Hacker News new | ask | show | jobs
by eToThePiIPower 2961 days ago
I have to disagree. A phishing scam from "billing.foo.com" would be much harder to spot than one from "user-content.foo.com/billing". Especially if the user has free reign over the style + content.

If the user is going to be able to design + style the pages any way they want, having something in the URL to indicate it's still user content is important.