

Yeah… No
I didn’t mean RFC Base32.
I meant human-safe alphabets.
Base58 or Crockford Base32 that intentionally remove I, L, O, and 1 (which is distinct from “base 32”).
RFC Base32 still hits the exact problem I’m ranting about.
To be clear the (vanilla) base32 version of the aforementioned string:
“I dont fucking know lots of lllllIIIIIIlllIII etc”
Outputs:
“JEQGI33OOQQGM5LDNNUW4ZZANNXG65ZANRXXI4ZAN5TCA3DMNRWGYSKJJFEUSSLMNRWESSKJEBSXIYY=”
You can use cyberchef to check for yourself.
This does not solve the problem.
I meant what I’d said: base 58.


https://crt.sh/
When a CA issues an SSL/TLS certificate, they’re required to submit it to public CT logs (append-only, cryptographically verifiable ledgers). This was designed to detect misissued or malicious certificates.
Red and Blue team alike use this resource (crt.sh) to enumerate subdomains.