5 ms·
This feels like such a weird ask? Why would anyone do this, so their content can be easily read elsewhere potentially with a load of ads surrounding it? This
by hvb2 7mo ago
This feels like such a weird ask?
Why would anyone do this, so their content can be easily read elsewhere potentially with a load of ads surrounding it?
This seems to really reason through only the happy path, ignoring bad actors, and there'll always be bad actors.
- bigstrat2003 7mo agoAlso, why would an RSS reader be a website? An application installed on your PC is superior in every way.
- socalgal2 7mo agoUm, no? the most popular RSS reader back when RSS readers were a thing was Google's. It was a website. And why not. Like other websites, you can log in from any device that has a browser and immediately pick up where you left off, including work machines where you aren't allowed to install native apps.
- staticassertion 7mo agoI couldn't feel more strongly in the other direction. The fewer programs running on my computer, the better. By far my preference is that "random dev code" gets placed into the strongest possible sandbox, and that's the browser.
- adhamsalama 7mo agoSo, about that...That's how I read RSS feeds on my Kindle. https://github.com/adhamsalama/simple-rss-reader https://github.com/adhamsalama/simple-rss-reader
- mr_mitm 7mo agoWith a website you get shared state (these days many people are using multiple devices), platform independence and sandboxing for free. Plus custom CSS and tamper scripts for customization, browser addons, bookmarks, an API for other applications to consume the content, and probably more.
- ef2k 7mo agoTo be fair, they do explain their motivation. It's an in-browser RSS reader, so it's fetching the RSS feed directly without a proxy server. There's not much risk since the content is public and non-credentialed. The bigger risk is misconfiguring CORS and inadvertently exposing other paths with the wildcard.
- onion2k 7mo agoThis seems to really reason through only the happy path, ignoring bad actors, and there'll always be bad actors. True, but the bad actors can defeat any security mechanism you put in place with a proxy, or a copy'n'paste, so the downside risk is pointless worrying about. The upside of allowing traffic is that your content that you presumably want people to read can be read by more people. For all but the most popular blogs that's probably a net benefit.
- sheept 7mo agoIf a malicious website wanted to copy a blog's website to put ads on it, they already can just copy it outside of the browser on their end, which has the "benefit" of preventing the original blog from taking the post down. CORS also doesn't prevent a popular website with a personal vendetta[0] against a blogger from DDOSing the blog with their visitors, since CORS doesn't block requests from being sent. For a purely static website, there shouldn't be any risk from enabling CORS. [0]: https://news.ycombinator.com/item?id=46624740 https://news.ycombinator.com/item?id=46624740
- hvb2 7mo agoSure but copy and pasting stuff isn't a practical solution? The DDOS angle is unrelated? You can do that whenever you want. The risk is other people profiting/taking credit for your work. If all of this is true, why does anyone put a license on any software? It doesn't mean someone can't copy paste, but it gives them recourse. Enabling CORS is completely giving up any recourse you have IMHO
- trick-or-treat 7mo ago[dead]