9 ms·
The URL shortener that makes your links look as suspicious as possible
- dreadsword 9mo agoSaw this on relaunched Digg and figured HN would appreciate it.
- koakuma-chan 9mo agoI don't appreciate how AI generated this website looks.
- 4k93n2 9mo agowhich bit are you getting an AI smell from?
- koakuma-chan 9mo agogradient background, card, button
- nimih 9mo agoIt seems appropriate that, for a website whose purpose is to make links which raise your suspicions, the visual design itself also raises your suspicions.
- olyjohn 9mo agoJust looks like every other generic framework oriented site.
- bundie 9mo agoDigg is back? Edit: looks like you need an invite code. Bummer
- qweiopqweiop 9mo agoNow that's a name I've not heard in a long time
- awesome_dude 9mo agoFor humour I shortened "https://www.facebook.com/ https://www.facebook.com/" And got https://twitter.web-safe.link/root_4h3ku0_account_verification.vbs https://twitter.web-safe.link/root_4h3ku0_account_verificati...
- vanc_cefepime 9mo agoI added google.com and it spit out https://twitterDOTc1icDOTlink/install_Jy7NpK_private_videoDOTzip Interesting that it spit out a .zip url. Was not expecting that so I changed all the “.” to “DOT” so I don’t get punished for posting a spammy link despite this literally being a website to make links as spammy and creepy as possible.
- bmacho 9mo agopunished by whom?
- gnabgib 9mo agoRelated: A URL shortener not shortening the URL but makes it look very dodgy (434 points, 2023, 100 comments) https://news.ycombinator.com/item?id=34609461 https://news.ycombinator.com/item?id=34609461
- Bengalilol 9mo agoThe key point here is "not shortening"
- vedmakk 9mo agoThat's less a URL shortener and more a URL dodgifier.
- tylervigen 9mo agoTo be fair, the one in the OP also did not shorten any of the links I gave it.
- CrimsonCape 9mo agoIt is hilarious and i'm not clicking any link lol.
- hnst1 9mo ago[dead]
- domoregood 9mo agoFor funsies I shortened https://creepylink.com https://creepylink.com And got: https://c1ic.link/account_kPvfG7_download_now.bat https://c1ic.link/account_kPvfG7_download_now.bat
- hahahahhaah 9mo agoSquared: https://c1ic.link/ad_k9OFWW_redeem_gift.bat https://c1ic.link/ad_k9OFWW_redeem_gift.bat
- archb 9mo agoI also tried that and got https://twitter.web-safe.link/BUuLrg_document.zip https://twitter.web-safe.link/BUuLrg_document.zip
- champagnepapi 9mo agohttps://jpmorgan.c1ic.link/G4JQKX_money_request.dll https://jpmorgan.c1ic.link/G4JQKX_money_request.dll
- html5cat 9mo agowell played sir
- reincarnate0x14 9mo agohttps://jpmorgan.web-safe.link/flash_7KzCZd_money_request https://jpmorgan.web-safe.link/flash_7KzCZd_money_request I love this version and I hope you do too.
- fancychancy 9mo agoHaha, it's fun. Just thinking, is there some place where creepy links would be better ?
- AnotherGoodName 9mo agoI've been at a company that internally sends out fake links that log the user and links to an educational page on internet safety. I honestly don't mind too much since it's a once a year thing (hacktober) and honestly companies should be trying to catch out employees who click any and all links.
- trollbridge 9mo agoWe used to have fun hammering millions of requests to such URLs from a VPS when they would send such emails to role mailboxes. Eventually we got asked to please make it stop. I asked them to please stop sending fake phishing emails to robots.
- CGMthrowaway 9mo agoUse case? Besides humor and phishing tests
- cr125rider 9mo agoFun!
- bityard 9mo agoIIRC, shadyurl was the original version of this. Doesn't seem to be around anymore, though.
- nomel 9mo agoshadyurl a whole bunch of different incredibly shady domains that were used at random. it was beautiful.
