logoalt Hacker News

Faelian2 • today at 4:15 PM • 2 replies • view on HN

It's a shame that ICANN did get so greedy and put everyone at risk.

Having internal domain names owned by some guy on the internet has already compromised multiple corporate networks. See the talk from this guy:

https://www.romhack.io/wp-content/uploads/2025/10/Internal-D...


Replies

stackskipton • today at 4:23 PM

As former AD person and dealing with that several companies, the recommendation for internal network DNS has long been subdomain.company.com that is not on public internet.

Even today when setting up greenfield networks, I generally use internal.company.com. It also lets you get public trusted SSL certificates so you don't have to deal with internal PKI.

➕ show 1 reply
john_strinlai • today at 4:19 PM

im not super keen on all of these gTLDs, but anyone choosing to use .lan should have been aware of the risks of using an unofficial/unreserved domain.

at the very least, the .dev stuff should have had people second-guessing their usage of unreserved domains.

➕ show 2 replies