-
I create a well crafted post to a normal site that gets 10.000 upvotes.
-
I change the URL to a malicious site.
-
???
-
Profit
Yeah, this is why reddit didn’t allow it. I don’t think Lemmy should either.
It makes it a little bit easier to do, but it is not difficult to replicate this effect without changing the URL in the title - using a redirected URL and changing the redirect address, for example.
I think that this small increase in the way this kind of attack can be delivered is more than counter-balanced by the convenience of having editable titles.
Most subreddits also blocked redirect links for (partially) reason.
You don’t need to use a known redirect link. If the plan begins with a post that obtains 10,000 likes, I am sure the attacker can spend a small amount of effort and register a domain.
Surely you don’t think that’s equivalent to a simple 5 second copy paste of a new URL into the textbox, right?
And it’s not just about attack vectors, it’s also about stealth ads and misinformation
I’m not sure what you’re getting at but he’s right, it’s incredibly simple to setup a new redirect site.
There’s also
-
I create a well crafted post woth a url to a normal site in the body of my post that gets 10.000 upvotes.
-
I change the URL to a malicious site.
-
???
-
Profit
This pretty much - any user can do the same to a link in the body of a post
Yeah, I had exact same thoughts lol, check my other comment with my thoughts and let me know what you think. Maybe I missed something.
-
Reminds me of a long time ago when GameSpot and GameFAQs forums merged. GameSpot users had the ability to edit titles so they would have threads like “what’s your shoe size?” Then they would change the title to something like “how old are you?” to get the GameFAQs posters banned (due to the minimum age requirements)
It would be important to ensure, that the URL can only be changed until a few minutes after submission to correct any mistakes.
In addition to what was suggested before, editing the title could disable hyperlinks in the title, adding anotger layer of protection from malicious edits.
I see what you are doing here. But being able to edit title is so convenient, I couldn’t live without it.
Maybe add a heads-up notice saying the URL has been specifically edited after some time has passed since post creation? e.g. Two hours?
Or do something like what Twitter is doing now, letting users add specific context on the title notifying people about what changed, even confirming misinformation?
Or always crosscheck the hyperlink in title or body with an open-source malicious site database and flag all malicious sites once and for all?
I’m not talking about the title but the actual page a post links to. Your idea to mark edited URLs is great, though.
Or always crosscheck the hyperlink in title or body with an open-source malicious site database and flag all malicious sites once and for all?
The internet is in flux. Once and for all is not possible.
I see! Thanks for clarifying.
deleted by creator
One down vote?? Why lol
The url and title should both be locked after a post. The contents should be free to change, that way updates and such can be posted if necessary.
Comments can continue to work as-is, there is a similar danger there, but it doesn’t matter nearly as much.
Titles being editable is really useful. So many posts have misleading titles, causing posts to have to either get removed or flaired (I don’t think we have an equivalent of flairing yet).
Plus, unless we’re prohibiting editing the body or even comments within posts, it has similar risks to editing the title or URL. Though the post URL is the one most likely to get clicked and thus is the highest risk.
It is something tooling could help detect. Moderator tools could detect posts changing the URL and flag the post for review. The general idea of spam filters apply well here. Spam filters aren’t just for completely preventing spam, but also for flagging potential spam. We could train spam filters on diffs of comments so that they can recognize when posts seemed to have completely changed in a way that we’d classify as spam.
Yeah, people have really dumb arguments, you can change link in the body anyway so I don’t see how would changing link in the “url” section would be any more dangerous? And if it was actually dangerous then we can just request on github to make it so you need an moderator approval after x time since the post was created without removing the feature completly like fucking idiots suggest. The same goes for changing title, oh, you’re afraid someone may abuse the feature? Then maybe instad of locking the feature we should simply implement public history of changes for titles. Like bruh, people are so dumb to not come up with such basic fixed and instead want to make this platform worse lol.
And I know I will get downvotes for my attitude but I’m just angry at how people want to remove good popular features on the platform and make it worse for everyone without thinking of ways to make them safe without removing them.