# What is up with Salon.com? Is this legit, or a phishing scheme?

**URL:** <https://boards.straightdope.com/t/what-is-up-with-salon-com-is-this-legit-or-a-phishing-scheme/625792>\
**Category:** Factual Questions\
**Created:** [June 20, 2012, 9:39pm UTC](https://boards.straightdope.com/t/what-is-up-with-salon-com-is-this-legit-or-a-phishing-scheme/625792 "2012-06-20T21:39:37Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lamia](https://avatars.discourse-cdn.com/v4/letter/l/8e7dd6/32.png) [@Lamia](https://boards.straightdope.com/u/Lamia)\
**Post date:** [June 20, 2012, 9:39pm UTC](https://boards.straightdope.com/t/what-is-up-with-salon-com-is-this-legit-or-a-phishing-scheme/625792/1 "2012-06-20T21:39:37Z")

</div>

I visited Salon today for the first time in a few weeks, and after reading a few articles without problem clicked on one of the ones listed in the “Most Read” sidebar at left. I did not realize until I’d already clicked it that the links for this sidebar (and as far as I can tell only this sidebar) didn’t go to [salon.com](http://salon.com) but [origin.railrode.net](http://origin.railrode.net). (Not a misspelling, it is railrode and not railroad.) An authentication window popped up and asked me to log in.

A little searching indicates that [railrode.net](http://railrode.net) is registered to Salon so that part seems legit, if weird, but why was it asking me to authenticate? I’ve never had that happen on Salon before. Maybe I’m worried about nothing – since Salon is such a popular site I’d expect there to be complaints all over the Internet if they’d been hacked – but it seemed really strange and I’m worried that when I hit “Cancel” in the authentication window I may have unwittingly agreed to the download of something nasty.

---

<div class="post-metadata">

**Author:** ![Blakeyrat](https://avatars.discourse-cdn.com/v4/letter/b/ecd19e/32.png) [@Blakeyrat](https://boards.straightdope.com/u/Blakeyrat)\
**Post date:** [June 20, 2012, 9:46pm UTC](https://boards.straightdope.com/t/what-is-up-with-salon-com-is-this-legit-or-a-phishing-scheme/625792/2 "2012-06-20T21:46:30Z")

</div>

I wager someone at Salon just goofed-up and put a bad link on their page. They probably fixed it seconds after you clicked it. No conspiracy here.

They might use that Railrode domain for testing internally, which is why it was asking you for authentication. Just a guess though.

---

<div class="post-metadata">

**Author:** ![Lamia](https://avatars.discourse-cdn.com/v4/letter/l/8e7dd6/32.png) [@Lamia](https://boards.straightdope.com/u/Lamia)\
**Post date:** [June 20, 2012, 10:16pm UTC](https://boards.straightdope.com/t/what-is-up-with-salon-com-is-this-legit-or-a-phishing-scheme/625792/3 "2012-06-20T22:16:18Z")

</div>

> [@Blakeyrat](#):
>
> I wager someone at Salon just goofed-up and put a bad link on their page. They probably fixed it seconds after you clicked it. No conspiracy here.

I checked again an hour or two later and the same thing happened. I’d rather not do it a third time if I don’t know what the deal is, though.

---

<div class="post-metadata">

**Author:** ![Blakeyrat](https://avatars.discourse-cdn.com/v4/letter/b/ecd19e/32.png) [@Blakeyrat](https://boards.straightdope.com/u/Blakeyrat)\
**Post date:** [June 20, 2012, 11:12pm UTC](https://boards.straightdope.com/t/what-is-up-with-salon-com-is-this-legit-or-a-phishing-scheme/625792/4 "2012-06-20T23:12:15Z")

</div>

> [@Lamia](#):
>
> I checked again an hour or two later and the same thing happened. I’d rather not do it a third time if I don’t know what the deal is, though.

Hm, I just checked [Salon.com](http://Salon.com) and I’m not seeing the same thing you are. Maybe it is a real problem.

---

<div class="post-metadata">

**Author:** ![Captain\_Amazing](https://avatars.discourse-cdn.com/v4/letter/c/6de8d8/32.png) [@Captain\_Amazing](https://boards.straightdope.com/u/Captain_Amazing)\
**Post date:** [June 20, 2012, 11:25pm UTC](https://boards.straightdope.com/t/what-is-up-with-salon-com-is-this-legit-or-a-phishing-scheme/625792/5 "2012-06-20T23:25:04Z")

</div>

You also might want to check your computer to see if it’s a problem there. rather than the website.

---

<div class="post-metadata">

**Author:** ![Ferret\_Herder](https://avatars.discourse-cdn.com/v4/letter/f/e47774/32.png) [@Ferret\_Herder](https://boards.straightdope.com/u/Ferret_Herder)\
**Post date:** [June 21, 2012, 1:42am UTC](https://boards.straightdope.com/t/what-is-up-with-salon-com-is-this-legit-or-a-phishing-scheme/625792/6 "2012-06-21T01:42:40Z")

</div>

:smack: Never mind, missed part of the OP.

---

<div class="post-metadata">

**Author:** ![Lamia](https://avatars.discourse-cdn.com/v4/letter/l/8e7dd6/32.png) [@Lamia](https://boards.straightdope.com/u/Lamia)\
**Post date:** [June 21, 2012, 2:35am UTC](https://boards.straightdope.com/t/what-is-up-with-salon-com-is-this-legit-or-a-phishing-scheme/625792/7 "2012-06-21T02:35:27Z")

</div>

I had emailed Salon about this, not really expecting a response, but I got one this evening:

> [@](#):
>
> It was an error on our end. Salon has not been hacked - things are fixed now.

So I guess everything is okay. “That’s just what hackers would say if they’d hacked Salon’s contact email!” was a thought that did briefly cross my mind, but I think that’s just my usual paranoia kicking in. 😉

---

<div class="post-metadata">

**Author:** ![Canuckistan\_Bob](https://avatars.discourse-cdn.com/v4/letter/c/d6d6ee/32.png) [@Canuckistan\_Bob](https://boards.straightdope.com/u/Canuckistan_Bob)\
**Post date:** [March 10, 2013, 6:35pm UTC](https://boards.straightdope.com/t/what-is-up-with-salon-com-is-this-legit-or-a-phishing-scheme/625792/8 "2013-03-10T18:35:46Z")

</div>

Man Salon has been having issues over the last few months. Anyway, logging into [railrode.net](http://railrode.net) is back, on some articles.

---

<div class="post-metadata">

**Author:** ![tellyworth](https://avatars.discourse-cdn.com/v4/letter/t/977dab/32.png) [@tellyworth](https://boards.straightdope.com/u/tellyworth)\
**Post date:** [March 10, 2013, 9:35pm UTC](https://boards.straightdope.com/t/what-is-up-with-salon-com-is-this-legit-or-a-phishing-scheme/625792/9 "2013-03-10T21:35:32Z")

</div>

The domain [railrode.net](http://railrode.net) is owned by Salon. I’d guess they probably use it for stats collection, ad click tracking or testing.

Is the login screen an old-fashioned modal dialog box? That would point to a configuration error on their side (their clicktracker returning a HTTP 401 response).

Nothing malicious, in short.