- arjvik 9mo agoMy favorite link of all time: https://jpmorgan.c1ic.link/logger_zcGFC2_bank_xss.docm https://jpmorgan.c1ic.link/logger_zcGFC2_bank_xss.docm Definitely not meta
- deleted 9mo ago[deleted]
- fuddle 9mo agoImagine using this as your personal website lol
- morshu9001 9mo agoemail too
- cuechan 9mo agoWith Firefox on Android it simply says Deceptive site issue This web page at [...] has been reported as a deceptive site and has been blocked based on your security preferences. What's going on? I can't find any setting to disable this.
- Yeri 9mo agoNextDNS is blocking it too (https://google.c1ic.link/lottery_qrdLCz_account_verification https://google.c1ic.link/lottery_qrdLCz_account_verification). The reason is that Google Safe Browsing considers that site as unsafe.
- fc417fc802 9mo agoTBF it ought to trigger even the simplest heuristics so it wouldn't surprise me if it was automatically categorized that way.
- bmitch3020 9mo agoI was able to get past that (Firefox on the Desktop) by clicking the "see details" button and then clicking the "ignore the risk" link. It took me a while to actually read the text too.
- pabs3 9mo agoPlease don't make any more URL shorteners, they are just a bad idea. https://wiki.archiveteam.org/index.php/URLTeam https://wiki.archiveteam.org/index.php/URLTeam
- aussieguy1234 9mo agoI always end up making my own, they're so simple to write. Saves using one of the "free" ones which looks like its free but you're actually on a free trial, then you can't access your links after that trial expires.
- blenderob 9mo agoWay to miss the point of the project!
- postalcoder 9mo agoThere may actually be some utility here. LLM agents refuse to traverse the links. Tested with gemini-3-pro, gpt-5.2, and opus 4.5. edit: gpt-oss 20B & 120B both eagerly visit it.
- devsda 9mo agoI wish this came a day earlier. There is a current "show your personal site" post on top of HN [1] with 1500+ comments. I wonder how many of those sites are or will be hammered by AI bots in the next few days to steal/scrape content. If this can be used as a temporary guard against AI bots, that would have been a good opportunity to test it out. 1. https://news.ycombinator.com/item?id=46618714 https://news.ycombinator.com/item?id=46618714
- jnrk 9mo agoOf course, the downside is that people might not even see your site at all because they’re afraid to click on that suspicious link.
- postalcoder 9mo agoSite should add a reverse lookup. Provide the poison and antidote.
- gala8y 9mo agoBitly does that, just add '+' to Bitly URL (probably other shorteners, too).
- xlii 9mo agoI posted my site on the thread. My site is hosted on Cloudflare and I trust its protection way more than flavor of the month method. This probably won't be patched anytime soon but I'd rather have some people click my link and not just avoid it along with AI because it looks fishy :)
- caminanteblanco 9mo agoI'm not sure what the use case for this is, but I've been using it as a inefficient messaging service with my girlfriend, ie: https://c1ic.link/campaign_WxjLdF_login_page_2.bat https://c1ic.link/campaign_WxjLdF_login_page_2.bat You seem to be able to encode arbitrary text, so long as it follows [A-Za-z0-9]+\.[A-Za-z0-9]+
- fuddle 9mo agolol, I'm not clicking a .vbs link
- jmward01 9mo agoThis had to be done: https://wellsfargo.c1ic.link/TODO_obfuscate_url_8wyS7G_hot_singles.msi https://wellsfargo.c1ic.link/TODO_obfuscate_url_8wyS7G_hot_s...
- bl4ckneon 9mo agoThought this might be it... I clicked it anyways haha. I will need to update the Rick roll url on my nfc implant with this new link!
- jhalderm 9mo agoFantastic! I miss the original ShadyURL. https://news.ycombinator.com/item?id=31386108 https://news.ycombinator.com/item?id=31386108
- dieggsy 9mo agoThis is fun. Is it not checking for previously submitted URLs though? I can seemingly re-submit the exact same URL and get a new link every time. I would expect this to fill the database unnecessarily but I have no idea how the backend works.
- saghm 9mo agoAm I missing something, or would these essentially be implemented via DNS records? It's not clear to me that keeping the links in a database would be necessary at all (unless the DNS records are what you mean by "database")
- janwillemb 9mo agoDNS is only for resolving the host part. The path is not passing through a dns query. In example.com/blah, the /blah part is interpreted by the host itself. And apart from that I would indeed consider DNS records a database.
