Post #3237428
2026-06-09 15:52 UTC
@tom7@mastodon.social
I know that you could create a wildcard certificate, and then create randomised subdomains to get around this, but still.
The average user that orders a new domain name, might think something like: "I've never told anyone about this domain name, I should be fine waiting to fully secure it, at least for a few days", and be fully pwned in the first few hours.
So I guess I'm saying I agree, always security maxin’ is bad.
Replies (1)
-
@jesse@chaos.social 2026-06-09 16:06
@tom7@mastodon.social Bonus content: The Dutch government has a service that scores organisations internet security. It scans all domains belonging to them, and then lists "Risks". Invariably the worst scoring domains are just being forwarded, or showing a default page. Since when does a domain that isn't being used pose a security risk? For example see noordzuidlijn.nl on the dashboard for the Amsterdam municipality: https://basisbeveiliging.nl/report/risksummary/NL/municipality/4084/?filter_url=&tmd=2026-06-09 Warning: this sites UX is horrible, visit at your own risk.