DNSSEC Comes To .Net Zone Today
wiredmikey sends news that as of today VeriSign has enabled DNSSEC on the .net zone. This is one milestone in a years-long process of securing the DNS against cache poisoning and other attacks. Next step will be for VeriSign to sign the .com root early next year."Having DNSSEC enabled for .net domains... [is] important as it represents one of the most critical implementations of DNSSEC technology, since .net serves as the underpinning for many critical Internet functions. The largest zone to be DNSSEC enabled to date, .net currently has more than 13 million... domain name registrations worldwide."
worldwideds
Am I just spending too much time on /. or have there been a lot of typos in stories recently?
It may be more secure for business, but it's less secure now for private individuals and the politically-active. Also, it's not more secure for websites not based in the United States, as those keys are already in government possession. This is just another way for the United States to exert control over an international resource for its own gain. And we're giving up that decentralized and free nature of the internet because of hackers/terrorists/boogiemen? Sad day.
#fuckbeta #iamslashdot #dicemustdie
Looks like the lawyers of Microsoft were anticipating this move and were itching for a fight. They have sued the entire internet for infringing on their trademark .Net
sed -e 's/Chuck Norris/Rajnikant/g' joke > fact
Fucking idiot. Learn to spell. "worldwideds" ?
Does DNSSEC allow storing SSL certificates in the DNS records? It would seem that this is an awesome way of getting free SSL certificates.
Also, I doubt anyone bothered with this, but does DNSSEC have any way of saying "this domain should only be contacted with SSL"? That would prevent SSL stripping MitM attacks.
Actually, .net was enabled sometime around 16:00 GMT yesterday. They just didn't announce it until today.
I was doing testing of a DNSSEC system yesterday, and one of my test cases change state on me unexpectedly. (Signed zone in an unsigned parent)
"It may be more secure for business, but it's less secure now for private individuals and the politically-active." - by girlintraining (1395911) on Friday December 10, @09:48AM (#34513928)
Per my subject-line above: This is part of the "WHY" I do "hardcodes" of 250 of my fav. sites into my custom HOSTS file (912,000 unique entries, mostly for blocking out KNOWN sites/servers/domain-host names that are known to serve up exploits)
However, for the case of speeding yourself up - some of my custom HOSTS files entries are for avoiding DNS request logs, and to be able to reach said fav. sites of mine F A S T E R (by not doing the roundtrip resolution for IP Address - to - Host/Domain names, since HDD access alone (7-10ms access, vs. 30ms or more to DNS servers roundtrip) is faster!
Especially once my HOSTS is cached, it then even goes FASTER (after the 1st request to it gets cached into RAM via caches).
Plus, I get there, & even IF the DNS server is redirect-poisoned, or is down even!
Then, the custom HOSTS file is read F A S T (after changes to it in %WinDir%\system32\drivers\etc, it's marked/flagged as "dirty", & reloads)
Then, it's cached into RAM!
That's either by the DNS ClientCache service in Windows (junk, it's limited in size & uses a queue/structure - you must turn this off saving both RAM &/or CPU cycles used for its operation, with relatively "largish" HOSTS files) OR then, its cached via the local kernel mode diskcaching subsystem (works on HOSTS files of ANY SIZE), it's operating @ the SPEED OF RAM!)
APK
P.S.=> Don't get me wrong though: I do think that DNSSEC is overall, a GOOD thing... even if only for businesses &/or the gov't. as you feel "git"
As far as DNS servers though? I cannot put the "entire internet" into my HOSTS file w/ the IP Address - to - Domain/Hosts name equation in for "every site there is under the sun", so I use OpenDNS or ScrubIT DNS (there's also GOOGLE's DNS & even AMAZON DNS now as alternatives also) for that...
Why?
Well, when Mr. Dan Kaminsky found the "kaminsky flaw" in DNS servers for a form of redirect poisoning, OpenDNS was the FIRST TO PATCH no less!
(I.E.-> The "general mechanics" of which work like so - You "bum rush" a DNS server that someone you wish to attack & that you have "lured" to a certain site via a URL for example for them to click on? You, as the attacker, flood said DNS server with tons of false 50's series ports updates to it, & you have them)
The problem w/ unpatched DNS vs. this (especially if the DNS server's are in recursive mode)?
They take the FIRST REPLY THEY SEE & DON'T VERIFY IT! This makes redirection poisoning a second's notice (& Mr. Kaminsky demonstrated it, seconds of work only...)
Other forms of redirect exist also (std. DNS poisoning) or what the Chinese are doing with DNS too:
BIND vs. what the Chinese are doing to DNS lately? See here:
http://yro.slashdot.org/story/10/11/29/1755230/Chinese-DNS-Tampering-a-Real-Threat-To-Outsiders
or
SECUNIA HIT BY DNS REDIRECTION HACK THIS WEEK:
http://www.theregister.co.uk/2010/11/26/secunia_back_from_dns_hack/
(Yes, even "security pros" are helpless vs. DNS problems in code bugs OR redirect DNS poisoning issues, & they can only try to "set the DNS record straight" & then, they still have to wait for corrected DNS info. to propogate across all subordinate DNS servers too - lagtime in which folks DO get "abused" in mind you!)
When THAT occurred in the latter? I was going to the site ALL WEEK LONG even when the update propogations were lagging to subordinate DNS servers... & simply because of the hardcodes in my HOSTS file.
I stay safe(r) from it, & faster too... Especi
Yesterday I thought we were planning on getting rid of DNS... huh.
Cool, does it really have a proper delegation chain through the name hierarchy?
If so, how long until we can get automatically-generated, free server certificates based on this? There shouldn't be a need for any fees to validate this delegation chain, if it's been designed correctly to allow every client to validate the chain.
It's always been a complete sham that you have to pay some random CA to assert an FQDN to CN/public key binding, when it ought to be a trivial function of the existing DNS system that knows who controls each FQDN. Even worse, trusting a CA means trusting them to make assertions about any part of the FQDN space, no matter how little actual authority the CA has over that namespace.
What is the .NET Zone? Is that where Silverlight came from? Do you just mean the .net TLD?
And yet when the US government asked VeriSign to revoke domain names, all the root servers mirrored that decision. Just because DNS is distributed doesn't make it the least bit decentralized.
I'm aware that DNSSEC is currently supported in test builds of PowerDNS, but consider this a vote for having it available in stable by the time .com gets signed..
(In the interim, I figure having BIND slaves serving data off of PowerDNS would work, since PDNS can handle DNSSEC RR types)
-1 Troll? Please - Is this malware makers, disgruntled webmasters, or advertisers doing this?? They're the ONLY ones that might even think about modding down a post where I show others the benefits of HOSTS files usage.
After all, I can make that assumption above, because it's only a simple matter of using that old adage of "follow the money"...
Mr. Bruce Perens can say how it is, better than I can, when it comes to "big money online" & what they'll TRY to do, to keep that money coming &/or their "rep" clean:
"I have been offered the online-perception-management services I'm talking about while managing at HP and Sourcelabs. If you are not aware of companys concern for their online perception and what they do about it, and won't take my word for it, there isn't much point in arguing about it with you." - by Bruce Perens (3872)
on Friday July 30, @09:27PM (#33092398) Homepage Journal
FROM -> http://linux.slashdot.org/comments.pl?sid=1738364&cid=33092398
and
"It just takes one Ubuntu sympathizer or PR flack to minus-moderate any comment. Unfortunately, once PR agencies and so on started paying people to moderate online communities, and to have hundreds of accounts each, things changed." - by Bruce Perens (3872) on Friday July 30, @03:55PM (#33089192) Homepage Journal
FROM -> http://linux.slashdot.org/comments.pl?sid=1738364&cid=33089192
APK
P.S.=> See my subject-line above, and the content from Mr. Bruce Perens... Does whoever is downmodding me, from a formerly "up modded" post even begin to *THINK* they're fooling anyone here? apk
TomHudson goes DOWN too easily, especially on HOSTS file data, vs. myself... everytime:
http://tech.slashdot.org/comments.pl?sid=1699526&cid=32716428
There in that URL?
Your "hero" tomhudson, ran, & refused to answer questions put to he many times, and in the end? All tomhudson had was effete name-tossing &/or adhominem attack attempts, vs. the facts I use in favor of HOSTS files...
(LMAO - it ALL there, in "black & white" too, no denying it!)
So, please - DO go ahead, & do call on "your hero" tomhudson, please!
As I'll trash him just as easily here this time, and then some, as I did before numerous times on this topic of HOSTS files (& others).
APK
P.S.=> You trolls, you just DON'T GET IT, do you? I'll burn you with facts, everytime, vs. your adhominem attacks & "fantasyland" misleading b.s. you try to feed others here & elsewhere online, especially in regards to HOSTS files!
"Nobody touches, my hurricane... (Nobody DARES to even try!)... You try to catch me, but you-just-can't-catch-a-hurricane!" - THE RODS
As to that tune, & what it says & how it pertains to that link above + our discussion on HOSTS files (where I completely BLEW tomhudson AWAY, on HOSTS files)?
See THE RODS' video here ->
http://www.youtube.com/watch?v=apOdWOK5Rh8&feature=related
It explains it all as to what happened at the 1st URL above I posted now here where tomhudson tried to take me on with his pals, and lost badly!
That video & the quotes I used from it, say it all, & FAR better than I can say it myself... apk
metrix007 is pissed about this http://yro.slashdot.org/comments.pl?sid=1888084&cid=34462614 [slashdot.org] where he blundered on hosts files against the person he's trolling now. metrix007 got played: He played himself.
"Nah, you just burn yourself with bullshit. You have no facts. They're all lies. And you're full of it." - by Anonymous Coward on Monday December 13, @01:21PM (#34536360)
Funny, see my subject-line above... LMAO!
APK
P.S.=> As for TomPudson running like he did before vs. my points on HOSTS files he could not disprove? See my last post:
http://tech.slashdot.org/comments.pl?sid=1905218&cid=34528770
The URL's are there and so is he, lol, RUNNING! apk
this does have the benefit being one of the best legal protection for free-speech in the world [i.e. in the US].
Q: what do you get if you register free-speech.us at a DNS provider?
A: a free-speech zone.