Example Domain
example.com
example.com
> 2. Application software SHOULD NOT recognize example names as special and SHOULD use example names as they would other domain names.
> 3. Name resolution APIs and libraries SHOULD NOT recognize example names as special and SHOULD NOT treat them differently. Name resolution APIs SHOULD send queries for example names to their configured caching DNS server(s).
> 6. DNS server operators SHOULD be aware that example names are reserved for use in documentation.
You are guaranteed to be able to try and resolve the domain, which should generally be enough for the crappy man-in-the-middle systems to work.
However, example.com should never suddenly start serving you a cryptominer, etc. Which is the larger concern.
I have never seen any captive portal work at DNS level though (and that by itself sounds problematic). They works at HTTP level. So if one day example.com start using HSTS then it will also be a problem, in addition to nowadays browser defaulting to HTTPS so you have to type http://example.com yourself.
neverssl.com guarantees all of that, at least as long as it's there.
It didn't work for me when I tried to use it in the airport (DCA). I tried to get to the captive portal through Firefox and Vivaldi. It took a couple restart of my browser to managed to get to the captive portal. It is not guaranteed that it will work as in my case.
Those were pretty problematic, for all the reasons you're thinking... Better to use a hostname you're not hoping to actually use.
Sure, it might go away one day. Until it does, it’s the best solution to this problem.
Neat tools as until I learned of the existence of these ssl-less sites to prompt captive portals I use to try to connect to various sites until it showed up.
1. Examples
https://security.stackexchange.com/questions/149852/how-legi...
https://zapier.com/blog/open-wifi-login-page/
http://www.my80211.com/home/2012/7/23/web-auth-redirect-does...
Probably the number of people that care about overriding this behavior could be counted on one hand.
> Is this another example of "tech" company paternalism.
No.
It'll never resolve to anything, and makes it really obvious the code is for testing or sample code.
There is a huge chance that you hit a mailbox when you make up an email address.
It's a real domain with functioning... whatever I need to test. Email, DNS, Identity servers, etc.
You'd need the right info at URLs like:
https://example.com/apple-app-site-association
https://example.com/.well-known/apple-app-site-association
https://example.com/.well-known/assetlinks.json (Android)
(which obviously don't exist for this domain)
[1] https://developer.android.com/training/app-links/verify-site...
.test
.example
.invalid
.localhosthttps://krebsonsecurity.com/2020/04/microsoft-buys-corp-com-...
$ dig example.com. mx +short
0 .
It has an interesting MX record. I wonder what this does? Specifically, what should a mail agent do when the MX record points to "." ?https://www.iana.org/assignments/special-use-domain-names/sp...
I only left the Alexa on for a week while I was recovering from eye surgery, but it made those the top three most frequently queried domains for that whole month on my pi-hole charts.
Presumably it was some connectivity test, but all three of those domains were hosted at the same IP at the time. Which would defeat the point of using three domains, if the goal was to reduce the possibility of one outage causing a false negative on the test.
Edit: its a chrome extenstion I use.
But you are right. Its not really the fault of the markup of the side.
I use "Definer" chrome plugin [1].
That injects a absolute positioned #definer-bubble div with width:100% that does not work well with sites css thats sets a margin for every div.
https://chrome.google.com/webstore/detail/definer-advanced-p...