is NOT just about fraud, please take a look at this: http://news.ycombinator.com/item?id=3803981
by adsenseclient 14y ago
PG is absolutely right re: treating publishers as servers: this is NOT just about fraud, please take a look at this: http://news.ycombinator.com/item?id=3803981 http://news.ycombinator.com/item?id=3803981
- larrys 14y agoYour link goes to ycombinator.org not .com Requires a separate login to that to vote or reply. At first I thought you were potentially man in the middle. While the whois says the domain is owned by "Paul Graham" at the appropriate address I don't separately even know if this information is correct as anyone can put anything in whois owner info.
- MiguelHudnandez 14y agoFor what it's worth, the two names resolve to the same IP address for me. My recommendation for developers who might have this issue on their own site is to set up a redirection script at all the non-canonical names. The redirection script should redirect to the canonical name and include the full path and query string if they exist. I also take that opportunity to log the traffic so I can report on which names are generating traffic. That can help when you are deciding wether to allow names to lapse.
- larrys 14y agoThe issue for me is that it required me to login again with a password because a web browser treats domain.com and domain.org as two different sites. So it didn't have my password stored. That is what brought it to my attention. And it's obviously the correct behavior from a security perspective regardless of whether it redirects to the same ip or not (you are correct though).
- ahlatimer 14y agoThey (news.ycombinator.com/org) resolve to the same IP. It's safe to assume it's not a MITM.
- deleted 14y ago[deleted]