Hacker News new | ask | show | jobs
by CoryG89 2970 days ago
So? If we qualify it to preventing unauthorized use of one of their rented domains does that make it any less reasonable?
1 comments

The conceit here is that you must be "authorized" in order to write an app that puts the domain in question into the SNI field of a TLS connection that it initiates. I don't think that's reasonable.

It is of course up to Amazon what their servers then do when presented with such a connection, in particular whether they ensure the Host: header later presented matches the SNI data.