15 ms·
Twitter is rejecting posts containing JSFiddle URLs
- ecares 7y agoI feel it's actually pretty fair. Not perfect, but keeps users safe
- envolt 7y agoSo is Net Neutrality. Ensures that random sites (new sites) doesn't distract you.
- gear54rus 7y agoYeah it keeps users from getting smarter and blocks large part of web community from performing their day to day tasks. So 2 birds with one stone, eh? Maybe these fat corporate aholes could sell the option as a paid tier and make it 3 :D
- mattigames 7y agoExcept they will now use github pages; and if they block all github pages (github.io) they will use codepen or repl.it or tumblr (custom templates), and so on until thousands of page are blocked.
- martin_a 7y agoSounds somewhat like a "Win" to me. Twitter will die in doing so, I don't see anything getting lost there anymore.
- lifthrasiir 7y agoThere are tons of other websites you can host a crypto script. If Twitter really wants to keep users safe, they should implement a mandatory warning (I've seen this being referred as a "cushioning" page) instead of having a questionable blacklist.
- yahwhatev 7y ago> They most likely have no-explanation-needed-policy I wonder when alternatives to today's big sites will take serious root. It used to happen much more often.
- vermontdevil 7y agoIt’s due to crypto scammers using it. From the founder’s post: At some point in the past crypto scammers used JSFiddle to host pages with a wallet code and posted links to that on Twitter. Due to the nature of JSFiddle, anyone can post anything, so wallet codes are ok – we did implemented a content filter to shadow-ban these. I asked Twitter if they they could help out and ban twitter accounts that were posting scam tweets that included links to the rouge fiddles. Twitter just went the easy route and blocked all jsfiddle.net links instead of blocking spammer accounts on their platform. Tried to contact Twitter many many times, with no reply whatsoever. They most likely have no-explanation-needed-policy, which is why they never replied. There's nothing that can be done here unless somebody has contact to a higher op at Twitter who has the decision power to help out here.
- codedokode 7y agoI don't understand how posting a "wallet code" is dangerous. Is it mining coins while you are browsing the code? Then it just a minor annoyance. Also, browsers should block cryptominers when they are in the background tab.
- tannhaeuser 7y agoBlocking cryptominers or other script isn't possible because of JavaScript's nature as Turing-complete language, much less with new shiny WebWorkers/PWAs. It's also not just a minor annoyance when miners, trackers, and all kinds of other nefarious or just plain garbage scripts drain your batteries and consume power/bandwidth for no other reason than browser vendors being busy to develop webapp platforms and world domination schemes rather than declarative and privacy-focussed content consumption/authoring ... browsers.
- solarkraft 7y agoYou can detect crypto miners pretty easily by their behavior.
- 7y ago
- andybak 7y agoIt troubles me that something as well known as JSFiddle can't get a response from Github. I understand they can't reply to every question from Johnny Developer but JSFiddle must have thousands of users.
- akuji1993 7y agoThey didn't get a response from Twitter. Github isn't really part of this.
- deleted 7y ago[deleted]
- vfc1 7y agoGiven the nature of the product, there is no way for the maintainers of Js fiddle to prevent it from being used to run arbitrary code, because that is what it's meant to do. It's also impossible for both jsfiddle or twitter to scan the code of each fiddle and determine if it's legitimate or an attack, so this looks like a good measure from Twitter. What is surprising is how this was even allowed so far and still is in many social networks, as its such an obvious way to deliver exploits.
- mixedbit 7y agoShould Twitter also ban links to Amazon S3 or any other cloud storage? It can also be used to host arbitrary JavaScript.
- jaggirs 7y agoIt makes sense to ban a website that is 100% mining, but blanket-banning jsfiddle is like banning the whole internet because there might be a crypto miner on any website. Probably 99% of jsfiddle links are not miners.
- maaaats 7y agoCouldn't any link point to anything that runs arbitrary code? Does it matter if it's on jsfiddle or xyz.com?
