Posted by jgx0 1 day ago
(This was when it had the language scroll though, I think moving the extras to JS should have resolved that issue; maybe I was misremembering the details too.)
example.com is not a user-facing service. I don't want to disparage the designer, but it's not meant to be pretty. It's meant to be small so you can copy its response to an automated test or visually verify its correctness, or just out of the bandwidth consideration you'd still be serving it to billions of requestors, even if you insist it's not meant to be used that way.
example.com is meant to be legally allowed to be used in text such as "You visit a website (example.com) to browse the internet"
It is not meant to be queried by automated tests or used as a service.
It's 4.5x the size of the original. Which sounds bad, until you notice this means it's 2540 bytes and serves the explanatory text in 6x the number of languages. And it's now served with brotli compression, for a total of 1713 bytes. Or 334 bytes if you only request the HTML (which still has a usable page with the full English version of the explanatory text), like a basic scraper or a health check would. So for the vast majority of traffic, it's now half the size of the old version.
I notice it's been through several revisions, the pre-2025 version of the site most people are familiar with is 1270 bytes because it didn't make use of any minification, and it also triggered an unnecessary `/favicon.ico` request because it didn't use the trick to cancel the request.
It is not, in fact, _meant_ to be used that way.
Apple operates http://captive.apple.com, which returns `<HTML><HEAD><TITLE>Success</TITLE></HEAD><BODY>Success</BODY></HTML>`.
Microsoft operates http://www.msftconnecttest.com/connecttest.txt, which returns `Microsoft Connect Test`.
Mozilla operates http://detectportal.firefox.com, which returns `success`.
These are what these companies' respective browsers/operating systems use to check if they have an internet connection and are not stuck behind a captive portal. Given the enormous quantity of devices out in the world that are relying on these URLs to stay up, you can probably feel comfortable using these in your tests. If they do go down, good chance you'll see news articles about it before you notice your tests failing.
eg If they put DNS, NTP etc on it... Likely billions per hour or something equally ludicrous.
Deluge is likely an exponential understatement.
It cannot manage a one page website. WTF
There are no page "aseets", no need for images, CSS, etc. It was a text-only website to test connectivity
iana.org forwards to Cloudflare, too
Fortunately the FTP server service still works
Without assistance from a third party
If it's been a sensible decision to use Cloudflare for some period of time then why did IANA wait until now
(Yes, I know they used Akamai in the past)
It's only responsible for root.zone, root.hints, .arpa and .int zones
AS112 is a volunteer project not a company
Years ago IANA started requiring a user-agent header
FTP access to root.zone remains
Isn't there a dedicated site called nohttps or something? NeverSSL? I just tried http NeverSSL, and it redirected me to an https page with a random hostname and an Amazon SSL certificate!
Does example.com still function this way, with http and no HSTS? I noticed that my Chrome browser was immediately redirected in the customary way.
Are you perhaps on an untrusted network which is spoofing that url to make it redirect somewhere else?
If this is a joke, it's over my head. If not, I'm not knowledgeable enough in this space to pass judgement, but that would seem crazy to me. Like the owner should consider a domain name change :)
Kinda weird setup!
Edit: okay, the subdomains also have SSL. I guess the random subdomain thing is to make sure it hasn’t been cached in a “this site has HTTPS” list. The HTTPS is needed, of course, to please the browser makers, as the parent says.
This is very useful, thanks for sharing!