Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Embedded Tweet widgets being blocked #9

Closed
eugf opened this issue Feb 2, 2018 · 4 comments
Closed

Embedded Tweet widgets being blocked #9

eugf opened this issue Feb 2, 2018 · 4 comments

Comments

@eugf
Copy link

eugf commented Feb 2, 2018

This domain on your blacklist cdn.syndication.twimg.com seems to target the widgets used on sites to embed Tweets.

For reference, this is the site I noticed it on
http:https://www.iflscience.com/environment/truck-driver-ignored-signs-and-drove-across-perus-2000yearold-nasca-lines/

And I narrowed it down with the help of this forum
https://support.mozilla.org/en-US/questions/1189443?page=2
Specifically, this section
" This address should pop up a download dialog (no need to download):
https://cdn.syndication.twimg.com/tweets.json?callback=__twttr.callbacks.cb0&ids=950804340675088384&lang=en&suppress_response_codes=true&tz=GMT-0800 "

CDN is a Content Delivery Network, and as far as I can tell it seems to load images. Another domain I saw used it for shopping and keeping the pictures on their server rather than the store's own website. Here is the Wiki for reference
https://en.wikipedia.org/wiki/Content_delivery_network

Is there a history of abusing the Twitter CDN for ads? If not would it be possible to remove this from your blacklist?

anudeepND added a commit that referenced this issue Feb 3, 2018
@anudeepND
Copy link
Owner

@eugf Thanks for reporting :)
Removed both syndication.twitter.com and cdn.syndication.twimg.com

@eugf
Copy link
Author

eugf commented Feb 3, 2018

Thanks anudeepND!

In my testing of explicitly whitelisting cdn.syndication.twimg.com and blacklisting syndication.twitter.com I got the Twitter widget to display, but not the other way around. (Still works with both whitelisted, presumably because cdn.syndication.twimg.com is the one that the Twitter widget needs)

Do you know what syndication.twitter.com does? A quick Google around shows that it may be a redirect for some kind of malware:
https://community.webroot.com/t5/Webroot-SecureAnywhere-Internet/What-the-heck-is-https-syndication-twitter-com-i-jot-syndication/td-p/146267
https://forums.malwarebytes.com/topic/198133-syndicationtwittercomijot-help/
https://productforums.google.com/forum/#!topic/chrome/WFBt-OInEoM;context-place=forum/chrome
https://discussions.apple.com/thread/6526142

@anudeepND
Copy link
Owner

I think it's kind of tracking domain, but it's not present in any other blacklist. I will add it again.

anudeepND added a commit that referenced this issue Feb 4, 2018
@eugf
Copy link
Author

eugf commented Feb 4, 2018

With your hint, I found these after filtering out all the malware results
https://blog.twitter.com/marketing/en_us/a/2015/promote-content-on-and-off-twitter-now-syndicating-promoted-tweets.html
https://blogs.wsj.com/cmo/2015/02/12/marketing-world-says-meh-to-twitters-ad-syndication-initiative/

Seems to be a paid ad service, which sounds like a Promoted ad on Google, except that it shows up off the Twitter platform in aggregated Twitter feeds. I would imagine something like a news site that shows the latest tweets.

Thanks for adding it back on! I think the community will benefit from this being on your blacklist.

@eugf eugf closed this as completed Feb 4, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants