Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There's other ways to signal ad impressions that aren't a huge security risk. Maybe not quite as convenient, but I doubt banning redirects would have a measurable effect as long as Google gave a deprecation warning.

You can achieve the same thing without redirects using URL parameters or the referer field. Google should ban any destination that doesn't match the sites domain. It's an unfixable security risk that's being actively exploited



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: