4 ms·
I'm wondering whether people have tried this as a workaround for some use cases: 1. Use a CA that allows certificate-transparency opt out, e.g., https://docs.a
by pledess 5y ago
I'm wondering whether people have tried this as a workaround for some use cases:
1. Use a CA that allows certificate-transparency opt out, e.g., https://docs.aws.amazon.com/acm/latest/userguide/acm-bestpractices.html https://docs.aws.amazon.com/acm/latest/userguide/acm-bestpra...
2. Restrict the browsers that access the website before its public launch. For example, only use a custom build of Chromium that's been modified to omit all of the code for certificate-transparency checks.
In theory, it's possible to have perfect access control for the staging website, and it's possible to ensure that the staging website's hostname reveals nothing about an undisclosed business plan. In practice, though, probably not. I feel that certificate-transparency opt out is occasionally a reasonable mitigation for https://attack.mitre.org/techniques/T1596/ https://attack.mitre.org/techniques/T1596/