3 ms·
The certificate transparency log for an internal network would let you see which domains are in use and make it far easier for an attacker to exploit internal s
by orisho 6y ago
The certificate transparency log for an internal network would let you see which domains are in use and make it far easier for an attacker to exploit internal services. The attacker need not be an APT for this, it could be as mundane as a XSS attack.
- bawolff 6y agoThat's why i was suggesting using wildcard certs - they would not have the actual domain name in them. That said, regardless of what one does, i wouldn't reccomend putting too much faith in security by obscurity.