Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Just be sure to allow URLs from *.push.apple.com if you are in control of your server push endpoints.

Wait, why would anyone be doing any sort of whitelisting? That seems a disastrously bad idea that utterly ruins interoperability. I could understand checking that the IP address the URL resolves to isn’t private, but what they’ve written suggests something much broader.

Am I missing something, or have they gone off the deep end, or are they reacting to implementers that have gone off the deep end?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: