This is a completely unacceptable vulnerability in any software purporting itself to be an identity provider. OP, name and shame this provider. I do not want to find myself using it.
Question: How does a subdomain get discovered by a member of the public if there are no references to it anywhere online?
The only thing I can think of that would let you do that would be a DNS zone transfer request, but those are almost always disallowed from most origin IPs.
Honest question, why is this your reaction? Why are people on this forum so unwilling to be happy for others? I have noticed that this attitude is extremely prominent in tech. Everything is either perfect (according to the person making the judgement) or it’s utterly worthy of ridicule. I am growing very, very tired of seeing this throughout tech.
Well, maybe he shouldn’t but it seems he’d rather not deal with this problem at all and now we have the status quo. That has to be a situation you’re willing to accept, unless you’re saying Facebook should be forced to allow news, and be forced to pay for it.
Isn't this more to prevent ISPs from modifying the results of your DNS queries? Also, in the future when we get encrypted SNI, users of websites behind CDNs like CloudFlare or similar (where the website you are visiting will not be discernible from the IP you're connecting to) will benefit from DoH + eSNI.
Maybe I'm misunderstanding, but why would there be a boot time flag instead of just having two versions, seeing as a particular CPU could only run one version?
If the United States pre-emptively attacks a foreign country with a cyber attack resulting in the loss of human life, then yes, Russia or any state would be justified in retaliating. This is equally true for any such use of any weapon of mass destruction.
Then we should not be so meek as to do nothing. During the Cold War, nations did not sit idly by as their adversaries developed nuclear capabilities which, make no mistake about it, targeted civilians and civilian infrastructure. Of course, we developed our own defensive capabilities but then, as now, we faced a type of threat which hugely favored the attacker. So we kept pace with the offensive capabilities of our adversaries. If China or Russia (the states themselves) is identified beyond doubt as the source of this attack, then our policy must be to retaliate in kind.
Mutually assured destruction for the cyber-age.
If it's organized criminal hackers we're dealing with, then we should treat them how we would treat any legitimate terroristic threat. I would want our intelligence agencies to reach out and touch them.
This may not be a popular point of view on Hacker News. I unfortunately cannot fathom an alternative solution.