5 ms·
> There are now 40 such TLDs: android, app, bank, chrome, dev, foo, gle, gmail, google, hangout, insurance, meet, page, play, search, youtube, esq, fly, eat, ne
by burglins 3y ago
> There are now 40 such TLDs: android, app, bank, chrome, dev, foo, gle, gmail, google, hangout, insurance, meet, page, play, search, youtube, esq, fly, eat, nexus, ing, meme, phd, prof, boo, dad, day, channel, hotmail, mov, zip, windows, skype, azure, office, bing, xbox, microsoft
Interesting how Google and M$ added their own TLDs (and a fairly large amount of them).
(Edit: .meme and .dad are also google, so it's all forgiven)
- CydeWeys 3y agoWe announced we were doing this way back in 2017 and have stuck to it. It's just surprising that so few others have joined us. https://security.googleblog.com/2017/09/broadening-hsts-to-secure-more-of-web.html https://security.googleblog.com/2017/09/broadening-hsts-to-s...
- bullen 3y agoCan you stop redirecting http to https if there is nothing on port 443 please. Also zip does not execute.
- CydeWeys 3y agohttp is insecure and should not be used. Not always using https would defeat the entire purpose of the added security, not least because a MitM attacker could block only the https packets and then force a silent downgrade to insecure http. It needs to always be https, never anything else.
- jackweirdy 3y agoI know this is good for the internet, but not all HTTP is the internet. I have to upload TLS certificates to a printer. A printer! The printer doesn’t even have a sensible tls algorithms, because its firmware was written at least a decade ago. And the likelihood of someone, anyone, MITMing my printer is 0
- CydeWeys 3y agoNow you're talking about something completely different though. Connecting to a printer over LAN is not at all the same as a Web browser talking to a third party webserver over WAN.
- jackweirdy 3y agoIsn’t the HSTS behaviour identical when the domain is the same, regardless of whether the route goes over the internet? Ie if you have a .dev domain that resolves to your intranet - you will still need HTTPS on example.dev, the browser won’t let you off?
- CydeWeys 3y agoWhy are you connecting to a printer that's on your LAN using a .dev domain on the entire Internet in this example? Also, if this is really a problem, use a different TLD?
- jackweirdy 3y agoBecause using a domain you don't own (https://krebsonsecurity.com/2020/04/microsoft-buys-corp-com-so-bad-guys-cant/ https://krebsonsecurity.com/2020/04/microsoft-buys-corp-com-...) or that isn't an ICANN-known TLD (https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/selecting-the-forest-root-domain#selecting-a-suffix https://learn.microsoft.com/en-us/windows-server/identity/ad...) is trouble Split horizon DNS just how DNS works. Its weird that HSTS preload lists has made security decisions assuming all domains under these TLDs exclusively point to the internet, when that's not how DNS works Just use another TLD is nice when everything is from scratch, but when it isn't it means migrating an intranet to another TLD and managing hostname changes for every instance under the domain...
- bullen 3y agoWhen I link to http (because I want to share public information that never will need encryption), your browser rewrites that to https and then the user gets an error.
- CydeWeys 3y agoYou need encryption even for public information because without it an attacker can change it to anything they want, even a malware download.
- russelg 3y agoWebmasters have a choice and your browser should respect their choice. Stop breaking the web. http://n-gate.com/software/2017/07/12/0/ http://n-gate.com/software/2017/07/12/0/
- CydeWeys 3y agoAnd by choosing a secure TLD to host their content on they're choosing https.
- bullen 3y agoNo, this is ridicoulus. The browser does not execute a jpeg. It displays it. The reason malwares worked was insecure automatic execution in IE. You do NOT need https for the browser to type check and securely sandbox downloaded data. MITM is not the problem, because if I can send a malware from my https server you still have the problem, all https does is waste a ton of electricity for your job (in)security. If your browser requests a jpeg an my https server returns a exe that the browser saves and the user is foolish enough to execute it, that is not a http problem. Stop using your monopoly to force waste.
- russelg 3y agohttp://n-gate.com/software/2017/07/12/0/ http://n-gate.com/software/2017/07/12/0/
- deleted 3y ago[deleted]
- arp242 3y agoThere are a whole bunch of brand TLDs: https://en.wikipedia.org/wiki/List_of_Internet_top-level_domains#Brand_top-level_domains https://en.wikipedia.org/wiki/List_of_Internet_top-level_dom...
- burglins 3y agoIt's kinda weird, I've never seen companies use them. I wonder why?
- arp242 3y agoMe neither, but it seems they are used somewhere, or at least have domains: 153 for .google, 37 for .apple, 2 for .android, 85 for .microsoft, etc. For many non-tech brands they don't seem to have any domains though. https://www.microsoft https://www.microsoft and https://www.hotmail https://www.hotmail seem to work. https://ntldstats.com/tld https://ntldstats.com/tld has some statistics.