4 ms·
One thing which I didn’t see clarified here was the deceptive CNN domain. Either the preview card can be exploited to spoof CNN (bad on twitter) or CNN.com has
by beager 7y ago
One thing which I didn’t see clarified here was the deceptive CNN domain. Either the preview card can be exploited to spoof CNN (bad on twitter) or CNN.com has an open redirect (bad on CNN).
- akersten 7y agoThe malicious webserver is probably redirecting the Twitter crawler based on its user-agent to CNN, and Twitter's redirect-busting is helpfully pulling in the "final" destination.
- edent 7y agoThe preview card can be exploited by Twitter. Visit https://cards-dev.twitter.com/validator https://cards-dev.twitter.com/validator and paste in the spam URL there. You'll see that the validator warns that it is being redirected, but follows it anyway. CNN is blameless (as far as I can tell).
- beager 7y agoSo the exploit is fake site -> user-agent specific redirector -> CNN. That would clear CNN. I’m thinking through how Twitter would combat something like this. IMO they would flag new domains for manual approval (or hey, require TFA for self-serve ad accounts!) but both of these add to the cost and friction of their adtech. Always a bummer when good security practice gets overruled by the need to squeeze every cent of revenue they can.
- leeoniya 7y ago> I’m thinking through how Twitter would combat something like this. twitter's bot can pull the link via Tor with a randomized UA
- rubyfan 7y agoCan’t you just time the redirect so that when you create the card you point to CNN then change the redirect to something malicious afterward?
- Sephr 7y agoThe list of Tor exit nodes is public. I can detect public Tor IP addresses and give them a different redirect with Zerodrop: https://eligrey.com/blog/zerodrop/ https://eligrey.com/blog/zerodrop/
- rubyfan 7y agoMaybe twitter could show something on the card “CNN.com via malicious.example.com”? Personally I like knowing when I’m clicking a tracked or affiliate link anyway.
- nkozyra 7y agoThis is probably the only viable choice other than randomizing user agents, which is dicey enough on its own.
- liability 7y agoI'm not sure how many people that would work for. If malicious.example.com were some pithy little domain on a trendy ccTLD like bit.ly, I think most twitter users would ignore it, assuming it was yet another URL shortener.
- jdietrich 7y ago>I’m thinking through how Twitter would combat something like this. Display the real link domain by default, but offer custom domains for manually verified advertisers. That obviously involves some degree of cost, but it's worthwhile to preserve trust in the platform.
- lozenge 7y agoFor ads they can verify domain ownership (TXT dns record, or verification file or HTML meta tag served from your domain). For links in Tweets, they can show the actual URL (domain part at least) instead of the t.co shortened URL.
- JetSpiegel 7y agoBut not using t.co means Twitter doesn't track every single click on their platform, defeating the purpose.
- caffeinewriter 7y agoThis isn't a new problem. Cloaking[1] has been around for a long time. Google[2], and Facebook[3] have been fighting this problem for years. Even Google hasn't had perfect luck with fighting off cloakers[4]. [1]: https://charlesngo.com/cloaking/ https://charlesngo.com/cloaking/ [2]: https://support.google.com/adspolicy/answer/6020954?hl=en#319 https://support.google.com/adspolicy/answer/6020954?hl=en#31... [3]: http://fortune.com/2017/08/09/facebook-cloaking-spam-advertising/ http://fortune.com/2017/08/09/facebook-cloaking-spam-adverti... [4]: https://wp.josh.com/2019/05/06/breaking-news-google-adwords-exploit-seen-in-the-wild-yikes/ https://wp.josh.com/2019/05/06/breaking-news-google-adwords-...
- TazeTSchnitzel 7y agoThere is a proper solution, and that is to show the actual URL. If that hurts URL shorteners and trackers, so be it.
- avian 7y agoVery likely this is the same issue that was recently discussed in the context of Google ads. Ad campaigns commonly use tracking redirects and it may be an intentional Twitter feature that the preview card hides intermediate domains. https://news.ycombinator.com/item?id=19858552 https://news.ycombinator.com/item?id=19858552
- simongr3dal 7y agoAs I understood it, twitter is following redirects to show the user the final destination in the card. The problem is the scammers recognise when twitter is generating the card and redirects twitter to a different domain than the what the actual user will be redirected to. The problem is that twitter follows the redirects to show the final URL, presumably to support advertising companies that use third-party link tracking software like bit.ly, if they just showed the actual link they wouldn't have this problem.