27 ms·
In regards to point number 2: the Name Constraints extension[1] appears to be getting more support, at least in Chrome and Firefox on non-OSX devices[2], which
by MathiasPius 6y ago
In regards to point number 2: the Name Constraints extension[1] appears to be getting more support, at least in Chrome and Firefox on non-OSX devices[2], which could help mitigate the very serious vulnerability presented by installing root certificates, by limiting the CAs scope to just the company domain, for example.
[1] https://tools.ietf.org/html/rfc5280#section-4.2.1.10 https://tools.ietf.org/html/rfc5280#section-4.2.1.10
[2] https://nameconstraints.bettertls.com/ https://nameconstraints.bettertls.com/
- est 6y agoThe point is, with a customized TLD, we don't need HTTPS traffic of videos in a LAN. Serving whatever content we embed in a HTTPS page should be a constitutional right.
- MathiasPius 6y agoA custom tld is only custom until it's not (see .dev, .corp), and using them for intranet purposes is widely regarded as bad practice. If you're already serving regular content over HTTPS internally, then I don't see the big issue in serving video and images the same way, but I'm not familiar with your particular use case so you may of course have a point here that I'm ignorant of.
- est 6y ago> them for intranet purposes is widely regarded as bad practice We are talking about the Open Web here. I think TOR wouldn't be as popular if we do not allow custom TLDs. And I politely disagree with ICANN's new gTLDs expansion. domains like blog.google is wrong.