4 ms·
I really dislike it when companies use a new extension like "github.community" instead of a subdomain like "community.github.com" because there is no real way t
by conradk 9y ago
I really dislike it when companies use a new extension like "github.community" instead of a subdomain like "community.github.com" because there is no real way to know if the site is a phishing attempt or not. Getting people used to accept going to another site seems very bad for security. Especially when there are already domains like http://github.co http://github.co (notice the .CO instead of .COM) that don't belong to the trademark owner.
- dingaling 9y agoMy UK bank recently started using nationwide.nationwide-service.co.uk as an origin for e-mails. I had to check WHOIS and contact them to ensure it was valid, it just sounded so phishy. Given that previously nationwide.co.uk was used and trusted, I wonder what internal discussions led to selecting that new domain and why. And what advocates for the end-users spoke up and said "whoa dudes that's just confusing".
- joefreeman 9y agoIt's fairly common for companies to send automated e-mails from a separate domain to try to mitigate the impact of spam filters. ceo@company.com doesn't want her e-mails to be marked as spam just because some marketing e-mails are being sent from noreply@company.com.
- dx034 9y agoNot sure why you're being downvoted, that's likely the reason. Employee email addresses will be sent with @nationwide.co.uk and even if the communication in this case was important, enough people will mark it as spam. Using a second domain helps keeping the domain clean.
- 3pt14159 9y agoAnd I take it using a separate subdomain wont work either? I.E. if you send mail from hi@marketing.example.com it will still hurt frank@example.com so they need to get a different domain?
- Posibyte 9y agoIt depends on how spam filters are configured, but yes, subdomains can harm root domain's reputations. However, it's generally seen as OK to use subdomains to mitigate reputations being spread to the main domain. As long as you have your records in order to show what's going on, using a subdomain is usually OK.[1] [1]: http://www.magillreport.com/Spamhaus-Provides-Answers-Part-Four/ http://www.magillreport.com/Spamhaus-Provides-Answers-Part-F...
- s_kilk 9y agoI wonder if this has caught on because the business want's to move fast with new email campaigns and such, but their IT people forbid them from getting a new subdomain? I wouldn't be surprised if in some organisations it's easier to register a new domain than to get any changes made to the "mothership" domain.
- scrollaway 9y agoYou think that's bad, look at PayPal. They talk big about phishing prevention but use a bunch of random domain names including paypal-community.com and other obscure stuff.
- ashtube 9y agoAlso from an SEO perspective, they could have bumped their domain authority even further by using the same domain - they now need to grow this new domain from square 1, and it's going to be hard, even for a large company like Github.
- cstuder 9y agoWhat do they have to fear? The market for Github forums isn't that big.
- pronoiac 9y agoMy immediate thought is that they did this for browser security reasons, like how they use github.io for Github Pages.
- wyldfire 9y agoBut isn't that governed by the same origin policy, which cares about specific hosts (so a subdomain would be equally effective)?
- hdhzy 9y agoSubdomain can set a cookie for root domain [0] and that can lead to session fixation attacks. Cookies are not subject to CORS. [0]: https://www.mxsasha.eu/blog/2014/03/04/definitive-guide-to-cookie-domains/ https://www.mxsasha.eu/blog/2014/03/04/definitive-guide-to-c...