Elektrine lite

← Feed

@jesse@chaos.social

Post #3237428

2026-06-09 15:52 UTC

@tom7@mastodon.social I know that you could create a wildcard certificate, and then create randomised subdomains to get around this, but still. The average user that orders a new domain name, might think something like: "I've never told anyone about this domain name, I should be fine waiting to fully secure it, at least for a few days", and be fully pwned in the first few hours. So I guess I'm saying I agree, always security maxin’ is bad.

Replies (1)

  • @jesse@chaos.social 2026-06-09 16:06

    @tom7@mastodon.social Bonus content: The Dutch government has a service that scores organisations internet security. It scans all domains belonging to them, and then lists "Risks". Invariably the worst scoring domains are just being forwarded, or showing a default page. Since when does a domain that isn't being used pose a security risk? For example see noordzuidlijn.nl on the dashboard for the Amsterdam municipality: https://basisbeveiliging.nl/report/risksummary/NL/municipality/4084/?filter_url=&tmd=2026-06-09 Warning: this sites UX is horrible, visit at your own risk.

    Open ##3237429