The Root of All E-Mail
wiredog writes "A Washington Post story about the DNS, the VeriSign NOC, and some of the security therein." Especially interesting in light of the recent security lockdowns throughout much of the Western world. The havoc of losing the A root server would be bad, like Staypuft Marshmallow Man bad.
Obscurity is the first line of defense. The building is unmarked, its address unspecified in company literature and its managers tight-lipped about disclosing driving directions or identifying markings to strangers.
They are apparently okay with featuring the place in an article in the Washington Post, though. Sheesh.
I watched C-beams glitter in the dark near the Tannhauser gate.
Reading about the physical security is interesting. I'm wondering why they wouldn't just contract out with the Government and move the operation to a secure military installation somewhere in the DC area. There are plenty of them around there. Granted, it seems that they have taken care of their current security needs, but it might be cheaper/easier to locate it in a protected area that is already guarded. I get the feeling that "Security through Obfuscation" (the actual building) might not be the best policy.
Still fascinating though.
Jason
He's totally creeping out the Great One, eh...
Security through obscurity will never solve anything when used as the first line of defense.
Dude, it's the first line of defense, not the ONLY line of defense. Read the article.
There is nothing wrong with security through obscurity as one facet of security. It's when it's the only security that it's a problem.
Sometimes it's best to just let stupid people be stupid.
Oh, I don't know about that. Sure, it's bad when it's the only line of defence, but as a mere "first" line I think it's perfectly reasonable. (Just as it's a reasonable defence to, say, have your web server misidentify itself, or to have an unlisted phone number, or what have you.) As long as the layers of security behind this first one are robust, obscurity is perfectly reasonable as a front line defense.
No offence, but thank god you're not, buddy... :)
Oh baloney, they work all the time. Maybe you should consider putting down the standard /. party line and try putting some of this hyperbole into perspective. If secrets have never worked then why is the story of the Trojan Horse so famous? If secrets have never mattered then why is the element of surprise considered to be so tactically valuable? If secrets didn't matter to security then why did Nixon have those 18 minutes of blank tape, and why did Cheney turn in thousands of blank documents, and why do all governments bother classifying things as top secret?
If you're in a position of just stupendously overwhelming strength -- like say if the US were to invade Bermuda tomorrow -- then no I don't suppose you need to be all that secretive about things. For everyone else, in every other situation, secrets can have an important role to play. Even if trolls would suggest otherwise.
DO NOT LEAVE IT IS NOT REAL
As briefly noted in the Post article, the DNS infrastructure, like most essential net technology, pretty much doesn't have any single points of failure. It's immune to local physical attacks or natural disasters. The article is just a sensationalist trip into a modern high security datacenter full of Ooh-ing and Aah-ing, and doesn't have much relevance at all to the security or stability of the 'net.
11*43+456^2