Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't think Google would consider this an open redirect. It displays a notice and requires user interaction.




It doesn't for me at all. If I go to the URL I provided in the OP, the Google server responds with a 301 status code and Location header. Both when logged into a Google account and without logging in. Strange that it behaves in a different way (?) for you.

It will probably filter the URL through Google Safe Browsing, but that doesn't help much for phishing as they mostly use new or reputable domains, and browsers check that list on default settings anyway.


Using Vanadium on grapheneos and I get

"The page you were on is trying to send you to https://news.ycombinator.com/item?id=46613684.

If you do not want to visit that page, you can return to the previous page."


Doesn't show a notice or require user interaction for me.

Android, mobile Firefox.


Firefox 146 on Arch, no notice just got redirected right away.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: