Technical notes on web development, DevOps, and AI integration.
1 article
Certificate Transparency logs publish every TLS certificate, SAN list included. Hostnames can surface before DNS ever shows them.
TL;DR: A TLS scan uncovered a hidden staging hostname via the certificate's SAN list, invisible to DNS enumeration. That's because Certificate Transparency makes every publicly-trusted issuance public and permanent, sometimes before DNS records or deployment exist. This cuts both ways: defenders spot unauthorized certificates while attackers discover hostnames early, though a logged name proves intent, not a live service.