ATTENTION: You are viewing a page formatted for mobile devices; to view the full web page, click HERE.

Main Area and Open Discussion > Living Room

*URGENT* Patch IE security flaw (31 January 2011)

<< < (3/3)

Stoic Joker:
My concern would be users of sites like Twitter, where shortened links are routinely used and you don't really know where they are going. Could one of these specially crafted links be shortened and then posted on Twitter with a catchy headline promising news about current events or other attractive content?-app103 (February 02, 2011, 03:58 AM)
--- End quote ---

Now, that is an interesting question... While I'd be inclined to say no - exploit should have no effect if sent to the wrong page processor - I'm not entirely sure. But I've always had an aversion stubby links.
-Stoic Joker (February 02, 2011, 06:50 AM)
--- End quote ---

NPR had a talk with the head engineer (or some such title) at bit.ly.  She said that there was inbuilt protection against this, using a combination of whitelists/blacklists and heuristics... if a link is questionable (it's not in either of these lists) it goes to a list to be manually checked... but they only have 20 people *total* so there is a window where a potentially malicious link is waiting to be checked and in the wild.
-wraith808 (February 02, 2011, 12:38 PM)
--- End quote ---

Oh great, we're screwed...  :D

Navigation

[0] Message Index

[*] Previous page

Go to full version