4 ms·
After Brian Krebs' reporting, the GSA just announced a new process to get a .gov domain. https://krebsonsecurity.com/2020/03/u-s-govt-makes-it-harder-to-get-go
by ENOTTY 7y ago
After Brian Krebs' reporting, the GSA just announced a new process to get a .gov domain. https://krebsonsecurity.com/2020/03/u-s-govt-makes-it-harder-to-get-gov-domains/ https://krebsonsecurity.com/2020/03/u-s-govt-makes-it-harder...
- Cpoll 7y ago> But I’m left to wonder: If I’m a bad guy who’s willing to forge someone’s signature and letterhead in a fraudulent application for a .gov domain, why wouldn’t I also be willing to fake a notarization? It's probably not enough. I think just by the nature of .gov domains, it's going to be very difficult to properly secure them. Even if registration is airtight, an attacker can still use other vectors: - XSS vuln on a legit .gov page to inject their own content - Open redirect vuln to redirect a legit .gov link to their page - Break a .gov server. I'm sure at least one of them is running a WordPress site with a vulnerable plugin - Break into or social engineer into the DNS server