news.volyx.in

When internal hostnames are leaked to the clown (rachelbythebay.com)

453 points by zdw · 166 days ago · 252 comments on HN

Article summary

The article appears to discuss a situation where internal hostnames were leaked, potentially due to misconfiguration or other security issues, and how this can lead to unwanted traffic and security risks. The exact details of the article are not available, but the comments suggest that the leak may be related to Certificate Transparency logs or other security measures. The discussion revolves around the consequences of such leaks and potential ways to mitigate them. The article's author seems to have experienced issues with their blog being inaccessible due to traffic, which may be related to the hostname leak.

Main themes

  • Hostname leaks
  • Security risks
  • Certificate Transparency logs
  • Misconfiguration
  • Unwanted traffic
  • Security measures

What commenters say

  • The leak of internal hostnames can lead to security risks and unwanted traffic, highlighting the importance of proper security measures.
  • Certificate Transparency logs may be a contributing factor to the leak of internal hostnames, as they publish domain names to the world.
  • Using wildcard certificates can help mitigate the issue of hostname leaks by only publishing the domain name instead of specific hostnames.
  • The use of Let's Encrypt certificates may increase the likelihood of parasite scanning due to the publication of domain names in Certificate Transparency logs.
  • Some argue that the issue is not with Let's Encrypt, but rather with the requirement for all Certificate Authorities to publish certificates to Certificate Transparency logs.
  • Others suggest that the problem lies in the fact that public DNS resolvers sell lists of domain names, which can be used by attackers to target specific hosts.
  • There is disagreement on whether the use of Let's Encrypt certificates increases the risk of security issues, with some arguing that it is a necessary measure for security and others claiming that it leads to more parasite scanning.
  • Some commenters propose that reducing certificate validity to short periods, such as 20 minutes, could help mitigate the issue by making it harder for attackers to scan all hosts in the logs.