- onion2k 7y agoGiven the nature of the product, there is no way for the maintainers of Js fiddle to prevent it from being used to run arbitrary code, because that is what it's meant to do. There are things they could do though - such as limiting the execution time of a fiddle to a couple of minutes, or limiting the size of the code, or blocking certain calls, and so on. Users are running code that's been saved to the JSFiddle server, so it's not unreasonable to suggest JSFiddle have some responsibility to their visitors. They could make it so the code runs fine if you're the owner or if you've explicitly said it's OK to take up more resources, but defaults to running with these limits if you've just browsed to a Fiddle from a link. They could block common mining scripts (which would only work against 'scriptkiddie' attacks rather than anything sophisticated, but whatever). There are things the JSFiddle maintainers could do. They don't have to, and in their position I might not do anything either, but the cost of inaction in this case is Twitter blocking links to their site.
- djsumdog 7y agoJSFiddle is big. They tried. They voiced concerns. They asked foe help. They got a ban with no explanation. Please just join the fediverse. It's broken too, but if you get banned, at least you can open an alt on another server. Force Twitter to be irrelevant.
- FreeHugs 7y agoThe problem is: I have yet to find a person in the fediverse that interests me. I like to read tweets from accomplished people. Successful startup founders for example. Is there anybody out there? Any links to people of significance in the fediverse?
- djsumdog 7y agoDrew Dewalt. Richard Stevens (Diesel Sweeties) and wait ... why do you give a shit? Why do people have to be famous to be relevant? Follow random people. Remember 90s AOL chatrooms?
- oblio 7y ago> Why do you give a shit? Why do people have to be famous to be relevant? Follow random people. Plan A: Use Twitter (or other media like it). Plan B: Change human nature. I wish you good luck in your endeavour with Plan B, djsumdog! :)
- arcturus17 7y agoThis comment is vintage open source jihadism.
- scrollaway 7y ago> why do you give a shit? Given your tone, I'm going to guess you're not asking the GP a question in earnest. You should try to think about why they might "give a shit". Twitter's userbase is its primary feature. Not its shitty UI, not its awful character limit, and none of the stuff mastodon's various UIs are copying. Its userbase. If you want the fediverse to succeed, you need to understand that. And you need to stop being so accusatory of people who don't use the internet the same way you do, FFS. (And for the record, I want the fediverse to succeed, but I also use Twitter because userbase)
- Timucin 7y ago> Twitter just went the easy route and blocked all jsfiddle.net links instead of blocking spammer accounts on their platform. This is a huge problem with all the tech giants that needs to be addressed. I don't expect them to be perfect but I expect them to be open to communications on any level. I also think Twitter is the Twitter today just because of the bots and fake accounts they have since those accounts were creating so much content and movement on the platform. I know people whose spending days by reading those fake accounts while they have no idea what's fake and what's real. So maybe -just may be- they may not want to get rid of all those fake accounts and bots.
- banachtarski 7y agoI just don't agree with this sentiment. I don't work for twitter or any social media company, but it strikes me as their prerogative to ban content deemed unsafe if they don't have the means or wherewithal to properly police the content. From an engineering standpoint, how exactly do you propose to scan fiddles for objectionable content. With an image link, you could throw a neural net at it and at least tag it as nsfw (or scan a few images in a linked page). And this isn't related at all to the bots and fake accounts (which I think is the bigger problem). But in the context of your argument, this is just non sequitur.
- IggleSniggle 7y agoOk, but they’re not blocking CodePen etc. And furthermore, you don’t even need a JSFiddle/CodePen whatever, you can run it on any website that you can edit code on! Is github.io next to be blocked? How about any unrecognized website? That JSFiddle has been targeted by this action is absurdity.
