Kaminsky flaw fixed for .com and .net by 2011
By Asavin Wattanajantra,
DNSSEC, the long-term solution to the Kaminsky vulnerability, should be completed for .com and .net domains by the first quarter of 2011.
So claims internet infrastructure company Verisign, which said it had made rolling out DNSSEC a "strategic priority," working with ICANN and business communities in a "collaborative industry-wide effort".
The Kaminsky vulnerability made headlines in 2008 for affecting the internet Domain Name System (DNS), which changes web addresses to IP addresses.
The flaw meant that users could be sent to malicious sites even if they typed in legitimate addresses, and forced a multi-vendor effort to fix the problem.
DNSSEC adds an extra layer of cryptography, which enables organisations to digitally sign their DNS data.
“This means that name servers that support DNSSEC can cryptographically authenticate and check the integrity of that data,” said Cricket Liu, vice president of architecture at Infoblox.
“That makes things like the Kaminsky vulnerability, which is a cache poisoning attack, impossible to carry out.”
Liu said that, up until recently, it had been difficult to put DNSSEC into place as it was "complex”.
“Tools that you would use to digitally sign the DNS data have been fairly rudimentary,” he said.
According to Infoblox’s annual DNS survey, released on the same day as Verisign’s announcement, the number of DNSSEC signed zones had increased by approximately 300 per cent.
Liu said: “In terms of the percentage it is pretty impressive, but in terms of the absolute zones that have been signed, it is pretty small.”
“We’d really like to see the adoption continue to increase,” he added.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Public Sector Analysis & Insight
Striving to solve the security skills crisis
The Cyber Security Challenge is doing a fine job, but flat registration growth and weak Government funding are cause for concern, Tom Brewster discovers.
- 2011: The year in news
- Are the cookie laws crumbling already?
- UK rural broadband: too little, and too late
- How the Data Protection Act's death will punish the UK economy
- Education: glad to be a geek
- Plugging public sector data leaks
- Going for Gold - IT at the London Olympics
- Fujitsu: out to steal HP market share
- What will Windows Mango mean for business?
Latest Public Sector Reviews
HTC Flyer review: First Look
- HP TouchPad review: First Look
- RIM BlackBerry PlayBook review - First Look
- MWC 2011: Acer Iconia A100 and A500 reviews – first look videos
- MWC 2011: HP TouchPad review - first look video
- MWC 2011: RIM BlackBerry PlayBook review - first look video
- MWC 2011: HP Pre3 review - first look video
- MWC 2011: Motorola Pro review - first look video
- MWC 2011: HTC Flyer tablet review - first look video
- MWC 2011: Samsung Galaxy Tab 10.1 review – first look video
advertisement
Most popular
- Ubuntu vs. Windows 7 on the business desktop
- York researchers heat storage to speed up data
- BlackBerry Bold 9790 review
- OneNote hits Google?s Android
- O2 trials Olympic-scale remote working
- Will someone rid me of these troublesome Macs?
- Lenovo beats expectations again
- Who to trust after the VeriSign hack?
- Google to promise fairness after Motorola buy
- Report: Google cloud storage coming soon
Latest News Videos in Public Sector
Q&A: David Elton, PA Consulting Group
CIOs are increasingly influential, but have to juggle "dual roles", study finds.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.



