Hotlinking to jquery.com will be disabled on January 31, 2011
blog.jquery.com
blog.jquery.com
If anyone is not aware, one of the best CDNs out there for getting jQuery is the Taylor Swift "TaylorNation" cdn.
http://cdn.thetaylornation.com/taylornation/resources/displa...
I encourage everyone to use it.
How have I never heard about this hilarious script before?
'PI': 3.2Could be improved a bit, though. Many of its entries lack subtlety. If you really want to be evil, make uppercase do something like uppercase all but one letter, or "uppercase" the digit 1 into exclamation marks, 2 into at signs, etc., convincing the poor developer that the JS upper case function is broken and affect digits. ("Must be unicode or something.")
Then again, maybe the point is to muddy your own waters? I'm reminded of an aphorism dealing with activities that should not be undertaken near one's place of slumber.
For example at my last job, I was pair programming with the "most valuable" C++ programmer. We were debugging one of his monolithic heightmap classes. Some top-level method was calling some deeper method that was doing a lot of different complicated things. After examining the top level method in the debugger, and looking at the results after calling the deeper method, he wrote some code to "patch over" the problem. I.e. The deeper method was causing the results to be bad in some way, and his solution was to add code to overwrite the bad results with the expected ones. Then we ran the program and it worked.
To my surprise, he stopped there and committed the code. As he was writing the commit message, I asked "Hmm, aren't you interested in why the internals don't seem to be working properly?" He shrugged and said "No."
I hear their game engine has suffered rather severe performance problems and general bugginess. It also looks visually to be 2004-era.
Many of its entries lack subtlety.
An Underhanded Javascript contest would be amusing.1. Every built in in Javascript can be overwritten.
2. If you see something like ObjectName.prototype.fnName, then what you're doing is defining a new fnName function on ObjectName. The thing about Javascript is that you can add new functions to objects, and since everything can be overwritten, you can also replace old functions with new ones. So when you do something like Array.prototype.sort = function(){...} then you're overwriting the builtin sort method on Arrays. Most of the script is just defining builtins to have bogus results.
3. Javascript has a built in Math object, like a few other languages. The language also allows you to create objects on the fly with bracket notation: the layout is key: value. So the Math definition defines Math.PI to be 3.2.
4. There are a few other jokes in there too (like defining alert, which makes a message box, to be eval, which evaluates the string).
This would probably be the best way to transition. If they add an alert to their library and leave it up a week, most people should notice and fix it.
if (location.host.search(/crockford.com$/i) != -1) {
alert("Stop hotlinking me!")
}
I don't think you can fool that, but I'd love to hear about how I'm wrong. if (location.host.search(/crockford.com$/i) != -1) {
throw "Stop hotlinking me!";
}And even then, this can bypass it:
var temp = String.prototype.search;
String.prototype.search = function() { return 0};
if (location.host.search(/crockford.com$/i) != 0) {
throw "Stop hotlinking me!";
}
String.prototype.search = temp;
Though that may cause other problems. var expectedHost = "crockford.com";
if (expectedHost.length !== location.host)
throw "Stop hotlinking me!";
for (var i = 0; i < expectedHost.length; i++)
if (location.host[i] === expectedHost[i])
throw "Stop hotlinking me!";
(though it string[x] might not work in every browser)So thanks for further demonstrating my point!
But really, just check the referrer header.
<script>
var oldAlertFunction = window.alert;
window.alert = function(){};
</script>
<script src="crockford.com/json.library.js"></script>
Arms race, but just sayin'<script> var oldAlertFunction = window.alert; window.alert = function(){}; </script>
<script src="crockford.com/json.library.js"></script>
<script>
window.alert=oldAlertFunction;
</script>I guess I shouldn't be but I'm still surprised people would even do this given that Google s offering the service for free. Hotlinking has always been antisocial.
I'm actually more surprised that the site didn't either use Google's API to host the download, or provide a hotlink button right there.
This also applies when .js is dynamically included as a type of API call to embed widgets and whatnot - but in those cases there's a necessary reason - it's the only practical way - but for a simple .js, you should be managing your own .js library and publishing on your own (including all the speedup tricks you know you should be doing)
This is why I can't understand people's recommendation to use Google's or Microsoft's CDN. Even if you assume they're not going to be malicious, you have to trust that they're secure. Not to mention that the CDN owner can derive accurate traffic stats from the number of requests for the JavaScript.
In a perfect world, the CDN would only handle one HTTP request per user per expires period (+1 year on Google and Microsoft's jQuery CDN). In reality, the file will be pushed out of or cleared from caches for various reasons, but they still persist long enough to make tracking end-usage of the CDN meaningless.
That said, I'm open to the idea that I'm being extremely foolish about this ;)
<script id="jquery" src="http://code.google.com/jquery.js"></script>
<script>
if (jQuery == undefined) {
document.querySelector("#jquery").src = 'Backup CDN';
}
</script>
That should work, in theory, if not then just remove script#jquery, create a new one and append to the document before executing any script(s). <!-- Grab Google CDN's jQuery. fall back to local if necessary -->
<script src="//ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.js"></script>
<script>!window.jQuery && document.write(unescape('%3Cscript src="js/libs/jquery-1.4.2.js"%3E%3C/script%3E'))</script>CPanel allows you to do this directly (although you might want to back up your .htaccess file first).
(Up to date CDN links for a bunch of javascript libraries, including jquery)
- Listing the sites that hotlink it would be a nice idea.
- Changing the script on the hotlinked files to pop-up a warning that the site is doing something improper and urging people to contact the owner.
