You are reading a single comment by @aggi and its replies. Click here to read the full conversation.
  • Cheers, I don't have issues with any of the above but assumed that the tooltip wouldn't replace the actual url you're clicking on ... micro.sm/whatever

    All I was looking for was the tooltip to show the full URL. I assumed that as it can already show a portion of the URL (which you can extend the length of) then the information must be there so showing the full URL shouldn't be an issue.

    I can't imagine that many people are going to type in the URL from the tooltip to bypass the redirection so I'm not sure if I'm missing something with regard to why the tooltip cuts off most of the URL. Surely people are more likely to click on spam/malware if they can't see the URL.

  • Cautious and smart people check the URLs, but the vast majority of people just click. Besides, even without our redirector it's trivially easy to mask URLs. As an example I offer Rickrolling and Goatse.cx .

    By having the redirector, and by masking the URL, we ensure two things:

    1. We can visit the end destination of any posted URLs to discover if people are masking something like spam and malware using perfectly reasonable things like the rickrolling trickery.
    2. If someone can get a person to install a browser extension, or gain some other control over the browser... they still can't manage to auto-trigger a link without us knowing they've done so (they couldn't swap the title attribute with the href and click the link, as the link would be useless).

    Basically, we want the ability to always detect nefarious stuff, and to be able to kill it really effectively and quickly.

    We don't want to find ourselves in the position, for example, that someone else could've used our platform for fake display ad clicks against advertisers, given that we need affiliate relationships to be quite strong for the business model to function. And this is feasible, given that third parties can make clients for this platform, we could detect whether they're f*ing with links by comparing the click-through rate against more trusted clients.

    It all gets a bit complex... but the value of the redirector and not publishing the full link, for spam and malware prevention... is too high for us to not do it.

About

Avatar for aggi @aggi started