- hinkley 9mo agoI got https://microsoft.web-safe.link/cZ17Xn_claim_gift_card.msi https://microsoft.web-safe.link/cZ17Xn_claim_gift_card.msi for this article. What do you get?
- dieggsy 9mo agoJust resubmit it, you'll probably get a new link. I get something different every time.
- abhinai 9mo agoPlease take my upvote. :)
- lzap 9mo agoI like how old-school HN comment section does not care about creepy links at all. Or link for that matter.
- zakki 9mo agoIs this suspicious: https://microsoft.c1ic.link/0B7jqd_invoice.vbs https://microsoft.c1ic.link/0B7jqd_invoice.vbs ?
- jimnotgym 9mo agoI think Microsoft have their own version of this Msn.com Office.com Sharepoint.com Hotmail.com Etc, plus all the subdomains they insert before them. It makes it very easy to create phishing emails that look plausible.
- Zambyte 9mo agomicrosoftonline.com is one of my favorites. Like how can you look any more scammy :D
- FuturisticLover 9mo agoI am sharing content using these creepy links to send to office people.
- thesebas 9mo ago[dead]
- qnleigh 9mo agoWhat's up with the creepy ads on this website? It seems like they are actually sketchy ads and not just fake ads for comedic effect. One shows some scammy nonsense about your device being infected and the other links to a real VPN app.
- lzzzam 9mo agoI can just say thanks
- olya_pllkh 9mo ago[dead]
- juliangmp 9mo agoThis is legit! If you disable your adblock you even get a suspicious ad
- phoe-krk 9mo agoI wouldn't call it a shortener, since most of the links it creates are longer than the originals. What would be a good name here? A URL redirector?
- johnisgood 9mo agoURL lengthener. :D
- phoe-krk 9mo agoHuh, https://loooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo.ng/ https://looooooooooooooooooooooooooooooooooooooooooooooooooo... comes to mind. Thanks!
- nephihaha 9mo agoSame here I took a six character url, and it turned into at least ten.
- kzrdude 9mo agoIt's an asymptotic link shortener
- Retr0id 9mo agolink obfuscator
- rendall 9mo agoThis is the best article on Wikipedia! https://c1ic.link/bzSBpN_login_page_2 https://c1ic.link/bzSBpN_login_page_2 Edit: Chrome on Android warned me not to visit the site!
- deleted 9mo ago[deleted]
- manthangupta109 9mo agolol
- bsza 9mo agoYeah but have fun explaining yourself to the police when the author abandons the project and an actual scammer ends up buying up all those domains.
- victorevogor 9mo agoJust wondering. so you bought c1ic.link and web-safe.link. That's very cool
- dizhn 9mo agoFirefox is freaking out on some of these. It's hilarious.
- vhurg 9mo agoPlease don’t use 3rd party relays for your URLs. It’s bad enough to have your own server, domain, etc. as single points of failure and bottlenecks without adding a 3rd party into the mix, who either themselves or someone that takes over their domain later track users, randomly redirect your users to a malicious site, or just fail. I know people have fond memories of long ago when they thought surely some big company’s URL shortener would never be taken down and learned from that when it later was.
- SilasX 9mo agoThis! I've run into very frustrating examples of legit sites doing that, for no defensible reason at all. For example, the healthcare.gov emails. For links to that domain, they would still transform them with lnks.gd, even though: 1) The emails would be very long and flashy, so they're clearly not economizing on space. 2) The "shortened" URL was usually longer! 3) That domain doesn't let you go straight to the root and check where the transformed URL is going. It's training users to do the very things that expose them to scammers!
- latexr 9mo agoI think it’s perfectly reasonable to make something useless for fun, it’s an interesting idea. But what I’d like to understand is why there are so many of the same thing. I know I’ve seen this exact idea multiple times on HN. It’s funny the first time, but once it’s done once and the novelty is gone (which is almost immediately), what’s the point of another and another and another?
- amne 9mo agoI think it's just someone learning something new most of the time. I have home made url shorteners in go, rust, java, python, php, elixir, typescript, etc. why? because I'm trying the language and this kind of project touches on many things: web, databases, custom logic, how and what design patterns can I apply using as much of the language as I can to build the thing.
