Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's all TLS certs, because they show up in the Transparency Log[1]

You can watch a live stream of it here: https://bencevans.io/security/certificate-stream

[1] https://en.wikipedia.org/wiki/Certificate_Transparency



I use subdomains and a wildcard cert to partly obfuscate this.


I do the same, but I switched from cert-per-subdomain a couple of years ago.

They're either using Passive DNS logs or a historical dataset.


When I stood up some sites last year, I used codenames for the subdomains thinking I was obfuscating a little. I didn't know about the transparency logs until months later.


TIL about Certificate Transparency (they didn't teach that in security school)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: