Top
Best
New

Posted by jgx0 1 day ago

Example.com just launched the biggest redesign in decades(www.debugbear.com)
338 points | 224 commentspage 3
dfox 14 hours ago|
It seems that they changed it again and now there is minified HTML with english message + simple script that injects the other languages and the icon, no animation. Which to me seems much more sensible.
pona-a 18 hours ago||
I actually noticed that! I was debugging some HTTP proxy and typed out an HTTP/1.1 request by hand in netcat, and was wondering why I saw a giant blob of dynamic nonsense instead of a small bit of markup.

(This was when it had the language scroll though, I think moving the extras to JS should have resolved that issue; maybe I was misremembering the details too.)

example.com is not a user-facing service. I don't want to disparage the designer, but it's not meant to be pretty. It's meant to be small so you can copy its response to an automated test or visually verify its correctness, or just out of the bandwidth consideration you'd still be serving it to billions of requestors, even if you insist it's not meant to be used that way.

eugenekolo 17 hours ago||
I believe your use is what they're trying to discourage.

example.com is meant to be legally allowed to be used in text such as "You visit a website (example.com) to browse the internet"

It is not meant to be queried by automated tests or used as a service.

pona-a 13 hours ago||
I never queried it _automatically_, but many projects do. They might not have set out to provide that use, but what happened has happened, and breaking this implicit contract for a silly redesign is an odd choice.
creatonez 16 hours ago|||
> and was wondering why I saw a giant blob of dynamic nonsense instead of a small bit of markup.

It's 4.5x the size of the original. Which sounds bad, until you notice this means it's 2540 bytes and serves the explanatory text in 6x the number of languages. And it's now served with brotli compression, for a total of 1713 bytes. Or 334 bytes if you only request the HTML (which still has a usable page with the full English version of the explanatory text), like a basic scraper or a health check would. So for the vast majority of traffic, it's now half the size of the old version.

I notice it's been through several revisions, the pre-2025 version of the site most people are familiar with is 1270 bytes because it didn't make use of any minification, and it also triggered an unnecessary `/favicon.ico` request because it didn't use the trick to cancel the request.

scubbo 17 hours ago||
> It's meant to be small [...], even if [...] it's not meant to be used that way

It is not, in fact, _meant_ to be used that way.

pipes 14 hours ago||
What should I use for example URLs in my testa.
hayleox 12 hours ago|
Google operates http://connectivitycheck.gstatic.com/generate_204 and http://www.gstatic.com/generate_204, both of which return a 204 No Content response.

Apple operates http://captive.apple.com, which returns `<HTML><HEAD><TITLE>Success</TITLE></HEAD><BODY>Success</BODY></HTML>`.

Microsoft operates http://www.msftconnecttest.com/connecttest.txt, which returns `Microsoft Connect Test`.

Mozilla operates http://detectportal.firefox.com, which returns `success`.

These are what these companies' respective browsers/operating systems use to check if they have an internet connection and are not stuck behind a captive portal. Given the enormous quantity of devices out in the world that are relying on these URLs to stay up, you can probably feel comfortable using these in your tests. If they do go down, good chance you'll see news articles about it before you notice your tests failing.

absynth 16 hours ago||
I just wonder how much unintended traffic they receive.

eg If they put DNS, NTP etc on it... Likely billions per hour or something equally ludicrous.

Deluge is likely an exponential understatement.

monskov 1 day ago||
who's job was it to make incremental stylesheet changes on example.com in the 2010s?
failbuffer 23 hours ago||
The government. It was a top secret skunkworks project to see if centering a <div> was possible.
johnnyanmac 22 hours ago||
I see the government continues to try solving impossible problems in the shadows. A pity.
efilife 17 hours ago||
Whose. Who's is a contraction of who + is
ErroneousBosh 3 hours ago||
I did not know about that empty favicon trick, and I will be adding it to all my base HTML templates for my Flask projects where I get annoyed at all the 404s scrolling past as my browser keeps requesting a favicon that will not exist in that form.
1vuio0pswjnm7 20 hours ago||
I just don't understand why the operator, IANA, has to use Cloudflare for example.com

It cannot manage a one page website. WTF

There are no page "aseets", no need for images, CSS, etc. It was a text-only website to test connectivity

iana.org forwards to Cloudflare, too

Fortunately the FTP server service still works

Without assistance from a third party

If it's been a sensible decision to use Cloudflare for some period of time then why did IANA wait until now

(Yes, I know they used Akamai in the past)

kijeda 20 hours ago||
Cloudflare is the latest in a number of different CDN providers we've used to serve this over many years. I guess the question is, why is it important not to use a CDN?
cheschire 14 hours ago||
HN is currently anti Cloudflare. The only thing worse probably would’ve been to serve the static files on GitHub.io
NavinF 20 hours ago|||
Same reason everyone else uses CF. Static page CDN only became too cheap to meter ~16 years ago, but if CF was around in the 90s IANA would have used it in the 90s too
gucci-on-fleek 18 hours ago|||
IANA has a history of hosting even more important services with third-parties [0] [1], so this doesn't seem too problematic to me.

[0]: https://root-servers.org/

[1]: https://datatracker.ietf.org/doc/html/rfc6305.html

1vuio0pswjnm7 17 hours ago|||
NB. IANA isn't responsible for "root servers"

It's only responsible for root.zone, root.hints, .arpa and .int zones

AS112 is a volunteer project not a company

1vuio0pswjnm7 17 hours ago|||
If it's a name in com/net/org only meant for documentation then why serve a page there for decades. If traffic is a problem then take it offline

Years ago IANA started requiring a user-agent header

FTP access to root.zone remains

1vuio0pswjnm7 18 hours ago|||
*assets
NicoJuicy 20 hours ago||
Well, it's a popular website. By using Cloudflare I think they will save a lot of bandwidth and traffic because the page and assets can be cached.
lifeisloving 22 hours ago||
Ive been using example1.com recently for availability type testing for what its worth.
chews 1 day ago|
it's nice, and it surprised me when I saw the redesign.... I use it to navigate into captive wifi portals that always seem to be misconfigured.
justinpombrio 18 hours ago||
I've used http://www.com for that.
ButlerianJihad 23 hours ago||
Same here! Yes, I used it as the well-known site that supported unencrypted http and no HSTS. Yes, I was one of those guys using the site "as a service" rather than simply documentation. Admittedly, it was perhaps interchangeable with other sites, but since it reliably worked for that purpose, I couldn't be arsed to find other ones.

Isn't there a dedicated site called nohttps or something? NeverSSL? I just tried http NeverSSL, and it redirected me to an https page with a random hostname and an Amazon SSL certificate!

Does example.com still function this way, with http and no HSTS? I noticed that my Chrome browser was immediately redirected in the customary way.

drdeca 22 hours ago||
http://neverssl.com/online/ seems to work for me?

Are you perhaps on an untrusted network which is spoofing that url to make it redirect somewhere else?

Arainach 22 hours ago|||
No, NeverSSL changed to have SSL a while back - around the time that Chrome/Firefox started throwing big warning signs and/or blocking non-https pages.
red369 21 hours ago||
Wait, are you saying neverssl.com now sometimes uses SSL?

If this is a joke, it's over my head. If not, I'm not knowledgeable enough in this space to pass judgement, but that would seem crazy to me. Like the owner should consider a domain name change :)

notpushkin 16 hours ago||
It has SSL on the main domain, and some subdomains without SSL (wildcard perhaps?). The main domain (when accessed over SSL?) redirects to a subdomain with plain HTTP.

Kinda weird setup!

Edit: okay, the subdomains also have SSL. I guess the random subdomain thing is to make sure it hasn’t been cached in a “this site has HTTPS” list. The HTTPS is needed, of course, to please the browser makers, as the parent says.

bobbean 21 hours ago||||
http://http.rip/ is one I use
DaSHacka 9 hours ago||
Wow finally, a "no ssl" site that actually doesn't use SSL! I was so disappointed when "NEVERssl" added SSL, like you literally have ONE job. Some clients automatically upgrade http->https or prepend https if left unspecified, so it's nice to have an explicitly HTTP-only (IE port 80-only) service for testing/captive portals.

This is very useful, thanks for sharing!

what 21 hours ago|||
My browser (iOS safari) just takes me to the ssl version from that link, so “never ssl” seems wrong?
onedognight 18 hours ago||
http://example.com/ works for me in Safari, warning that the site is “not secure”, but only if I type it in by hand.
More comments...