logoalt Hacker News

binkyesterday at 7:42 PM1 replyview on HN

The TLS/SSL and DNS carveouts are pretty normal. There are a million security options for those services and enabling them all would often mean denying access to anyone running a browser/client more than a few weeks old. Documenting them all would be a PITA so most policies simply prohibit them entirely.

Testing against customers is also a common prohibition for obvious reasons.


Replies

vayuptoday at 1:06 AM

Hm... not normal in my experience. Not enabling a config is not a vulnerability in itself. If not enabling something means a security guarantee is broken (Eg: videos are accessible) then it is a vulnerability, and typically included in VDP, atleast VDPs that are in good faith.