[Enigmail] First signed message -- Is tinyurl.com safe and reliable?

Phil Stracchino alaric at metrocast.net
Sun Aug 24 09:06:53 PDT 2008


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Robert J. Hansen wrote:
> James Gillespie wrote:
>> Zone Labs does not advise connecting to tinyurl.com. ZoneAlarm Spyware
>> Blocker blocks the site by default. Gurus on the ZA forum claim that
>> tinyurl.com "does not check and bar links containing malware" and that
>> it "is known to actually send the user to the wrong site or list".
> 
> I think ZoneAlarm is being unreasonable.  TinyURL is just a link
> redirector.  Expecting TinyURL to also check for malware and hostile
> sites is an unreasonable burden.  Think about how much more difficult
> TinyURL's job would be if they had to scan all sites they link to for
> malware -- not just when the URL first goes up, but _constantly_, since
> the contents of a URL can change over time.

As it happens, this subject came up on geeks at sunhelp.org recently.
Anthony Ortenzi pointed out http://lmk.nu/tools, which has a URL
shortened that embeds the target domain in the new URL.  For example,
http://cgi.ebay.com/Intel-BOXD945GCLF-MINI-ITX-945GC-Atom-230-1-6GHZ-30092T_
W0QQitemZ310072960433QQihZ021QQcategoryZ131535QQssPageNameZWDVWQQrdZ1QQcmdZV
iewItem becomes http://lnk.nu/cgi.ebay.com/n3t

It does at least give you some assurance you're not going to, say, goatse.


- --
  Phil Stracchino, CDK#2     DoD#299792458     ICBM: 43.5607, -71.355
  alaric at caerllewys.net   alaric at metrocast.net   phil at co.ordinate.org
         Renaissance Man, Unix ronin, Perl hacker, Free Stater
                 It's not the years, it's the mileage.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iEUEAREIAAYFAkixhx0ACgkQ0DfOju+hMkl8ZgCYjUxAAAc3qtWuz8Jemfnn8Z4R
AwCfeBhkjBCb7jgOdjQI0RFsH7CHMpA=
=Ot6Y
-----END PGP SIGNATURE-----


More information about the Enigmail mailing list