Slashdot Mirror


Generic TLDs Threaten Name Collisions and Information Leakage

CowboyRobot writes "As the Internet Corporation for Assigned Names and Numbers (ICANN) continues its march toward the eventual approval of hundreds, if not more than 1,000, generic top-level domains (gTLDs), security experts warn that some of the proposed names could weaken network security at many companies. Two major issues could cause problems for companies: If domain names that are frequently used on a company's internal network — such as .corp, .mail, and .exchange — become accepted gTLDs, then organizations could inadvertently expose data and server access to the Internet. In addition, would-be attackers could easily pick up certificates for domains that are not yet assigned and cache them for use in man-in-the-middle attacks when the specific gTLD is deployed." Another way to look at it: why were they using invalid domains in the first place?

3 of 115 comments (clear)

  1. That's why I have been giving my internal by ls671 · · Score: 5, Insightful

    That's why I have been giving my internal domains silly like .zyxprivnet for at least 15 years...

    It would be nice to reserve some domain names for internal use although, just like internal ip addresses.

    --
    Everything I write is lies, read between the lines.
    1. Re:That's why I have been giving my internal by Anonymous Coward · · Score: 5, Insightful

      oh, like .local ? >_>

    2. Re:That's why I have been giving my internal by TheLink · · Score: 5, Insightful

      I actually tried to get a TLD reserved for "RFC1918" style use about 12+ years ago: http://tools.ietf.org/html/draft-yeoh-tldhere-01

      I also tried the ICANN but they weren't interested either. And when they approved stuff like .biz, .info. I got the impression they weren't really interested in improving the Internet from a technical aspect but more interested in $$$$. Did the creation of .biz etc really help the Internet that much?

      Maybe others may have more success trying it now?

      --