6 ms·
Google Warns: bit.ly Links Are Unsafe
- novium 12y agoCan't this just be bit.ly links to unsafe sites? That dosen't make bit.ly unsafe as a whole.
- DyslexicAtheist 12y agoagree, it's a bit like saying emails from unverified senders are a threat because they may be malicious. true but obvious
- justincormack 12y agoYes it does, as you cannot sanely identify what the link is first.
- mcintyre1994 12y agoJust FYI, you can append a + to a "bitlink" to preview it's url and see some stats. http://support.bitly.com/knowledgebase/articles/136551-can-i-preview-a-bitlink-before-clicking-on-it http://support.bitly.com/knowledgebase/articles/136551-can-i...
- justincormack 12y agoSure. I said "sanely".
- gpvos 12y agoYeah, like that's obvious or well-known.
- r721 12y agolongurl.org is awesome to check what is behind a shortened URL. Has an API too: http://longurl.org/api http://longurl.org/api
- corobo 12y agoHTTP has an API for that too, just make a HEAD request to the shortened URL and see where the Location header sends you
- kuschku 12y agoYeah, sadly doesn’t always work. Goo.gl and youtu.be sometimes send an http page consisting of <!DOCTYPE html> <meta http-equiv="refresh" content="0; url=https://www.youtube.com/watch?v=opoDBF_b-fg&feature=youtu.be"> https://www.youtube.com/watch?v=opoDBF_b-fg&feature=youtu.be... Which makes it far more complicated. Another occasion where it’s appropriate to say “Fuck you, Google!” (also fuck you for disabling audio/video control on chrome mobile from JS, EXCEPT for google.com/youtube.com etc)
- warfangle 12y agoUmmm... Html5 audio/video api works just fine on chrome mobile. IOS safari is the bad actor, there ;)
- kuschku 12y agoUmmm..., no? In Chrome mobile you can only do for example .play() on an audio or video element, if you call it from an eventListener that reacted to an onClick event.
- warfangle 12y agoWell, yes. You have to initiate things that could cause bandwidth use from a user interaction instead of, say, a timeout or an XHR or a DOMContentLoaded. youtube follows the same rules as everywhere else: it doesn't autoplay. Unless you're unwittingly opening youtube urls in the app instead of chrome. iOS on the other hand actually -does- initiate bandwidth use on a <video> element, even if no interaction has taken place. If you watch Charles during an iOS video session, you will see 2-3 HTTP GETs before you even initiate playback. This can play merry hell if with your HTTP logs, if you pay attention to that sort of thing. iOS also has major issues with multiple <video> elements; <video> must be full-screen on non-tablet i-devices (you cannot create custom controls); you cannot control volume via the user interface; it uses a nonstandard progression for its status-related events... (and sometimes they're just plain missing)... I've spent the past few years working on web media players for mobile and desktop ;) I kind of know what I'm talking about. And due to its position in the marketplace, iOS Safari has stagnated - it's easier to get HTML5 multimedia working correctly in IE11 than iOS Safari. iOS Safari is the new IE6.
- petercooper 12y agoGoogle is definitely not a fan. I send a lot of email each month (it's my business) and having bit.ly links in mail is a fast track to Gmail's spam folder or, in some cases, being rejected entirely. (Note: I'm talking bulk mail, not personal mail.)
- eps 12y agoI hate getting emails with proxied links, bit.ly included, because it's an in-your-face "I want to track you" statement. Never open them and unsubscribe after a couple of strikes. Your audience may be different, but I can't say I disagree with Google junk'ing your emails.
- petercooper 12y agoThey're not junking my mails anymore because I'm not stupid enough to include bit.ly links ;-) However, clicks are still tracked in the majority of non-personal email nowadays, mostly using the click tracking provided by the large mail service providers, it's just not bit.ly.
- PhasmaFelis 12y agoWhy would you use bit.ly links in email?
- corobo 12y agoto track whether people open them or not
- warfangle 12y agoBecause they want to track clicks on links to URLs that they don't control the content of. Otherwise they'd be using utm_ query parameters and an in-site analytics system. Bitly links in email are super super shady.
- troels 12y agoAre they though? They could just set up their own redirection service on their own domain - not anything complicated in that. My guess is they use it because it's just a simple way for marketing to add some analytics - that doesn't have to be shady.
- randunel 12y agoMicrosoft could swoop in and solve this :D https://www.noip.com/blog/2014/06/30/ips-formal-statement-microsoft-takedown/ https://www.noip.com/blog/2014/06/30/ips-formal-statement-mi...
- ChrisGranger 12y agoAny URL shortening site that doesn't have an active block list is likely linking to some unsafe sites. Singling out bit.ly in this instance is frankly unfair. Guess who else Google warns is linking to unsafe sites: https://www.google.com/safebrowsing/diagnostic?site=google.com https://www.google.com/safebrowsing/diagnostic?site=google.c...
- anoncow 12y agoCan somebody explain the part where it says "google.com has infected plus.google.com" and other websites in your link?
- dsl 12y agoSomeone with a Google Plus account embedded content (likely a block of JavaScript, iframe, or Flash object) from a bit.ly URL. That content was in turn deemed malicious.
- rapcal 12y agogoo.gl too, with nearly 6,300 links to Trojans, way more than on the bit.ly report: https://www.google.com/safebrowsing/diagnostic?site=goo.gl https://www.google.com/safebrowsing/diagnostic?site=goo.gl
- abraham 12y agoAlthough for goo.gl "6292349 pages we tested on the site over the past 90 days, 826 page(s) resulted in malicious software" and for bit.ly "91856 pages we tested on the site over the past 90 days, 721 page(s) resulted in malicious software". The % of pages on goo.gl with malicious software is much lower.
- deleted 12y ago[deleted]
- sumnulu 12y agoNot using google but also safari warns about malware via google some how.
- dewey 12y agoThat's because Safari is using "Google Safe Browsing Service" - You can toggle that in Preferences/Security.
- rapcal 12y agoEvery bit of technology provides benefits and threats. URL shorteners are no exception: they definitely add value (and I don't mean just from the sender's perspective, but also on the recipient's end, eg. by allowing you to customize web addresses making it easier for people to remember them) but can also lead to harm (obfuscating links to malware). It's like saying a hammer is a useless tool because it can bust your thumb.
- praeivis 12y agoFor now most shortener services give warnings. Internet is broken for next half day.
- Aoyagi 12y agohttp://unshort.me/ http://unshort.me/ Never fear.Also could you do some enlightening of others? Some people use URL shorteners by default when they are absolutely unnecessary. Not to mention privacy policy of these services is often uncomfortable at best.
- elwell 12y agoBut what if we're dealing with a bitly within a bitly? A 'bitly-ception'? It's bitly's all the way down... Does unshort.me recursively check? (Oh, and what if the bitly goes to an unmarked, safe-looking site with a js redirect or etc.?)
- Aoyagi 12y agoI believe unshort.me "unshorts" it all the way. I have no tested it as I'm a lazy useless individual, but feel free to try it out. Edit: OK, I just did a quick test, "unshorting" t.co link that hides a bit.ly link gives the final link.
- unshort 12y agoHey thanks for mentioning http://unshort.me http://unshort.me I created http://unshort.me http://unshort.me and you are correct it follows all the way until the shortened url is resolved unless it is a circular link. It also stores the result in a database so it works faster once someone resolves the URL. I also created fuseurl.com. It used to be a bitly but for many URLs but I shut it down because it started to contain a lot spams and viruses.
- Aoyagi 12y agoWell, then let me thank you for making the service work and keeping it clean.
- jehiah 12y agoAll Bitly links are no longer blocked by Google Safebrowsing in Chrome or Firefox.
- JacobEdelman 12y agoEh, frankly it just seems like its google slipping up. If only a few hundred bitly links have viruses I'm impressed (I'm sure there are more but the percentage still doesn't seem that bad).
- kefs 12y agoif you're curious about following a bit.ly link, simply append a + to the end of the url and you'll be taken to that link's statistics page, which will also display the full link you're being forwarded to. a lot of other shorteners employ the same feature. but obviously, just use an unshortener extension for peace of mind.
- paulhauggis 12y agoI feel like Google does this many times to hurt the competition.
- ipsin 12y agoWhat is "this" in this context? Scan websites for vulnerabilities? Make the results of automated vulnerability scans available?
- paulhauggis 12y agomakes it difficult for website operators to exist like bit.ly to exist by warning users that there are potential risks, when the risks are almost the same if not more with their own, similar services.
- eappleby 12y agoBitly has confirmed that this issue is resolved: https://twitter.com/Bitly/status/526012694835757057 https://twitter.com/Bitly/status/526012694835757057
- Urgo 12y agobit.ly is working fine for me currently but fb.me is currently being blocked