- dwild 7y ago> their prerogative Thus any business decision isn't a problem? Whether it's their prerogative, it still a problem in tech. > to ban content deemed unsafe Like any links? Or even text itself? The only thing that makes JSFiddle "worst" is how easy it is, but even then almost anything else is just as easy. If there's money to be made too, unless you block everything that cost less than the money to be made, what you do won't stop it. Why not just put that warning over EVERY single links and not block anything? Do a white list instead.
- diveanon 7y agoAt what point is the tech community going to abandon twitter? From my perspective it is just bots, "influencers", and propaganda. I see very little social utility for using the network, especially when compared to the damage it is causing through the spread of misinformation and outright lies.
- stevekemp 7y agoFrom your perspective it is just bots, "influencers", and propaganda. From my perspective it's the everyday chat of my friends, and interesting security-researchers posting their findings. It's also a randomly acquired group of people I follow to improve my ability to read the Finnish language.
- dmix 7y ago> From my perspective it's the everyday chat of my friends, and interesting security-researchers posting their findings. I wish this was true. I’ve struggled for years to keep my feed about the tech topics I’m interested in. Twitter keeps making that harder and harder. Now twitter force feeds every viral anti-Trump or political outrage tweet, liked by some random user I followed 4yrs ago, into my main feed. Their insistence on choosing what content I want to see for me, instead of just the feeds of the people I opted-in to follow, has made it nearly impossible to avoid the cancerous US political and other social issue outrage machine which is what 90% of Twitter’s popular content seems to be. I had no choice but to abandon Twitter. Unfollowing people who post political stuff was hard enough, unfollowing people who use the like button on political/outrage stuff plus other viral content that surfaces the highest is near impossible. I hope Twitter makes a ‘retro’ mode where I can just see the actual tweets of only the people I follow in semi-chronological order. With the same option to turn off retweets for certain users, with no "liked" or trending tweets forced in.
- luu 7y ago> I hope Twitter makes a ‘retro’ mode where I can just see the actual tweets of only the people I follow in semi-chronological order. With the option to turn off retweets for certain users. I think both of these exist? There's a way to turn off retweets for particular users (it's in the same menu you'd use to mute or block someone) and there's an option to show a plain timeline (uncheck "show the best tweets first"). The plain timeline option doesn't seem to consistently work on the mobile app, but many (most? all?) alternative Twitter clients show you the plain timeline.
- vanderZwan 7y agoWhat I find strange how this is presented as an either-or option between banning and not banning. You can also have an intermediate warning page. YouTube does this to any third-party website for example. Something like "Warning: JSFiddle has been abused by spammers to run crypto mining scripts. We recommend that you that you do not continue to this JSFiddle page unless you trust the source of the link" should work just fine, no?
- luu 7y ago[Edit: whoops, misread the issue. Sorry!]
- vanderZwan 7y agoThanks for clarifying that you misread, but please keep the text or at least enough contextual information so we know what the replies to you are talking about. Which link did you edit out? Because I missed it.
- bestnameever 7y agoPer the text, the screenshot you are seeing is what happens when someone links to a jsfiddle using a url shortner but posts linking directly to jsfiddle are rejected. >Twitter is rejecting posts with JSFiddle URL inside. >If a URL shortener is used the unsafe page warning is displayed[1]
- danmur 7y agoI think that screenshot was from a link posted with a URL shortener. Weird that it makes a difference.
- skrebbel 7y agoTwitter doesn't exactly target the kind of demographic that understands what "to run crypto mining scripts" even means, let alone how to assess whether they "trust the source". I mean, it was retweeted by someone I follow and it has a funny picture of Trump with a dancing turd emoji on his head, what's there not to trust? It's extremely hard to coach non-technical users into making the right call when presented with a security warning box. That said, if Twitter can assess whether a posted video contains "sensitive material" (i.e. exposed body parts), they can also assess whether a jsfiddle link (or any link, really) likely contains crypto miners.
