# Preventing malicious linking

**URL:** https://meta.discourse.org/t/preventing-malicious-linking/37982
**Category:** Feature
**Created:** [January 15, 2016, 3:07am UTC](https://meta.discourse.org/t/preventing-malicious-linking/37982 "2016-01-15T03:07:44Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![john\_mardlin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/john_mardlin/32/115622_2.png) [@john\_mardlin](https://meta.discourse.org/u/john_mardlin)
#### Post date: [January 15, 2016, 3:07am UTC](https://meta.discourse.org/t/preventing-malicious-linking/37982/1 "2016-01-15T03:07:44Z")

</div>

Continuing the discussion from [How Coinbase Uses Discourse to Educate Customers and Improve SEO](https://meta.discourse.org/t/how-coinbase-uses-discourse-to-educate-customers-and-improve-seo/37863/3):

> [@How Coinbase Uses Discourse to Educate Customers and Improve SEO](https://meta.discourse.org/t/how-coinbase-uses-discourse-to-educate-customers-and-improve-seo/37863/3):
>
> I was going to add that I’m still keeping my eye on the topic about warning on external links, e.g. bad guys posting phishing links like this:
> 
> [totally safe and normal link](http://evil-phishing-site.com/bad-link)
> 
> It might be best to warn (if enabled) on TL0 posted links, like so:
> 
> ![image](https://global.discourse-cdn.com/meta/original/3X/f/7/f7389b6fa67d0b759d7f91f3de658e6ab49d9622.jpg)

If I understand, that warning would be shown to anyone who clicks on a link posted by a TL0 user?

What if a TL0 users posts a link to one of our KB articles, or StackOverflow, or Wikipedia? I suppose we could whitelist domains, but it seems like all users are being punished instead of the new user being asked to gain trust.

If that was only shown until moderator review, it could work.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [January 15, 2016, 3:21am UTC](https://meta.discourse.org/t/preventing-malicious-linking/37982/2 "2016-01-15T03:21:05Z")

</div>

No, it would be global for all TL0 user links outside the main domain. Turning it into a manual URL review queue would be a big jump in complexity and UI.

---

<div class="post-metadata">

### Author: ![john\_mardlin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/john_mardlin/32/115622_2.png) [@john\_mardlin](https://meta.discourse.org/u/john_mardlin)
#### Post date: [January 15, 2016, 3:34am UTC](https://meta.discourse.org/t/preventing-malicious-linking/37982/3 "2016-01-15T03:34:19Z")

</div>

Makes sense, it would just feel a bit silly to see a security warning on a wikipedia link.

---

<div class="post-metadata">

### Author: ![cpradio](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/cpradio/32/4970_2.png) [@cpradio](https://meta.discourse.org/u/cpradio)
#### Post date: [January 15, 2016, 3:41am UTC](https://meta.discourse.org/t/preventing-malicious-linking/37982/4 "2016-01-15T03:41:38Z")

</div>

> [@john\_mardlin](#):
>
> Makes sense, it would just feel a bit silly to see a security warning on a wikipedia link.

I agree. Almost would need the ability to turn this off, as for our given instance, links are typical, most go to CodePen, or JSFiddle, SQL Fiddle, etc. Sometimes to the user’s own site because they are trying to work out an issue of some sort. In no way would we want to display such a warning on all TL 0 links that link to external resources.

Even whitelisting would be extremely difficult for our community (unfortunately). So if it could be enabled by default, with the ability to turn it off, that’s be great!

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [January 15, 2016, 10:22am UTC](https://meta.discourse.org/t/preventing-malicious-linking/37982/5 "2016-01-15T10:22:36Z")

</div>

Enabling by default with a option to turn off. 👍

Btw, I suggest taking a look at how Steam chat does this, the wording of their message, because they are a big pishing target.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [January 15, 2016, 10:42am UTC](https://meta.discourse.org/t/preventing-malicious-linking/37982/6 "2016-01-15T10:42:24Z")

</div>

Can you post a screenshot?

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [January 15, 2016, 11:23am UTC](https://meta.discourse.org/t/preventing-malicious-linking/37982/7 "2016-01-15T11:23:31Z")

</div>

Looks like there are two versions:

Normal Link:

[](https://i.sstatic.net/sQF82.png)

Possible phishing: (maybe when the link and hostname are similar?)

 ![bSz6AR7](https://global.discourse-cdn.com/meta/original/4X/7/5/6/756cd8b47dfbe9ad0adf448ceaf62368e8bc3c49.png)

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [November 9, 2017, 4:59pm UTC](https://meta.discourse.org/t/preventing-malicious-linking/37982/8 "2017-11-09T16:59:22Z")

</div>

After thinking about it, I have very little enthusiasm for this feature. I view it as borderline useless, a lawyerly way of CYA without any real effect on user behavior. It’s just another meaningless warning that appears all the time on external links that users quickly learn to click past without thinking to get where they want to go.

What _would_ work is a plugin that checks domains server-side against a known blacklist of dangerous domains and **warns _ONLY_ when attempting to visit known bad domains**.

> **[Google Safe Browsing  |  Google for Developers](https://developers.google.com/safe-browsing/)**
>
> APIs to access the Google Safe Browsing lists of unsafe web resources.

But then again, this is best done at the **browser** level not at the website level. So the protection would then be global.

---

<div class="post-metadata">

### Author: ![Stranik](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stranik/32/85638_2.png) [@Stranik](https://meta.discourse.org/u/Stranik)
#### Post date: [November 9, 2017, 5:00pm UTC](https://meta.discourse.org/t/preventing-malicious-linking/37982/9 "2017-11-09T17:00:16Z")

</div>

This can be a very good function. Several users have already asked to do this and I was thinking about implementing it with the help of a plugin. If it’s in the core, then it’s very good.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [November 9, 2017, 5:01pm UTC](https://meta.discourse.org/t/preventing-malicious-linking/37982/10 "2017-11-09T17:01:19Z")

</div>

If @erlend_sh wants to add such a plugin to the ✨ ENCOURAGEMENT fund, that is up to him. Seems like an OK candidate, _provided it only warns on known bad domains_ as stated above.

Global warn on every outgoing link is very, very bad as you are training users to ignore warnings. So bad.

---

<div class="post-metadata">

### Author: ![Stranik](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stranik/32/85638_2.png) [@Stranik](https://meta.discourse.org/u/Stranik)
#### Post date: [November 9, 2017, 5:04pm UTC](https://meta.discourse.org/t/preventing-malicious-linking/37982/11 "2017-11-09T17:04:00Z")

</div>

In the social network Vkontakte, that’s exactly how it is implemented. Transitions to the bad domains open the window. The administration has the option to manually add any domain.

---

<div class="post-metadata">

### Author: ![HAWK](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/hawk/32/86627_2.png) [@HAWK](https://meta.discourse.org/u/HAWK)
#### Post date: [November 9, 2017, 5:09pm UTC](https://meta.discourse.org/t/preventing-malicious-linking/37982/12 "2017-11-09T17:09:18Z")

</div>

> [@codinghorror](#):
>
> Global warn on every outgoing link is very, very bad as you are training users to ignore warnings. So bad.

[External link icons](http://fontawesome.io/icon/external-link/) are pretty common practice these days though. Not a warning but an indicator…

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [November 9, 2017, 5:13pm UTC](https://meta.discourse.org/t/preventing-malicious-linking/37982/13 "2017-11-09T17:13:29Z")

</div>

I don’t historically derive much value from that kind of indicator, though. Plus we already mini-onebox internal links, like this… [Preventing malicious linking](https://meta.discourse.org/t/preventing-malicious-linking/37982) .. so we already have a “different” version of links.

Plus full oneboxing!

---

<div class="post-metadata">

### Author: ![nsuchy](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/nsuchy/32/166530_2.png) [@nsuchy](https://meta.discourse.org/u/nsuchy)
#### Post date: [November 10, 2017, 1:56am UTC](https://meta.discourse.org/t/preventing-malicious-linking/37982/14 "2017-11-10T01:56:38Z")

</div>

Why not rewrite to the HTTPS version? It’s astounding they don’t use an HTTP 301 redirect to HTTPS, but for trusted domains / domains that return a 301 upon Discourse reviewing the post and post content it could work.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [November 10, 2017, 2:29am UTC](https://meta.discourse.org/t/preventing-malicious-linking/37982/15 "2017-11-10T02:29:40Z")

</div>

This has very little to do with https, it is about malicious domains in general. Which could be https, that part is not relevant.

---

<div class="post-metadata">

### Author: ![Sudaraka](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sudaraka/32/68401_2.png) [@Sudaraka](https://meta.discourse.org/u/Sudaraka)
#### Post date: [November 25, 2017, 7:51am UTC](https://meta.discourse.org/t/preventing-malicious-linking/37982/16 "2017-11-25T07:51:34Z")

</div>

Hi all,  
I’m really happy to build a plugin for the above mentioned task. I am thinking of using Google Safe Browsing API. I tried some sites with the api. Its giving good results

 ![api-demo](https://global.discourse-cdn.com/meta/original/3X/8/6/864e8446c6a4ad54cdabcbd4fdc6d35d15fbd1d0.png)

I’m thinking of two ways of triggering this check. We can either check the url when it’s added and add a flag or else we can check when the url is clicked. But I think the first way is better. What u guys think ?

---

<div class="post-metadata">

### Author: ![itsbhanusharma](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/itsbhanusharma/32/180717_2.png) [@itsbhanusharma](https://meta.discourse.org/u/itsbhanusharma)
#### Post date: [November 25, 2017, 8:02am UTC](https://meta.discourse.org/t/preventing-malicious-linking/37982/17 "2017-11-25T08:02:22Z")

</div>

Adding a flag seems like a better idea as checking everytime someone clicks doesn’t seems very resource friendly.  
though adding a warning modal to all the flagged links when clicked seems like a bonus.

---

<div class="post-metadata">

### Author: ![Sudaraka](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sudaraka/32/68401_2.png) [@Sudaraka](https://meta.discourse.org/u/Sudaraka)
#### Post date: [November 25, 2017, 8:03am UTC](https://meta.discourse.org/t/preventing-malicious-linking/37982/18 "2017-11-25T08:03:52Z")

</div>

My idea was the same. We can reduce the API hits that way. 🙂

---

<div class="post-metadata">

### Author: ![itsbhanusharma](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/itsbhanusharma/32/180717_2.png) [@itsbhanusharma](https://meta.discourse.org/u/itsbhanusharma)
#### Post date: [November 25, 2017, 8:04am UTC](https://meta.discourse.org/t/preventing-malicious-linking/37982/19 "2017-11-25T08:04:36Z")

</div>

Exactly! and that way, everyone clicking it can be warned in advance that the link isn’t trusted.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [November 25, 2017, 8:04am UTC](https://meta.discourse.org/t/preventing-malicious-linking/37982/20 "2017-11-25T08:04:57Z")

</div>

Only check the first time it is clicked and then save the result. It simply does not matter one way or the other when a link is never clicked.

But what about a year later, can a link become safe?

[Next page](https://meta.discourse.org/t/preventing-malicious-linking/37982.md?page=2)
