Hacker News new | ask | show | jobs
by captncraig 3167 days ago
Do you own a huge block of IPs or something? We have a massive monster cert in order to support non sni on a single ip. I hate it.
1 comments

That wouldn't avoid the issue, actually — I need to put a dozen domains in the same IP space with one cert to get this security property.

Otherwise an adversary could simply see what IPs you connect to and reverse DNS them.