Hello All,
Recently, I came across this domain: www.youtube-nocookie.com in duckduckgo.com
which basically uses it for to play embeeded Videos
As you all know DuckDuckGo focus more on removing the tracking, so they use this Domain, this is my idea behind using youtube-nocookie in place of youtube.com
but anyways
it is good.
After this i tried DOMAIN: youtube-nocookie.com
which is also the same Domain
but what i saw was really strange
Google is a big Giant, It can buy a New Certificate for youtube-nocookie or it can add SAN to the Existing one.
Strange that they left with a Default Google.com certificate which actually does not has youtube-nocookie.com
Which i feel is wrong. but anyway it is not used by Google, so it is OKAY kind of of stuff.
but for me,it was something interesting.
so posted it
have a look at the POC.
Is Big Giants like Google doing it right,when trying to do SSL Configuration?
Re: Is Big Giants like Google doing it right,when trying to do SSL Configuration?
Google is using a certificate that includes *.youtube-nocookie.com in SAN (Subject Alternative Names) but does not include youtube-nocookie.com. Looks like the erratic certificate was issued recently by an versight. Terrible, yes. Even organisations considered to be "authoritative" can make such serious mistakes.