← Back to context

Comment by zahrevsky

1 day ago

> There is no requirement there is a HTTP service present on the host in order to fulfill its purpose, we just operate it as a courtesy.

I guess this is also done to prevent bad actors from abusing the fact that this domain is hit by people who might not know what they're doing (the ones copy-pasting code without reading it)

More the DNS and DNSSEC and the like. Whether or not there is actually an HTTP server responding is irrelevant to whether or not those securely point anywhere but a malicious system.

Yeah there’s definitely a lot of sensitive data that gets sent to the domain just because of people not changing configs