Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's a typo, the actual URL is vjs.zencdn.net. No wonder the domain was available.


The URL in the thread he shows is zendcdn though:

https://forums.informaction.com/viewtopic.php?f=10&t=17066


This is consistent with it being a typo. Typo's just in the forum post now.


Wait, so a domain typoed in the forums was added to the NoScript default whitelist without even being checked?

Oh dear.


That should have been the takeaway of the story, it's certainly the most alarming part. I'd certainly assume there'd be a thorough vetting process.


Wow... That is definitely alarming and should be reported...

Edit:

I reported it on the same thread since it's still active.

Edit: Someone else reported it, it seems.


This is the cost of the "hats off" quick response time to complaints.

The article itself mentions that a patch was pushed within hours of contacting the author. Not much vetting can be done in such short time.


something something "move fast and break things(TM)" something something




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: