← Back to context

Comment by bigiain

7 hours ago

I reckon there's a decent argument to be made that an authorization to scan *.tesla.com definitively does NOT extend to any hosts resolved via a CNAME chain that goes foo.tesla.com -> bah.not-tesla.com -> host-that-never-authorized-attacking.

Pretty hard to implement in practice!

% dig www.tesla.com +short

www.tesla.com.edgekey.net.

e1792.dscx.akamaiedge.net.

<akamai IP>