TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Domain Validation and Padlocks

2 点作者 _jomo超过 6 年前

1 comment

LinuxBender超过 6 年前
You can also use LetsEncrypt to get a wildcard for any domain and put &quot;paypal&quot; in front of it. That won&#x27;t even show up in the cert transparency database [1] or any of the API&#x27;s that spammer bots use for newly registered domains.<p>The reason I mention this is that you can have dozens or hundreds of domains warmed up and ready to provide malicious websites. And to the point of the authors site, there is no way to tell that these sites are not legit, beyond people knowing in advance that paypal uses EV certs and the average person has no idea what EV certs are.<p>[1] - <a href="https:&#x2F;&#x2F;crt.sh&#x2F;?id=1106070533" rel="nofollow">https:&#x2F;&#x2F;crt.sh&#x2F;?id=1106070533</a>