3 ms·
I would save yourself the trouble and create a separate domain now for customer subdomains. The problem with your current path is that it is impossible to tell
by bunkat 12y ago
I would save yourself the trouble and create a separate domain now for customer subdomains. The problem with your current path is that it is impossible to tell the difference between a 7sheep.net subdomain that is owned and operated by 7sheep and a subdomain that is owned and operated by a 3rd party.
For example, training.7sheep.net is an official subdomain, but I could create docs.7sheep.net and make it look like an official subdomain and request peoples account information or do other bad things. GitHub ran into the same problem when they started supporting GitHub pages. Originally these were subdomains off of github.com, but after all the spoofing and other issues they moved them all to github.io. This way you never need to create a list of 'reserved' names and don't need to worry about confusion down the road.
You can read about GitHub's transition and reasoning at https://github.com/blog/1452-new-github-pages-domain-github-io https://github.com/blog/1452-new-github-pages-domain-github-....
- icebraining 12y agoFrankly, I use Github almost every day, and I had no idea of the .com/.io distinction; if I saw a docs.github.io URL, I'd probably assume it was just an alternative domain. The separate domain is a good advice, but I'd rather use something really different (e.g. github-user.com) if I was to let anyone post anything they wanted there.
- SideburnsOfDoom 12y ago> Frankly, I use Github almost every day, and I had no idea of the .com/.io distinction; Neither did I; but a browser does make the distinction. It is a security separation.
- icebraining 12y agoSure, and that's obviously useful, but it doesn't help with social engineering. If the site had a copy of the login page, I can see many people falling for it.
- mtbcoder 12y agoWouldn't you still need to do a combination of filtering and manual moderation even with a subdomain? What would stop someone from creating something like 'login.7sheep.io'? If you are spoofing a domain, you probably aren't too concerned with what the TLD is and are counting on people to glance over it.
- gioele 12y ago> GitHub ran into the same problem when they started supporting GitHub pages. I think this passage is the main reason for the GitHub switch: «Because Pages sites may include custom JavaScript and were hosted on github.com subdomains, it was possible to write (but not read) github.com domain cookies» This is well know cookie security problem: if you have live at x.example.co.uk you can set cookies for example.co.uk and co.uk itself. This is usually evident in organizations like universities that let their departments have their own subdomains run by different software. Usually the root domain contains dozens of unrelated cookies. Mozilla is addressing this with the public suffix list [1], but I think a more solid solution is needed. [1] https://publicsuffix.org/ https://publicsuffix.org/