4 ms·
Because using a domain you don't own (https://krebsonsecurity.com/2020/04/microsoft-buys-corp-com-so-bad-guys-cant/ https://krebsonsecurity.com/2020/04/microsof
by jackweirdy 3y ago
Because using a domain you don't own (https://krebsonsecurity.com/2020/04/microsoft-buys-corp-com-so-bad-guys-cant/ https://krebsonsecurity.com/2020/04/microsoft-buys-corp-com-...) or that isn't an ICANN-known TLD (https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/selecting-the-forest-root-domain#selecting-a-suffix https://learn.microsoft.com/en-us/windows-server/identity/ad...) is trouble
Split horizon DNS just how DNS works. Its weird that HSTS preload lists has made security decisions assuming all domains under these TLDs exclusively point to the internet, when that's not how DNS works
Just use another TLD is nice when everything is from scratch, but when it isn't it means migrating an intranet to another TLD and managing hostname changes for every instance under the domain...