←back to thread

1743 points caspii | 1 comments | | HN request time: 0.454s | source
Show context
commandlinefan ◴[] No.27427573[source]
I suspect this will only get worse over time. There was a time when, if you wanted to put a site online, you (or somebody that represented you) made a point of understanding everything that went into it. But, even as what's considered a professional web site has gotten exponentially more complicated, too many people see setting up an online presence as something like printing a brochure: details irrelevant. Somebody who does understand the details is going to use them to their advantage.
replies(3): >>27427769 #>>27428387 #>>27428880 #
bentcorner ◴[] No.27428880[source]
Feels similar to "Reflections on Trusting Trust".

Could someone inject links into content in such a way that you cannot find the link in your own source or even your hosting stack?

replies(1): >>27430214 #
1. bombcar ◴[] No.27430214[source]
You could modify the web server to modify the code in a similar way to the reflections paper.

But even more imaginative would be to work it into the kernel or the ssl layer somehow.