5 ms·
For a second there, I thought this was an official GitHub page and thought "Wow, those GitHub guys really have balls to attack SF that directly". But then I rea
by xrstf 11y ago
For a second there, I thought this was an official GitHub page and thought "Wow, those GitHub guys really have balls to attack SF that directly". But then I realized it is "helb" and not "help" in the URL.
- helb 11y agoAuthor here. Sorry about that confusion, i probably should host it elsewhere… Help/helb is not intentional, it's just my nickname since 2nd grade or so.
- sounds 11y agoYou have a disclaimer at the bottom of the page. I was also confused by the help/helb thing until I saw the disclaimer.
- yaph 11y agoWonder how many others thought exactly the same, I did too.
- jotm 11y agoThey don't have to say anything when their users do it for them :-)
- espadrine 11y agoI think that was part of the reason to switch from github.com to github.io a while back. Their .io is user content and can be downgraded by Google independently from github.com.
- billyhoffman 11y agoPerhaps, but using a separate hostname github.io vs github.com is also a security mechanism. Project owners can supply rich content (read: HTML + JavaScript) on these .io pages. If these pages were on GitHub.com or subdomains of GitHub.com, this user supplied content can interact with and hijack the github.com cookies like session ids. Yes, GitHub can use the domain attribute on a cookie to prevent this, but then you have designed a system that will fail open if you mess up. (i.e. potentially malicious user content would always be able to access a cookie, unless GitHub does something). Better to just stick it on a separate domain entirely, and this is a commonly used practice. For example, Google does this with their googleusercontent.com domain
- willglynn 11y agoIn addition to that, putting user-supplied content on separate domains allows GitHub to list those domains in https://publicsuffix.org/ https://publicsuffix.org/, which they did: // GitHub, Inc. // Submitted by Ben Toews <…@github.com> 2014-02-06 github.io githubusercontent.com Apple/Google/Microsoft/Mozilla use this list to restrict cookies -- foo.github.io can't set a cookie for github.io, even though it normally would be permitted. This list is also used to highlight the address bar, so "foo" would be emphasized, rather than "foo.github".
- nilved 11y agoAnd "io" instead of "com".