|
|
|
|
|
by politelemon
679 days ago
|
|
It's the opposite - there is a risk, but not a larger risk. Environment traversal is easier through a certificate transparency log, there is almost zero work to do. Through a wildcard compromise, the environment is not immediately visible. It's much safer to do wildcard for certs for internal use. |
|
Security by obscurity while making the actual security of endpoints weaker is not an argument in favour of wildcards...