4 ms·
I know this is good for the internet, but not all HTTP is the internet. I have to upload TLS certificates to a printer. A printer! The printer doesn’t even ha
by jackweirdy 3y ago
I know this is good for the internet, but not all HTTP is the internet.
I have to upload TLS certificates to a printer. A printer!
The printer doesn’t even have a sensible tls algorithms, because its firmware was written at least a decade ago. And the likelihood of someone, anyone, MITMing my printer is 0
- CydeWeys 3y agoNow you're talking about something completely different though. Connecting to a printer over LAN is not at all the same as a Web browser talking to a third party webserver over WAN.
- jackweirdy 3y agoIsn’t the HSTS behaviour identical when the domain is the same, regardless of whether the route goes over the internet? Ie if you have a .dev domain that resolves to your intranet - you will still need HTTPS on example.dev, the browser won’t let you off?
- CydeWeys 3y agoWhy are you connecting to a printer that's on your LAN using a .dev domain on the entire Internet in this example? Also, if this is really a problem, use a different TLD?
- jackweirdy 3y agoBecause using a domain you don't own (https://krebsonsecurity.com/2020/04/microsoft-buys-corp-com-so-bad-guys-cant/ https://krebsonsecurity.com/2020/04/microsoft-buys-corp-com-...) or that isn't an ICANN-known TLD (https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/selecting-the-forest-root-domain#selecting-a-suffix https://learn.microsoft.com/en-us/windows-server/identity/ad...) is trouble Split horizon DNS just how DNS works. Its weird that HSTS preload lists has made security decisions assuming all domains under these TLDs exclusively point to the internet, when that's not how DNS works Just use another TLD is nice when everything is from scratch, but when it isn't it means migrating an intranet to another TLD and managing hostname changes for every instance under the domain...