3 ms·
Isn’t the HSTS behaviour identical when the domain is the same, regardless of whether the route goes over the internet? Ie if you have a .dev domain that resol
by jackweirdy 3y ago
Isn’t the HSTS behaviour identical when the domain is the same, regardless of whether the route goes over the internet?
Ie if you have a .dev domain that resolves to your intranet - you will still need HTTPS on example.dev, the browser won’t let you off?
- CydeWeys 3y agoWhy are you connecting to a printer that's on your LAN using a .dev domain on the entire Internet in this example? Also, if this is really a problem, use a different TLD?
- jackweirdy 3y agoBecause using a domain you don't own (https://krebsonsecurity.com/2020/04/microsoft-buys-corp-com-so-bad-guys-cant/ https://krebsonsecurity.com/2020/04/microsoft-buys-corp-com-...) or that isn't an ICANN-known TLD (https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/selecting-the-forest-root-domain#selecting-a-suffix https://learn.microsoft.com/en-us/windows-server/identity/ad...) is trouble Split horizon DNS just how DNS works. Its weird that HSTS preload lists has made security decisions assuming all domains under these TLDs exclusively point to the internet, when that's not how DNS works Just use another TLD is nice when everything is from scratch, but when it isn't it means migrating an intranet to another TLD and managing hostname changes for every instance under the domain...