The Insecurity of Short URLs

I just got an email from the awesome folks at Joyent alerting me that someone was using Culld.us to redirect to their phishing scam site.

I promptly blocked their IP, wiped the offending URLs from the system and reset the cache.

This experience brings to mind an after hours conversation I had with a couple U of MN network security guys about inherent security risks of short URL services.

Cullect currently recognizes 83 URL shortening services.

EIGHTY-THREE

I’m hard pressed to think of 83 providers of anything (outside of entertainment services). That’s a measure of demand if anything. Even more reason publishers should – as Dave Winer recommends – pull this capability under their own umbrella.

“Every web app that produces long urls should provide a built-in url-shortening facility.” – Dave Winer

comments

Leave a Reply