Google and Microsoft shortened URLs make it easy to spy on people

Cornell Tech’s Martin Georgiev and Vitaly Shmatikov on Thursday published the results of an 18-month study that found the 5- or 6-character tokens added to domains such as 1drv.ms or goo.gl are so short, all possible URLs can be scanned by brute force by “anyone with a little patience and a few machines at her disposal.” Those short URLs are, in effect, public, the researchers say.

https://nakedsecurity.sophos.com/2016/04/18/google-and-microsofts-shortened-urls-make-it-easy-to-spy-on-people/

http://arxiv.org/pdf/1604.02734v1.pdf