- latexr 9mo agoRight. But the question is why redo the exact same joke? Why not come up with another twist (like the URL lengthener) or do no twist but be useful? I’m not criticising the author or anyone who came before. I’m trying to understand the impetus between redoing a joke that isn’t yours. You don’t learn anything new by redoing the exact same gag that you wouldn’t learn by being even slightly original or making the project truly useful. Ideas are a dime a dozen. You could make e.g. a Fonzie URL shortener (different lengths of “ayyyyy”), or an interstellar one (each is the name of a space object), or a binary one (all ones and zeroes)… Each of those would take about the same effort and teach you the same, but they’re also different enough they would make some people remember them, maybe even look at the author and their other projects, instead of just “oh, another one of these, close”.
- postalcoder 9mo agoA joke isn’t the best example because there are jokes that never changes but the delivery is a sign of mastery. The Aristocrats is like Bach’s cello suite for comedians.
- neuroelectron 9mo ago/instagram.c1ic.link/mCLIIp_free_vacation_offer.zip
- virajk_31 9mo agowhy do creepy links look creepy?...
- zX41ZdbW 9mo agoI would also like to have something like this, but for "vintage" links - something that looks like it was from the late 90s. I use them in tests, just for fun: https://github.com/ClickHouse/ClickHouse/blob/master/tests/queries/0_stateless/03150_url_hash_non_constant_level.sql https://github.com/ClickHouse/ClickHouse/blob/master/tests/q...
- eythian 9mo agoThere was a "shadyurl". The site itself seems to be long gone, but this'll give you some context: https://www.mikelacher.com/work/shady-url/ https://www.mikelacher.com/work/shady-url/
- Retr0id 9mo agoThere's an example shadyurl link in here: https://news.ycombinator.com/item?id=14628529 https://news.ycombinator.com/item?id=14628529 Funnily enough the domains appear to have been bought up and are now genuinely shady.
- deleted 9mo ago[deleted]
- _egtx 9mo ago[dead]
- TomMasz 9mo agoThis is great. It created a link to my personal site that Firefox blocked me from going to.
- codemogul 9mo agoBRILLIANT! Even Chrome says nope/DANGEROUS to a creepified link to mail.google.com
- CupricTea 9mo agoThe other day in a Facebook Messenger group chat I tried to link to https://motherfuckingwebsite.com/ https://motherfuckingwebsite.com/ as a joke, but Messenger kept blocking it. It's quite overzealous with its blocking.
- Avamander 9mo agoIt would've been top-notch if it actually sometimes just used Outlook/O365 or similar vendor's "safelinks" redirector that they use.
- falsedev 9mo agoI can't tell if the website works as advertised because I don't want to open the generated links
- thimkerbell 9mo agoAdd this to "HN for psychopaths" please.
- danielpetrica 9mo agoAs someone who built a standard shortener (coz.jp), this is hilarious. I spent so much time trying to make links look trustworthy; doing the exact opposite is a surprisingly fun concept.
- tcgv 9mo agoHole in one! I shortened a link and when trying to access it in Chrome I get a red screen with this message: Dangerous site Attackers on the site you tried visiting might trick you into installing software or revealing things like your passwords, phone, or credit card numbers. Chrome strongly recommends going back to safety.
- zefhous 9mo agoMy city utility provider used secured-server.biz for billing for a long time. I always thought it was hilarious and very suspicious looking.
- yc784567 9mo agoThis is cool, since the links are actually short, but for properly suspicious links I prefer phishyurl [1] . [1] https://news.ycombinator.com/item?id=45295898 https://news.ycombinator.com/item?id=45295898 edit: fixed typo
- autoexec 9mo agoEvery URL shortener is suspicious. While this seems like it would make it harder for them I wouldn't be surprised if scammers eventually try to abuse this service too and I have no doubt that people would happily click these if they found in them in a phishing email, that said I give the folks behind this a lot of credit for having a way to contact them and report links if that happens.
- unnouinceput 9mo agoMy link: https://update.web-safe.link/iy1bxm_money_request https://update.web-safe.link/iy1bxm_money_request
- snehalbaghel 9mo agoImagine someone compromises apps like these and replaces the creepy looking links to actually dangerous links
- arthurezende 9mo agoIt's so creepy my corporate VPN blocked it
- lasgawe 9mo agohaha I love this