fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

10K
active users

fishy

TIL about Certificate Transparency logs, basically every Let's Encrypt certificate you got shows up there as public information, so your subdomains are also public information.

crt.sh/ is a good tool to check that yourself.

crt.shcrt.sh | Certificate SearchFree CT Log Certificate Search Tool from Sectigo (formerly Comodo CA)

@fishy This feels pretty significant. You could sure leak information this way

@annika @fishy Yeah I feel NSEC3 records became obsolete after CT. Just sign the whole zone, lol

@Extelec @fishy It's extra fun if you're weird and have a standalone DNS server JUST for Let's Encrypt validations, but then you get to watch obviously sketchy queries come in, clearly by people monitoring the Certificate Transparency log.

Truly enlightening insights! 😬