4 ms·
Crockford used to prevent hotlinking to his JSON library (its now on github) in an interesting way: right at the top there was an alert() line that you had to r
by zbanks 16y ago
Crockford used to prevent hotlinking to his JSON library (its now on github) in an interesting way: right at the top there was an alert() line that you had to remove before using.
This would probably be the best way to transition. If they add an alert to their library and leave it up a week, most people should notice and fix it.
- orblivion 16y agoIf Crockford used it in production though, the alert() would be removed there, right? So someone could still in theory hotlink that.
- deleted 16y ago[deleted]
- Nycto 16y agoUnless jquery.com itself uses Google's CDN (which it already is for some of its javascript)
- jerf 16y agoif (location.host.search(/crockford.com$/i) != -1) { alert("Stop hotlinking me!") } I don't think you can fool that, but I'd love to hear about how I'm wrong.
- adamdecaf 16y agowindow.alert = function () {};
- tlrobinson 16y agoif (location.host.search(/crockford.com$/i) != -1) { throw "Stop hotlinking me!"; }
- simonsarris 16y agoYou code should read != 0 to have the desired effect. And even then, this can bypass it: var temp = String.prototype.search; String.prototype.search = function() { return 0}; if (location.host.search(/crockford.com$/i) != 0) { throw "Stop hotlinking me!"; } String.prototype.search = temp; Though that may cause other problems.
- tlrobinson 16y agoMy point was that it's just a game of cat and mouse. I could come up with lots of workarounds for almost anything you throw at me. Example: var expectedHost = "crockford.com"; if (expectedHost.length !== location.host) throw "Stop hotlinking me!"; for (var i = 0; i < expectedHost.length; i++) if (location.host[i] === expectedHost[i]) throw "Stop hotlinking me!"; (though it string[x] might not work in every browser) So thanks for further demonstrating my point! But really, just check the referrer header.
- jerf 16y agoPoint. I was unclear in my phrasing, I was more looking into just not accidentally bypassing it. Deliberately bypassing it probably can't be stopped but really at that point you've already lost. Given what I've seen in the world somebody grabbing an existing proxy script and regexing out the check and never once stopping to think this is way worse than hosting the file yourself wouldn't even make me blink.
- deleted 16y ago[deleted]
- hk9565 16y agoYou can definitely fool that: http://www.adambarth.com/papers/2009/adida-barth-jackson.pdf http://www.adambarth.com/papers/2009/adida-barth-jackson.pdf
- axod 16y ago<script> var oldAlertFunction = window.alert; window.alert = function(){}; </script> <script src="crockford.com/json.library.js"></script> Arms race, but just sayin'
- alex_c 16y agoThe point would be to give webmasters a heads-up and time to fix their sites before hotlinking is disabled, not so much to prevent them from using the file.
- axod 16y agoIndeed. I was just being silly :)
- MBlume 16y agoAnd if you want to avoid changing the rest of the page: <script> var oldAlertFunction = window.alert; window.alert = function(){}; </script> <script src="crockford.com/json.library.js"></script> <script> window.alert=oldAlertFunction; </script>
- nerfhammer 16y agoAnyone smart enough to think of that would be smart enough not to hotlink