|
|
|
|
|
by greatgib
481 days ago
|
|
In theory it is good, but somehow it is also a big threat to privacy and security of your infrastructure. No need anymore to scan your network to map the complete endpoints of your infrastructure! And it's a new single point of control and failure! |
|
The fact that public infrastructure is mappable is actually beneficial. It helps enforce best practices rather than relying on the flawed 'no one will discover this endpoint' approach.
> And it's a new single point of control and failure!
This reasoning is flawed. X.509 certificates themselves embed SCTs.
While log unavailability may temporarily affect new certificate issuance, there are numerous logs operated by diverse organizations precisely to prevent single points of failure.
Certificate validation doesn't require active log servers once SCTs are embedded.