4 ms·
> Apparently some folks, like the people running ccTLD registries, believe that allowing the public to know IP addresses for large numbers of domains is a "secu
by gregmac 4y ago
> Apparently some folks, like the people running ccTLD registries, believe that allowing the public to know IP addresses for large numbers of domains is a "security" issue.
There's some merit to this.
Doing the reverse lookup - finding all other domains that resolve to the same IP (or same subnet) can leak a lot of information. For example: what other businesses are run by the same entity, and test/staging/admin infrastructure.
It can also be another way to attack a specific http server, since different names on the same IP can be routed to different applications or even different internal servers.
Actually relying on this is silly security-by-obscurity, but there's really no upside to publishing a detailed map.