logoalt Hacker News

gitgudlast Saturday at 10:42 PM2 repliesview on HN

Wait, so bots watch for new records added to this HTTPS cert public ledger, then immediately start attacking?

To me that sounds like enabling HTTPS is actually a risk here…


Replies

yjftsjthsd-hlast Saturday at 10:57 PM

The server was already exposed. All this does is remove obscurity

show 3 replies
moontearlast Monday at 10:20 AM

Yes. Yes, of course they do. Check for example https://crt.sh with your domain name to see the glorious public history of everything the certificates tell about your domain.