Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You seem to be assuming that there needs to be a distinctive backend codebase for each domain covering the wildcard certificate.

This is something entirely orthogonal to the number of certificates. You could have 1000 codebases with different attack vectors under one SSL certificate, or 1 codebase the same attack vectors serving up 1000 SSL certificates.



I'm not sure I follow?

What I was trying to say was that it's a good idea to have one key per DISTINCT($attack_surface), which includes anything from physical security to the software stack, in order to limit the damage during a compromise. Throwing wildcards at everything tends to go against that principle, even though I admit there are use-cases where wildcards are entirely appropriate (namely those where each subdomain has the exact same attack surface anyway), and using something else isn't worth the trouble.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: