/Users/sjs % curl -i http://xrl.in/33qj
HTTP/1.1 301 Permanent Redirect
Date: Sun, 09 May 2010 00:38:19 GMT
Server: Apache
Location: http://www.donationcoder.com/CodingSnacks/index.php
Content-Length: 0
Content-Type: text/htmlBit.ly see's your xrl.in and does a request. They find 301 and the location at donationcoder.com. They conclude "this site is ok". Later, the xrl.in url is changed to <malware link>.
They aren't going to do a request to every url they're linking to on every click, obviously. So they'd only get the one chance.
Now, I'm not actually sure that xrl.in lets you change links after shortening. The point is that bit.ly doesn't know either.
I think it is misleading to display that message based on the possibility of a redirection. Any page can do that, not just xrl.in.
If they let urls with redirects on them they can inadvertently bit.ly link directly to a malware site. They don't want to do that at all and take measures to prevent it. Checking urls against malware lists and not allowing redirects are just a couple, I'm sure there are more.
As for being misleading in the interstitial itself... I don't think so. They've updated it to be more clear about the issues with this link:
* Some URL-shorteners re-use their links, so bit.ly can't guarantee the validity of this link.
* Some URL-shorteners allow their links to be edited, so bit.ly can't tell where this link will lead you.
* Spam and malware is very often propagated by exploiting these loopholes, neither of which bit.ly allows for.
I'm all for whitelisting and being paranoid, but it just doesn't make sense here and it seems a bit like they're trying to make the competition look bad. This should really be a blacklist instead.