3 ms·
I saw a successful attack on a .dev domain doing exactly this. Links on PCs worked correctly, but phones showed a scam site, so emailed links were attacked. It
by blowski 3y ago
I saw a successful attack on a .dev domain doing exactly this. Links on PCs worked correctly, but phones showed a scam site, so emailed links were attacked.
It was hard to fix because they couldn’t get the spoofed domain, and there were so many copies of bad links everywhere.
- gerwim 3y agoAnother fun fact about .dev which I recently found out while working on a side project: You NEED to use https when visiting any .dev domain. Google has put it on the HSTS preload list. It took me a while to find out why my browser kept redirecting me to https when I wanted to use http (local development). Curl worked fine…
- chopin 3y agoPretty much the first I do on any fresh server is to disable http, no matter what it is used for. IMHO http has no use in the modern world.
- traceroute66 3y ago> Google has put it on the HSTS preload list. Just for the record, anybody can add their own domain to HSTS via the submission site[1]. [1] https://hstspreload.org/ https://hstspreload.org/