Hacker News new | ask | show | jobs
by vidarh 4409 days ago
#1 is done by pretty much any site that lets you display "third party" content where said third-party is untrusted. Such as most webmail providers, when loading remote images, and often for links too.

(but there's no reason to do shortening)