Slashdot Mirror


Security Researcher Kaminsky Pushes DNS Patching

BobB-nw writes "Dan Kaminsky, who for years was ambivalent about securing DNS, has become an ardent supporter of DNS Security Extensions. Speaking at the Black Hat DC 2009 conference Thursday, the prominent security researcher told the audience that the lack of DNS security not only makes the Internet vulnerable, but is also crippling the scalability of important security technologies. 'DNS is pretty much our only way to scale systems across organizational boundaries, and because it is insecure it's infecting everything else that uses' DNS, the fundamental Internet protocol that provides an IP address for a given domain name, said Kaminsky, director of penetration testing at IOActive. 'The only group that has actually avoided DNS because it's insecure are security technologies, and therefore those technologies aren't scaling.'"

7 of 57 comments (clear)

  1. Job title by psnyder · · Score: 5, Funny

    I'd love to have the title "Director of Penetration Testing", but can only think of 2 types of jobs where the title is appropriate. And I don't have the stamina for either.

    1. Re:Job title by pushing-robot · · Score: 2, Funny

      Bombardier?

      --
      How can I believe you when you tell me what I don't want to hear?
    2. Re:Job title by Anonymous Coward · · Score: 4, Funny

      -1 Tasteless

      says someone who chose the handle Penguinshit

  2. Re:One trick pony by gavron · · Score: 1, Funny
    Try this link:

    http://www.google.com/

  3. Re:Bad Article, Bad Summary by SIR_Taco · · Score: 4, Funny

    mmmmmmmmmmmmmmmm... unfortunate salad

    --
    I say don't drink and drive, you might spill your drink. Before you get behind the wheel just stop and think.
  4. Re:Who is Dan Kaminsky by ascari · · Score: 5, Funny

    It's a DNS error: Mark Russinovich and Dan Kaminsky resolve to the same person.

  5. Re:Who is Dan Kaminsky by mewsenews · · Score: 4, Funny

    His picture is available online, and he looks like a regular decent guy, for whatever that's worth.

    Sorry, he's not attractive enough for me to consider him a network security expert (what the hell???)