We (IPinfo) have a practice of adopting low-maintenance, high-utility services. Generally, we adopt websites that would have become defunct and run them as services.
Even though IANA says example.com is intended for documentation purposes and not as a service, I feel that it nonetheless serves as a service to the broader internet. I think there are some cornerstone services on the internet, regardless of the maintainers' intentions or their legal definitions.
For example, we ourselves sometimes have to recognize that we are not a standard API service. Considering that we expect to process 3 trillion requests this year, a major outage could take down a good chunk of IT systems everywhere. So, we invested in infrastructure to avoid outages. We then started adopting other cornerstone services and running them indefinitely because we might as well support the users who depend on them because we have infrastructure to support them and us.
I think what you describe is exactly right, it has organically become a service and it is maintained with that in mind. That doesn't mean you shouldn't be clear about what its for and what should be avoided. Otherwise it is setting up an implicit contract that it will service those needs without limitation which turns it into an even bigger dependency.
Not to mention indefinitely. Any decommission, even decades in the future, will be messy. Or imagine if ipinfo got bought up by private equity and they turned off the free service, or maybe attached some sort of agent-pay token to the response[0] so that they collect revenue from running it when possible.
Example.com is one of the sites I visit most often for troubleshooting my connection on the go. It's great for tickling a captive Wi-Fi login that didn't trigger properly.
that's a really good point I'd not considered but if you just hash the response and the followups remain consistent (they do in this case)... you're gonna do just fine.
You also failed to make it a link. In order to automatically create links, you should use the format https://example.com/ with scheme included. So in your case you'd do https://example.com/
Aww, I was wondering if I was just looking at an older version. How disappointing. But I suppose, unsurprising given the conversation here. I'm sure such transitions would be bringing a surprising amount of instrumentation down.
It still probably is as it is now. But there's better arguments to support localization than transitions.
> There is no requirement there is a HTTP service present on the host in order to fulfill its purpose, we just operate it as a courtesy.
I guess this is also done to prevent bad actors from abusing the fact that this domain is hit by people who might not know what they're doing (the ones copy-pasting code without reading it)
It's just part and parcel of owning the domain. It's one thing to have the domain, but the next step is offering an active website so that people that actually put that domain in a browser can see it's a placeholder.
More the DNS and DNSSEC and the like. Whether or not there is actually an HTTP server responding is irrelevant to whether or not those securely point anywhere but a malicious system.
Really funny coincidence, I noticed amazon wasn't loading a couple hours ago. Thought it was my internet so went to example.com to check and noticed the redesign. Figured it was a while ago though.
You may want to check your settings again or clear you cache as there is definitely a `s.js`[0] file that inserts the `<svg>` element into the HTML DOM[1], which you can see does not contain the element itself.
0
```
var B = document.body, P, p;
B.children[0].insertAdjacentHTML("afterend", "<p lang=ar dir=rtl>هذا النطاق مُخصص للاستخدام في أمثلة التوثيق دون الحاجة إلى إذن. هذه ليست خدمة، يُرجى تجنب الاعتماد عليها لأغراض الاختبار والمراقبة.</p><p lang=zh>该域名仅用于文档示例,无需获得许可。这并非一项服务,请勿将其用于测试和监控目的。</p><p lang=fr>L’usage de ce domaine est réservé à des exemples de documentation, sans autorisation préalable. Il ne s’agit pas d’un service ; son utilisation à des fins de test ou de surveillance est à éviter.</p><p lang=ru>Данный домен предназначен для использования в примерах документации без необходимости получения предварительного разрешения. Это не сервис; не рекомендуется его использование для тестирования и мониторинга.</p><p lang=es>Este dominio está destinado al uso en ejemplos de documentación sin necesidad de permiso. Esto no es un servicio; evitar utilizarlo para realizar pruebas o monitoreos.</p><a href=https://iana.org/help/example-domains>Learn more</a>");
P = [...B.querySelectorAll("p")];
P[0].lang = "en";
navigator.languages.some(l => p = P.find(p => p.lang == l.split("-")[0]));
p = p || P[0];
