Interesting how Google and M$ added their own TLDs (and a fairly large amount of them).
(Edit: .meme and .dad are also google, so it's all forgiven)
Interesting how Google and M$ added their own TLDs (and a fairly large amount of them).
(Edit: .meme and .dad are also google, so it's all forgiven)
https://security.googleblog.com/2017/09/broadening-hsts-to-s...
Also zip does not execute.
I have to upload TLS certificates to a printer. A printer!
The printer doesn’t even have a sensible tls algorithms, because its firmware was written at least a decade ago. And the likelihood of someone, anyone, MITMing my printer is 0
Ie if you have a .dev domain that resolves to your intranet - you will still need HTTPS on example.dev, the browser won’t let you off?
Also, if this is really a problem, use a different TLD?
Split horizon DNS just how DNS works. Its weird that HSTS preload lists has made security decisions assuming all domains under these TLDs exclusively point to the internet, when that's not how DNS works
Just use another TLD is nice when everything is from scratch, but when it isn't it means migrating an intranet to another TLD and managing hostname changes for every instance under the domain...
The reason malwares worked was insecure automatic execution in IE. You do NOT need https for the browser to type check and securely sandbox downloaded data.
MITM is not the problem, because if I can send a malware from my https server you still have the problem, all https does is waste a ton of electricity for your job (in)security.
If your browser requests a jpeg an my https server returns a exe that the browser saves and the user is foolish enough to execute it, that is not a http problem.
Stop using your monopoly to force waste.
https://www.microsoft and https://www.hotmail seem to work.
https://ntldstats.com/tld has some statistics.