Hmm, yeah, that's a great suggestion, thanks!
Also serve the default website (via IP) from a basically empty self-signed certificate that doesn't give away any domain names or owner details.
Also serve the default website (via IP) from a basically empty self-signed certificate that doesn't give away any domain names or owner details.