Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A lot of this complaint also applies to raw.github.com. Much of it applies anyone who provides an online service of any sort.

> If the content being served will be modified in some cases, is there really anything preventing it from being modified in a different (perhaps more malicious) way in some other cases?

Malicious modifications would be unethical and possibly illegal. Malicious modifications would also likely make customers who noticed them abandon the service and tell the world about the situation. Of course, these facts would only stop the service providers if they care about ethics, legality, retention or reputation. I'm assuming that this particular service provider does, because the Github repo where the code is hosted mentions the author's real name [1].

[1] Whether someone reveals their real name isn't a perfect test of malicious intent [2]. A malicious provider might make up a fake name to build trust, and many people -- myself included -- lack malicious intent, but prefer to remain anonymous.

[2] A perfect test to tell whether an RFC-compliant web service is malicious is to test the evil bit, as specified in RFC 3514. To quote from it, "Benign packets have [the evil] bit set to 0; those that are used for an attack will have the bit set to 1... An application/evil MIME type is defined for Web- or email-carried mischief."



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: