3 ms·
I'm printing and framing this for the next time our PO brings this amazing sub-domain per user idea back on our backlog.
by postit 8y ago
I'm printing and framing this for the next time our PO brings this amazing sub-domain per user idea back on our backlog.
- trevordixon 8y agoYep, I've learned that hosting other people's stuff on your domain will harm the domain's reputation. Use a different domain for user content, and make it fungible.
- mseebach 8y agoThe problem was the phishing, not the subdomain. If your app allows users to run phishing operations, moving the content from user.foo.com to www.foo.com/user probably won't help much in parent's scenario.
- Boulth 8y agoBut it would help to run user content on user.foo.io just like Github.
- txsh 8y agoNo. The problem is the subdomain. Allowing people to phish on a subdomain is lending the phisher the credibility of legitimate websites hosted on the domain. It’s like lending a thief your uniform so that he can disguise himself as an employee. You’re an accomplice when he uses it to steal.
- eToThePiIPower 8y agoI have to disagree. A phishing scam from "billing.foo.com" would be much harder to spot than one from "user-content.foo.com/billing". Especially if the user has free reign over the style + content. If the user is going to be able to design + style the pages any way they want, having something in the URL to indicate it's still user content is important.
- sillysaurus3 8y agoHow does zeit.co do it with `now`? https://zeit.co/now https://zeit.co/now