- When that doesn't work, break the sites.
To me, that seems like the polite thing to do.
Hotlinking like this has been a well known web evil for well over a decade. That people still do it and just hope for the best is indicative of extraordinary laziness and selfishness.
They could just break all those sites without giving them personalised warnings, yes. And they would also be completely entitled to yes. But for the small amount of effort needed, why not try to minimise the damage.
I'm attributing laziness, which is quite removed from malice. People using jquery should be evolved enough to know what CDNs are, and the dangers of hotlinking (which is as simple as "jQuery decided to reorganize their site, and now a thousand sites are broken").
These people don't need punishing, they need educating. I find the whole "fuck em, it's their fault" attitude to be very childish.
Is that not precisely what I said? Laziness.
I feel like I'm debating with a tired Hallmark card. Yes, high road and all that. We get it.
Just as you misplaced the malice quote (you were a little too eager to play that one), now you're on about punishment: Who said anything about punishment? Saying "Don't hotlink, but we're giving you 30 days grace" is not remotely "punishment". That you portray it as such is, honestly, outrageous.
No. You can't both understand the word "laziness" and attribute that to the explanations I provided.
"I feel like I'm debating with a tired Hallmark card. Yes, high road and all that. We get it."
I feel like I'm debating with somebody who is very intolerant.
"Just as you misplaced the malice quote (you were a little too eager to play that one)"
I did not misplace it, and I stand by the statement, and exactly how I used and formatted it.
"now you're on about punishment: Who said anything about punishment? Saying "Don't hotlink, but we're giving you 30 days grace" is not remotely "punishment". That you portray it as such is, honestly, outrageous."
You're easily angered aren't you. As I said, it would be trivial to contact them directly and tell them about the problem, and not doing so when it would be so easy giving the reason that they should have known better in the first place is a clear kind of punishment yes.
I'm not continuing this discussion with you. I have more fun things to do with my New Years Eve than debate with an angry troll.
I'm not done because I've debated with this ridiculous tactic enough to see it for what it is.
Copy-pasting code that you don't understand is pretty much the definition of laziness.
And just to be clear, it's "trivial" for jQuery to do this, in your mind, because you're not the one having to do it. Probably thousands of tiny sites that are doing this (I doubt it's any big numbers sites), each requiring you to go through the whois process to find a webmaster. Not as trivial as you proclaim.
Disagree. Copy-pasting code that you don't understand is how most people learn how to code on the web. It's how I learned.
Most junior web developers do not understand everything that goes on in the web stack. They piece together the ability to run a functioning website by putting together bits of knowledge they pick up along the way. Some of this knowledge comes from reputable sources, like the jQuery documentation. Some of it comes from sources that may, albeit wrongly, recommend hotlinking, such as friends or Experts-Exchange.
When you're new to a subject, and there are that many unknowns, and you don't have a great mentor, it's hard to know exactly which parts are important to understand thoroughly, and which can be attributed to "magic" for the moment. Most people learn to program for the web because they need to get a project online, which means they are more focused on getting something working, rather than trying to grok every bit of the stack. I would bet that the vast majority of people that hotlink jQuery fall firmly into this category. It's not that they don't want to learn how not to hotlink, or are too busy or too lazy to learn, it's that they don't know that this is something they need to learn.
And that, sir, is definitively ignorance, not laziness. To be precise, it's ignorance of the fact that they are ignorant.
PS: Don't take disagreement personally, and don't call the person you're disagreeing with a "Hallmark card". It makes you look like a troll.
How does one exit an argument with somebody who is behaving so irrationally, without getting accused of all that bullshit?
I guarantee that some people are using the wrong URLs because they received bad advice
Didn't doublecheck the advice: lazy.
or copied from code they shouldn't have
Lazy coding.
were simply told by somebody that they could link to the version on jquery.com, so did.
See #1.
Copying code is "lazy coding"? There isn't a programmer alive who hasn't done this.
So these people are guilty of being alive and being programmers? Yeah, lets break their websites! That'll teach them!
This is the wrong attitude. The professional attitude is to at least try to resolve your problems without fucking other people over.
There are lots and lots of monkeys using jquery. Cargo-cultist monkeys, at that. At least that's my impression from the browser bugs I've seen filed with snippets of jquery code.
I wouldn't extrapolate knowledge of CDNs, or much of anything other than jquery basics, from use of jquery.
Except where the site expressly permits it.
Well indeed, but even if you ignore the time taken to do WHOIS lookups and presume that they'll go to the right person (e.g. blogs hosted on Wordpress.com) you're still ignoring the serious amount of computing power that it takes to send a significant number of emails.
I'm assuming we're talking about thousands of emails here, not millions.
When was the last time you tried sending thousands of emails? It's a surprisingly non-trivial task to send more than a few hundred emails - and that's ignoring setting off spam filters and getting IP addresses blacklisted.
Speaking honestly, I like your idea, but it's my opinion that if it were that simple then the jQuery guys would do it. Since it isn't that simple, they're not.
It should take about a minute to craft a one liner to pull the relevant domains out of the access logs. It should then take maybe half an hour or less to write a batch script to queue up the emails.
Then sit back and watch them go... What else is there?
What hardware are you running that supports sending out tens of thousands of emails, handling the inevitable DNS errors, timeouts, bounces (yes yes, I've read about the RFC ;)) and that manages all of this in a reasonable amount of time? Genuine question, I'm curious.
http://ajax.googleapis.com/ajax/libs/jquery/1/jquery.min.js (always the latest version)