5 ms·
Funny how how all the links, including the ones to their own pages, are routed through google.com/url, e.g. the link "Assets Available to Download". Usually tra
by _flux 9mo ago
Funny how how all the links, including the ones to their own pages, are routed through google.com/url, e.g. the link "Assets Available to Download". Usually tracking isn't quite this visible.
- afandian 9mo agoIt is very odd. I don’t see a good reason, not even tracking.
- jmathai 9mo agoAren't those just the URLs in google search results if you copy from the results page instead of clicking through to the destination?
- esrauch 9mo agoThe reason for the intermediary is because the clickthrough sends the previous URL as a referer to the next server. The only real way to avoid leaking specific urls from the source page to the arbitrary other server is to have an intermediary redirect like this. All the big products put an intermediary for that reason, though many of them make it a user visible page of that says "you are leaving our product" versus Google mostly does it as an immediate redirect. The copy/paste behavior is mostly an unfortunate side effect and not a deliberate feature of it.
- afandian 9mo agoI don't understand. They are redirecting to their own S3 bucket, so who would be the recipient of the leak? Also, isn't this what Referrer-Policy is for? https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Referrer-Policy https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/...
- giancarlostoro 9mo agoQuoting web standards, you are more optimistic than I am, unfortunately, nobody uses them consistently or accurately (look at PUT vs POST for create / update as a really good example of this - nobody agrees) its a shame too, there's a lot of richness to the web spec. Most people don't even use "HEAD" to ensure they aren't making wasteful REST calls if they already have the data.
- afandian 9mo agoI was replying to > All the big products put an intermediary for that reason Surely whoever maintains the big products can add headers if they want? And this is about people who care enough about not showing up in Referer headers to do something about it rather than people in general not understanding the full spec .
- giancarlostoro 9mo agoThe other problem is if you're too big like Google, you cannot assume everyone will honor this, which is why they do these redirects.
- afandian 9mo agoReferrer-Policy is a response header, so in this case it would be Google sending it, and the browsers who would be honouring it. You have to hope that the browser makers get it correct... Unless I misunderstood?
- esrauch 9mo agoI worked on these big web products before and the answer then was that no, you couldn't trust it to be honored and it would have been considered a privacy incident so better off just having the redirect and having no risk. You can't trust the useragents for example. Not sure if the reliability of the intentional mechanism has improved enough where this is just legacy or if there's entirely new reasons for it in 2026.
- 9mo ago
- lionkor 9mo agoNot if you use the ClearURLs addon ;)
- reddalo 9mo agoIt's because their blog is hosted on blogger.com (yeah, weird decision), which is owned by Google and does that by default.
- XCSme 9mo agoI also have a blogger.com blog. Why? Because I had it for 20+ years, and I still didn't find an easy way to automatically migrate it to WordPress.
- wijwp 9mo agoYou're also presumably not a $400m+ company, which makes it more intestesting.
- XCSme 9mo agoMy point was that it's not trivial to migrate away from blogger.
- yunnpp 9mo agoI assure you no amount of capital trivializes the endeavour of migrating to/from Wordpress. GP speaks wisdom.
- Aurornis 9mo agoIn my experience, the blog usually falls in some weird space where the marketing team owns it somehow. It’s best to leave them be and let them handle it, because if you suggest an alternative and then something goes wrong or isn’t to their liking you’ll never hear the end of it.
- jonny_eh 9mo agoClearly engineers at Netflix have more important work to do.
- cfn 9mo agoAnd when I click them I get a page with "Did you mean netflix.com? The site you just tried to visit looks fake. Attackers sometimes mimic sites by making small, hard-to-see changes to the URL." which then sends me to the Netfçix home page. Chrome on MacOS.
- giancarlostoro 9mo ago...how is that even possible?
- bstsb 9mo agoit's because their s3 bucket is called "download.opencontent.netflix.com.s3.amazonaws.com". the subdomain makes chrome think it's pretending to be "netflix.com"
- IggleSniggle 9mo agoBut they said it sends them to Netfçix? That seems incorrect
- philsnow 9mo agoThe ios gmail app does the same thing, but why? I would assume the app could just transparently relay the click through its already-open grpc channel to google's servers, and it would be faster for them and (more importantly) for me.