Company
Date Published
Author
Ryan Tomayko
Word count
471
Language
English
Hacker News points
None

Summary

GitHub has transitioned all GitHub Pages sites to a new domain, github.io, as a security measure to mitigate potential vulnerabilities such as cross-domain attacks and phishing schemes that exploit the trust associated with the github.com domain. This change affects all User, Organization, and Project Pages not using a custom domain, with traffic previously directed to username.github.com now being permanently redirected to username.github.io, ensuring no manual link updates are necessary. The transition aims to address security threats like session fixation and CSRF vulnerabilities related to browser security issues, as well as phishing attacks that could deceive users into providing sensitive information on malicious sites mimicking official GitHub services. Custom domain users remain unaffected, and support is available for any issues arising from the change, which has been implemented with measures to prevent significant disruptions.