4th-Mar-2010 02:32 pm - Hijacking affiliate links
Skittish Eclipse
I've been given a heads up that has done some excellent sleuthing and investigation into hijacked LJ affiliate links:

Expect this post to be update through the day as I find out more and come up with a good summary.

ETA: No good summary, but I feel like I should say code got taken down, etc etc, business as usual.
6th-Mar-2010 11:56 pm (UTC)
Some of the commentary I've seen has wondered if the opt-out was deliberately included as part of the present code, and therefore indicates something more sinister about it. I've finally managed to track down this and related pages, which indicate that the opt-out was there long ago.

Also, I (and probably many others) had set the opt-out way back when and forgotten about it. So those munged links would have looked fine to Support volunteers looking at the relevant requests, if they had also set and forgotten the opt-out. That would have hampered the investigation as well, especially if no-one involved knew about the hinky code.

None of which excuses the whole stinking mess, but it might go some way to clarifying a couple of details :)
7th-Mar-2010 12:19 am (UTC)
Yeah, that sounds like a good explanation. I don't the Support volunteers got notified about this change to the code base, either, and it didn't show up in changelog or anything.