- deleted 7y ago[deleted]
- polymath_potato 7y agoTwitter is crazy. Recently I tried to change my gmail account to a more secure encryted email on my Twitter account but they never let me confirm that email to my account. It always remained pending even though I clicked confirmation links several times. When I went ahead and reverted the email to original gmail account, everything was done seamlessly within seconds. I've had many similar problems with Twitter for years. The Spam Accounts, getting locked for apparently following 'too many' people in a short period of time, clicking confirmation links multiple times, etc and now this.
- aquova 7y agoOut of curiosity, I went onto Twitter and tried to post a link with one of the similar sites as JSFiddle. It seems that CodePen URLs are still allowed. This seems very strange to me, as unless I'm missing something, CodePen has the same inherent faults as JSFiddle. Twitter clearly has taken the easy way out here, and instead of addressing the problem and tried to tackle it, just blanket banned JSFiddle with no regard to their users, or to the variety of similar services that provide the exact same functionality. If I was a crypto miner, I would simply copy paste into CodePen and continue on my way.
- megous 7y agoAny website can have a miner, outside of some safe content only sites. It may as well be, that in some distant future, users of social sites will be able to link only to other pre-approved major social sites. You can't even link on most of these websites without going through some intermediary URL forwarder.
- tveita 7y ago> Due to the nature of JSFiddle, anyone can post anything, so wallet codes are ok – we did implemented a content filter to shadow-ban these. > I asked Twitter if they they could help out and ban twitter accounts that were posting scam tweets that included links to the rouge fiddles. So they basically sent a message to Twitter saying "We're knowingly hosting malware and we don't intend to remove it, here are some examples"?
- a012 7y agoDid you read the actual block quote? > we did implemented a content filter to shadow-ban these JSFiddle shadow-ban these scam accounts, and they asked Twitter to do the same but Twitter bans _all_ JSFiddle URLs instead.
- tveita 7y agoI may be misinterpreting them but from the "wallet codes are ok" part it sounded like they weren't banning them. If by shadow ban they mean the link is completely inaccessible to other users then I'll agree that they were doing their part and banning links to their site was excessive.
- Ravengenocide 7y ago"Due to the nature of JSFiddle, anyone can post anything", therefore "wallet codes are ok" since "anyone can post anything". A shadow ban normally means that you, the creator, can see your content, but nobody else can. So them shadow banning people who post wallet codes is the direct opposite of allowing wallet codes.
- gatherhunterer 7y agoTwitter was being used to disseminate malware and addressed it in a way that hurt another platform without fixing their own. JSFiddle took a reasonable approach that did not affect Twitter and left their product offering intact while punishing bad actors. Twitter slapped a “JSFiddle bad” band-aid on the problem that does nothing to address the problem of Twitter being used to spread malicious content. Instead of using their size to do more Twitter uses it to do less.
- userbinator 7y agoA reminder that you don't need to technically link in order to refer to a link, nor even mention the site directly: "See JSviolin xxxxx" If anyone gets confused, simply reply "replace violin with synonym starting with f"... This reminds me of when YouTube banned URLs in comments (I don't think they do anymore), so people started posting pieces of them (like video IDs, the part after watch?v=...) with hints instead: "see video xxxx". Likewise, I can refer to this page with "see HN 20122583". The loss of being able to post a link is not good, but in no way does it absolutely stop communication. In fact, it will just cause "euphemisms" to appear, and further exercise human creativity.
- nashashmi 7y agoI think these euphemisms are healthy. better than posting the entire link. Similar to the @ and # handles.
- rchaud 7y agoThat workaround reminds me of phpBB Forums that blocked URLs, so users would spell them like "hxxp://www..."
- jrockway 7y agoSpeaking of removing links... in Overwatch there is a character called D.va. The Overwatch League twitch chat removes all links, meaning that if you mention her, other users see it as "" instead of "d.va". It's amazing.
- chrisacky 7y agoThis is a little offtopic, although I suppose there's a tangential link to JSFiddle getting no response from Twitter.. I too have failed in getting a response from JSFiddle.. About 70 days ago, I accidentally posted an anonymous submission to JSFiddle. There was no excuse for this other than human error. I was working on development and production at the same time and copied a users personally identifiable from an email template that our production env sent out instead of development. The development is all sanitised but the prod contains the user's name, email and an order reference ID and what they ordered. I submitted a take down request within 10 minutes of submitting at: https://airtable.com/shrm1ACZfg5PsTaUa https://airtable.com/shrm1ACZfg5PsTaUa Every day for a week I altered the reason. It's still not been taken down. I've tried the GDPR route, the copyright route.. I didn't get a single response from them and the page was still being hosted on their site despite many many _MANY_ attempts to have it removed. Update/Edit: Been contacted by JSFiddle directly and appreciate contact in helping resolve above.
- WrtCdEvrydy 7y agoSo, let me get this right... You, a software engineering professional copied a user'name, email and order reference ID, two of which are PII into an online service... on purpose.
- code_duck 7y agoYes, and they admitted error and the issue they're describing is that it was very difficult to rectify the error.
- blauditore 7y agoThis reminds me of how Russia banned Reddit because of one post of some dude describing how to grow shrooms at home.
- intrasight 7y agoAll links should be blocked IMHO. If you have something to say (in 280 characters) say it. If you have more to say, I'll find it on your blog.
- celeritascelery 7y agoHow will you show me where your blog is?
- ltc5505 7y agoI was going to make a joke, but actually a good answer to this is that users could just direct people to checkout their blog linked in their bio. This is assuming the person you are responding to didn't mean block all URLs from the site; just from tweets. Technically it doesn't solve the scam problem though: "I'm definitely the real Elon Musk. No question about it. Click the link in my bio to get 40 ETH, but you need to send me 20 ETH first so that I can verify things."
- intrasight 7y agoIt's in your bio
- Retra 7y agoHow is "go to my bio for a link" better than just providing the link?
- intrasight 7y agoAvoids the slippery slope of those links. I say ban them.
- tedunangst 7y agoWhat if I want to link to somebody else's blog? Or a hacker news comment?
- 7y ago
- Ensorceled 7y agoHow many people are actually linking to valid JSFiddle links from Twitter? This might have just been a math decision (X% malware > x% good links). I have my own problems with Twitter, but a social media site with a LOT of non-technical users blocking access to a site specifically designed to run anonymous code in their browser doesn't make me want to break out my pitchfork ...
- duxup 7y agoI think the math would then lead to only big sites being "good enough" to pass the twitter test as to who gets a whole domain filtered or not, and if you're running a site that someone does a bad thing on ... so much for anyone linking to you anymore on Twitter. That seems inherently bad.
- dmix 7y agoTwitter et al have already decided to become the self-anointed gatekeepers of what’s okay to post on the internet. I missed the days when it was just Google search results we had to worry about.
- Ensorceled 7y agoAgreed. I just think this isn’t an example, or at least not an example of the worst of it. I can’t think of any legitimate reason for my cousins who are on Twitter would want to go to JSFiddle. I’m ok with Twitter taking this stance. I’m not ok with many of the other policies.
- Ensorceled 7y agoThat’s not entirely my point. The whole point of JSFiddle (which I love) is at odds with the bulk of the demographic of Twitter. If your content sharing site inadvertently has malware you can remove it, JSFiddle will always be risky. The bulk of the people I follow on Twitter would have no clue what it was or how to even begin to understand it.
- 7y ago
- elcomet 7y agoI don't understand the difference with any other website. What prevents the scammers to post links to a website containing crypto miners, or any malware ?
- themacguffinman 7y agoIt doesn't stop scammers in their tracks, it just makes it harder. With dedicated scam websites, there is an actual cost to procuring new site addresses to evade domain blacklists, and they can't piggyback off jsfiddle's domain credibility.
- code_duck 7y agoI find messages like this frustrating. Facebook will show a generic 'this action could not be completed at this time' page, which is very vague and attempts to deflect their decision onto a nonexistent technical problem.