3 ms·
I agree with your position entirely, save for the "and if a shared provider has this issue, they might..." No one ever told the hosted service providers that t
by mdhardeman 9y ago
I agree with your position entirely, save for the "and if a shared provider has this issue, they might..."
No one ever told the hosted service providers that they should explicitly guard for TLS SNI names unrelated to any name of the customers they host. That certainly doesn't follow from any obvious logic.
I don't believe that a service provider who has this susceptibility is necessarily any more likely to surface other threats.