B.prepend(p);
B.insertAdjacentHTML("afterbegin", '<style>svg{display:block;margin:-2.75em auto 0;opacity:.55}p+p{font-size:.875em;opacity:.6}</style><svg viewBox=0,0,20,20 width=44 height=44 fill=currentColor aria-hidden=true><path fill=none stroke=currentColor stroke-width=1.3 stroke-linejoin=round d="M6 4H3v12q4 0 7 1.5-1-3.5-4-4.5V2q3.5 1 4 3v12.5q3-1.5 7-1.5V4q-4.5 0-7 1"/><g transform=rotate(-6,13.6,8.3)><path id=q d="M11.5 6.6h1.8v1.8l-1 1.6-.6-.3.8-1.3h-1z"/><use href=#q x=2.4 /></g></svg>')
body {
font: 16px/1.6 system-ui,sans-serif;
max-width: 26em;
margin: auto;
padding: 25vh 2em 2em;
text-align: center
}
</style>
</head>
<body>
<p>This domain is for use in documentation examples without needing permission. This is not a service; avoid relying on it for testing and monitoring purposes.</p>
<script src=/s.js></script>
</body>
Reducing egress bandwidth, if you have automated clients that don't support JS you save precious bytes from being served by not embedding the SVG, which at example.com scale may be worth it
I think the whole point is for it to be a static site that is easily distributed with little-to-no overhead, as it probably receives a non-trivial amount of traffic.
This feels like a “falsehood developers think about localization.”
It’s always funny when I get French YouTube ads. As if YouTube is desperately trying to offload the adbuys anywhere they can by pretending that Canada must mean French.
Interesting, didn’t know that. Also I would have expected German and Hindi to be official UN languages given the number of native speakers in the world
Same here! Yes, I used it as the well-known site that supported unencrypted http and no HSTS. Yes, I was one of those guys using the site "as a service" rather than simply documentation. Admittedly, it was perhaps interchangeable with other sites, but since it reliably worked for that purpose, I couldn't be arsed to find other ones.
Isn't there a dedicated site called nohttps or something? NeverSSL? I just tried http NeverSSL, and it redirected me to an https page with a random hostname and an Amazon SSL certificate!
Does example.com still function this way, with http and no HSTS? I noticed that my Chrome browser was immediately redirected in the customary way.
No, NeverSSL changed to have SSL a while back - around the time that Chrome/Firefox started throwing big warning signs and/or blocking non-https pages.
Wait, are you saying neverssl.com now sometimes uses SSL?
If this is a joke, it's over my head. If not, I'm not knowledgeable enough in this space to pass judgement, but that would seem crazy to me. Like the owner should consider a domain name change :)
We (IPinfo) have a practice of adopting low-maintenance, high-utility services. Generally, we adopt websites that would have become defunct and run them as services.
Even though IANA says example.com is intended for documentation purposes and not as a service, I feel that it nonetheless serves as a service to the broader internet. I think there are some cornerstone services on the internet, regardless of the maintainers' intentions or their legal definitions.
For example, we ourselves sometimes have to recognize that we are not a standard API service. Considering that we expect to process 3 trillion requests this year, a major outage could take down a good chunk of IT systems everywhere. So, we invested in infrastructure to avoid outages. We then started adopting other cornerstone services and running them indefinitely because we might as well support the users who depend on them because we have infrastructure to support them and us.
I think what you describe is exactly right, it has organically become a service and it is maintained with that in mind. That doesn't mean you shouldn't be clear about what its for and what should be avoided. Otherwise it is setting up an implicit contract that it will service those needs without limitation which turns it into an even bigger dependency.
Not to mention indefinitely. Any decommission, even decades in the future, will be messy. Or imagine if ipinfo got bought up by private equity and they turned off the free service, or maybe attached some sort of agent-pay token to the response[0] so that they collect revenue from running it when possible.
0: https://blog.cloudflare.com/monetization-gateway-beta/
Example.com is one of the sites I visit most often for troubleshooting my connection on the go. It's great for tickling a captive Wi-Fi login that didn't trigger properly.
I'm wondering how many automated tests this change broke.
Yes, I know it's not the example.com's fault, and it's a side effect of Hyrum's Law:
> This is not a service, avoid relying on it for testing and monitoring purposes.
Don't we all have a few fragile tests?
that's a really good point I'd not considered but if you just hash the response and the followups remain consistent (they do in this case)... you're gonna do just fine.
The page mentions example.com 14 times and not a single one is a link
Outrageous. How will people ever find it?!
You also failed to make it a link. In order to automatically create links, you should use the format https://example.com/ with scheme included. So in your case you'd do https://example.com/
Guess I am part of the problem. Thank you for the link kind stranger.
> there's a gradual opacity transition
Looks like they removed this and instead just show all languages with no CSS animation now.
Aww, I was wondering if I was just looking at an older version. How disappointing. But I suppose, unsurprising given the conversation here. I'm sure such transitions would be bringing a surprising amount of instrumentation down.
It still probably is as it is now. But there's better arguments to support localization than transitions.
For some reason the localization still requires javascript... (I'm pretty sure the transition could have been done in just CSS as well)
Discussed here a few days ago: https://news.ycombinator.com/item?id=49915060
> There is no requirement there is a HTTP service present on the host in order to fulfill its purpose, we just operate it as a courtesy.
I guess this is also done to prevent bad actors from abusing the fact that this domain is hit by people who might not know what they're doing (the ones copy-pasting code without reading it)
Yeah there’s definitely a lot of sensitive data that gets sent to the domain just because of people not changing configs
I don't understand, what risk would there be if they chose _not_ to serve a site?
Someone else could
No, because they can't register the domain, it's already taken, no matter if a web service is running behind it or not
It's just part and parcel of owning the domain. It's one thing to have the domain, but the next step is offering an active website so that people that actually put that domain in a browser can see it's a placeholder.
More the DNS and DNSSEC and the like. Whether or not there is actually an HTTP server responding is irrelevant to whether or not those securely point anywhere but a malicious system.
Really funny coincidence, I noticed amazon wasn't loading a couple hours ago. Thought it was my internet so went to example.com to check and noticed the redesign. Figured it was a while ago though.
I’m curious… who hosts and controls this content? IANA? Never really considered this question until now…
the 'about' link on example.com sends you here https://www.iana.org/help/example-domains
which does appear to say that yes, IANA hosts this
> Along with introducing multi-language support, the JavaScript code also inserts an SVG book icon.
Wait - using JS for dynamic content is understandable, but why using it for inserting a static SVG?
Simple answer is the article is wrong, I tried it with disabled JS and still see the SVG.
The whole article reads like something put together with AI, so maybe it’s not too surprising.
You may want to check your settings again or clear you cache as there is definitely a `s.js`[0] file that inserts the `<svg>` element into the HTML DOM[1], which you can see does not contain the element itself.
0
```
var B = document.body, P, p; B.children[0].insertAdjacentHTML("afterend", "<p lang=ar dir=rtl>هذا النطاق مُخصص للاستخدام في أمثلة التوثيق دون الحاجة إلى إذن. هذه ليست خدمة، يُرجى تجنب الاعتماد عليها لأغراض الاختبار والمراقبة.</p><p lang=zh>该域名仅用于文档示例,无需获得许可。这并非一项服务,请勿将其用于测试和监控目的。</p><p lang=fr>L’usage de ce domaine est réservé à des exemples de documentation, sans autorisation préalable. Il ne s’agit pas d’un service ; son utilisation à des fins de test ou de surveillance est à éviter.</p><p lang=ru>Данный домен предназначен для использования в примерах документации без необходимости получения предварительного разрешения. Это не сервис; не рекомендуется его использование для тестирования и мониторинга.</p><p lang=es>Este dominio está destinado al uso en ejemplos de documentación sin necesidad de permiso. Esto no es un servicio; evitar utilizarlo para realizar pruebas o monitoreos.</p><a href=https://iana.org/help/example-domains>Learn more</a>"); P = [...B.querySelectorAll("p")]; P[0].lang = "en"; navigator.languages.some(l => p = P.find(p => p.lang == l.split("-")[0])); p = p || P[0]; B.prepend(p); B.insertAdjacentHTML("afterbegin", '<style>svg{display:block;margin:-2.75em auto 0;opacity:.55}p+p{font-size:.875em;opacity:.6}</style><svg viewBox=0,0,20,20 width=44 height=44 fill=currentColor aria-hidden=true><path fill=none stroke=currentColor stroke-width=1.3 stroke-linejoin=round d="M6 4H3v12q4 0 7 1.5-1-3.5-4-4.5V2q3.5 1 4 3v12.5q3-1.5 7-1.5V4q-4.5 0-7 1"/><g transform=rotate(-6,13.6,8.3)><path id=q d="M11.5 6.6h1.8v1.8l-1 1.6-.6-.3.8-1.3h-1z"/><use href=#q x=2.4 /></g></svg>')
```
1
```
<!doctype html> <html lang=en> <head> <meta charset=utf-8> <link rel=icon href=data:,> <meta name=viewport content="width=device-width,initial-scale=1"> <title>Example Domain</title> <style> html { color-scheme: light dark; background: light-dark(#eee,#222) }
</html>
```
I get nothing but a gray page with the following with JS disabled https://i.imgur.com/81aYPeB.png in Firefox via javascript.enabled set to false.
Reducing egress bandwidth, if you have automated clients that don't support JS you save precious bytes from being served by not embedding the SVG, which at example.com scale may be worth it
Wouldn't removing the pointless SVG image entirely save the most precious bytes from being served no matter if JS (or SVG) is supported or not?
Here is some context: https://kimdavies.com/being-exemplary
who's job was it to make incremental stylesheet changes on example.com in the 2010s?
The government. It was a top secret skunkworks project to see if centering a <div> was possible.
I see the government continues to try solving impossible problems in the shadows. A pity.
Ive been using example1.com recently for availability type testing for what its worth.
IANA, a natural monopoly, can't even host simple html page is kinda funny.
the copy on example.com looks llm-generated now...
Static test is still, IMHO best, but if they want that fancy transition they could at least have used a gif. All that js is terrible overkill.
Overkill for a web of humans loading sites in browsers. Not overkill for a dead internet with swarms of agents DDoSing everything in sight.
What would have been nice is that depending on the visitors IP address’s region, showing a localised message instead of fixed number of languages
I think the whole point is for it to be a static site that is easily distributed with little-to-no overhead, as it probably receives a non-trivial amount of traffic.
Yep, that's exactly their reasoning:
> As it tends to be heavily trafficked, the overall bandwidth is a key consideration
This feels like a “falsehood developers think about localization.”
It’s always funny when I get French YouTube ads. As if YouTube is desperately trying to offload the adbuys anywhere they can by pretending that Canada must mean French.
Do you have ca-fr (or whatever) in your accept language header?
I believe it's just using the official languages of the UN
Interesting, didn’t know that. Also I would have expected German and Hindi to be official UN languages given the number of native speakers in the world
Guess most of German speaking and Hindi speaking also know English.
Just check the Accept-Language header
Previously:
IANA's email about why example.com changed
https://news.ycombinator.com/item?id=49915060
it's nice, and it surprised me when I saw the redesign.... I use it to navigate into captive wifi portals that always seem to be misconfigured.
Same here! Yes, I used it as the well-known site that supported unencrypted http and no HSTS. Yes, I was one of those guys using the site "as a service" rather than simply documentation. Admittedly, it was perhaps interchangeable with other sites, but since it reliably worked for that purpose, I couldn't be arsed to find other ones.
Isn't there a dedicated site called nohttps or something? NeverSSL? I just tried http NeverSSL, and it redirected me to an https page with a random hostname and an Amazon SSL certificate!
Does example.com still function this way, with http and no HSTS? I noticed that my Chrome browser was immediately redirected in the customary way.
http://neverssl.com/online/ seems to work for me?
Are you perhaps on an untrusted network which is spoofing that url to make it redirect somewhere else?
No, NeverSSL changed to have SSL a while back - around the time that Chrome/Firefox started throwing big warning signs and/or blocking non-https pages.
Wait, are you saying neverssl.com now sometimes uses SSL?
If this is a joke, it's over my head. If not, I'm not knowledgeable enough in this space to pass judgement, but that would seem crazy to me. Like the owner should consider a domain name change :)
My browser (iOS safari) just takes me to the ssl version from that link, so “never ssl” seems wrong?
http://http.rip/ is one I use
It's down?