logoalt Hacker News

Jnrlast Sunday at 5:30 PM1 replyview on HN

Cloudflare also issues certs and logs them in transparency logs. If you do not create a wildcard cert in Cloudflare, your subdomains will leak. And Cloudflare offers free wildcard certs only on the domain root.


Replies

j45last Sunday at 7:02 PM

Appreciate this super valid consideration.

If services are being exposed for friends and family, using cloudflare tunnels might be a trade off between security or convenience.

If the goal is to ensure security of a home lab online, the less of it that’s discoverable by automated bots, etc, the better.