The proliferation of new top-level domains (TLDs) has exacerbated a well-known security weakness: Many organizations set up their internal Microsoft authentication systems years ago using domain names in TLDs that didn’t exist at the time. Meaning, they are continuously sending their Windows usernames and passwords to domain names they do not control and which are freely available for anyone to register. Here’s a look at one security researcher’s efforts to map and shrink the size of this insidious problem.

  • taladar
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 months ago

    From what I recall Kerberos didn’t work all that well in environments with NAT so it is unlikely to replace modern single sign on systems like OpenID Connect.