Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I recently brought up a website on a never-before-seen .com domain. Within about 10 mins of bringing it up with a SSL certificate, Anthropic came knocking on the door requesting the front page. (Almost certainty due to them watching the Public Certificate Transparency logs)


Had a bit setup a new Wordpress install before I could lock it down. I was very confused why a brand new install didn’t give me the setup page before seeing in the logs someone had automated it. Pure evil to be scraping new renewals and dns changes to look for this kinda stuff.

For the record I thought I had this site behind basic auth.


"Public Certificate Transparency logs"...

The scam of "everyone should have SSL" right here, ladies and gentlemen.


How do you know who's visiting? Reverse IP lookups? Or do they announce it in the headers?


I saw it via the User-agent header + confirmed via IP ownership lookup.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: