Slashdot Mirror


ICANN Warns of 'Ongoing and Significant' Attacks Against Internet's DNS Infrastructure (techcrunch.com)

The internet's address book keeper has warned of an "ongoing and significant risk" to key parts of the domain name system infrastructure, following months of increased attacks. From a report: The Internet Corporation for Assigned Names and Numbers, or ICANN, issued the notice late Friday, saying DNS, which converts numerical internet addresses to domain names, has been the victim of "multifaceted attacks utilizing different methodologies." It follows similar warnings from security companies and the federal government in the wake of attacks believe to be orchestrated by nation state hackers.

[...] ICANN's chief technology officer David Conrad told the AFP news agency that the hackers are "going after the Internet infrastructure itself." The internet organization's solution is calling on domain owners to deploy DNSSEC, a more secure version of DNS that's more difficult to manipulate. DNSSEC cryptographically signs data to make it more difficult -- though not impossible -- to spoof.

94 comments

  1. Convert which way? by shabble · · Score: 5, Insightful

    DNS, which converts numerical internet addresses to domain names

    I thought it was more conventionally used the other way...

    1. Re: Convert which way? by Anonymous Coward · · Score: 0

      slashdot is going to hell, we only get political rants and then the occasional tech article, like this one, is riddled with mistakes. Embrace it and just troll

    2. Re:Convert which way? by Anonymous Coward · · Score: 1

      Right. Converting an IP address to a domain name is typically considered "Reverse" DNS.

    3. Re:Convert which way? by Anonymous Coward · · Score: 0

      Technically DNS only takes domain names and spits out resource records. Reverse DNS resolves a domain name which contains an IP address into a PTR record.

    4. Re:Convert which way? by Anonymous Coward · · Score: 0

      On the user end, they convert domain names to internet addresses, but on the other end, they assign a domain name to each address which could be considered converting them.

    5. Re:Convert which way? by DigiShaman · · Score: 1

      Well technically a, PTR (reverse DNS) does exist.

      --
      Life is not for the lazy.
    6. Re: Convert which way? by Anonymous Coward · · Score: 0

      All of which are DNS.

    7. Re:Convert which way? by Anonymous Coward · · Score: 0

      Just looking up some .in-addr.arpa addresses.

  2. Pah! by devlp0 · · Score: 3, Funny

    You should see my hosts file!

    --
    >/dev/null 2>&1
  3. handshake.org is the solution by Anonymous Coward · · Score: 0

    check it out.

  4. Hosts files are bad! by Anonymous Coward · · Score: 0

    They do nothing useful!

  5. This reads like propaganda by Anonymous Coward · · Score: 0

    To try and force the internet to use DNSSEC

    1. Re: This reads like propaganda by Anonymous Coward · · Score: 0

      Idiot.

  6. Index Article by Anonymous Coward · · Score: 0

    Index Article from ICANN
    https://www.icann.org/news/announcement-2019-02-22-en ...in the context of increasing reports of malicious activity targeting the DNS infrastructure, ICANN is calling for full deployment of the Domain Name System Security Extensions (DNSSEC) across all unsecured domain names. The organization also reaffirms its commitment to engage in collaborative efforts to ensure the security, stability and resiliency of the Internet’s global identifier systems.

  7. Sad to say by Anonymous Coward · · Score: 0

    But if you really want to read an informative thread about the issue, hop on over to Hacker News https://news.ycombinator.com/item?id=19239940

  8. Bet half the attacks are coming from Djibouti. by brucekeller · · Score: 2

    That place is always up to shenanigans.

    1. Re:Bet half the attacks are coming from Djibouti. by Anonymous Coward · · Score: 0

      How I imagine parent expected this would play out:

      "Huh huh. He said from Dji boouti."
      "Yeah yeah. My dji booouti."
      *Pppbbbbbbtttttt*

  9. Risk or attack? by Anonymous Coward · · Score: 0

    That's not the same thing and I wasn't expecting to read a sensionalist headline here on /.

  10. DNSSEC = vector for epic DDOS amplification by WaffleMonster · · Score: 5, Interesting

    This advice is ridiculous, dangerous and irresponsible. DRC should know better.

    Global deployment of DNSSEC without first addressing underlying transport issues (DNS over UDP without DNS cookies (RFC7873)) is guaranteed to have disastrous impacts on the availability of DNS itself and the Internet generally.

    1. Re:DNSSEC = vector for epic DDOS amplification by Anonymous Coward · · Score: 0

      Thought I'd heard something like this and that it was the reason it hasn't been deployed yet.

      What the fuck are people thinking? The "deploy now, secure later" method doesn't work.

    2. Re: DNSSEC = vector for epic DDOS amplification by Anonymous Coward · · Score: 0

      Plenty have deployed.

    3. Re:DNSSEC = vector for epic DDOS amplification by Anonymous Coward · · Score: 0

      Google and Microsoft dont even have DNSSEC deployed. -- DNSSEC Its poorly documented, and appears to be quite a pita to deploy.

      *But it should become a mandatory check*

      DNS Cookies looks like a hack with no regard for anonominity. Client-Server **IP** based keys

    4. Re:DNSSEC = vector for epic DDOS amplification by Anonymous Coward · · Score: 0

      Beat me to it. This smells like a mix of inside job and push for dnssec. I do not want MORE things requring trust of companies and three letter organizations, thanks. If providers can't control their peers doing bad things the internet as a whole needs to take a bit more stance against them. Back in the day we had things like UDP, Usenet Death Penalty.

      Regarding the attack we've certainly seen some strange things lately. Servers returning NXD only to become authorative a few seconds later. We were able to trace some of them down to receiving bogus replies from asian networks.

    5. Re: DNSSEC = vector for epic DDOS amplification by nullchar · · Score: 1

      The primary article on Techcrunch said

      DNSSEC adoption is currently at about 20 percent.

      Except that is totally wrong:
      Only 4% of domains are signed across all TLDs: http://rick.eng.br/dnssecstat/
      And for .com, it's less than 1%

      1M signed (https://scoreboard.verisignlabs.com/) 140M .com (http://research.domaintools.com/statistics/tld-counts/) = 0.7%

  11. Re: You should see mine & how it's built... ap by Anonymous Coward · · Score: 0

    shut the fuck up, retard

  12. MacOS version now available, too... apk by Anonymous Coward · · Score: 0

    See subject: APK Hosts File Engine 1.0++ 64-bit for MacOS h t t p : / / a p k . i t - m a t e . c o . u k / A P K H o s t s F i l e E n g i n e F o r M a c O S . z i p

    Yields more security/speed/reliability/anonymity vs. any 1 solution (99% of threats use hostnames vs. IP address most firewalls use) more efficiently/FASTER + NATIVELY 4 less!

    Vs. "Bolt on 'MoAr' illogic-logic" slowing you hosts speed u up 2 ways: Adblocks + Hardcode fav. sites u spend most time @ vs. competition loaded w/ security bugs (DNS/AntiVir) + overheads slowing u (messagepass 'souled-out' to advertisers easily detected & blocked addons + firewall filtering drivers) & their complexity leads to exploitation!

    * ONLY 1 of its kind in GUI 4 MacOS!

    (Better vs. Windows model in speed/efficiency)

    APK

    P.S.=> Protects against ALL known & unknown vulnerabilities. Now supports port filters in hosts. My work is world-class & China copied it because they can't do better. I am God's gift to Slashdot... apk

  13. How to get the best hosts file on MacOS... apk by Anonymous Coward · · Score: 0

    See subject: APK Hosts File Engine 1.0++ 64-bit for MacOS h t t p : / / a p k . i t - m a t e . c o . u k / A P K H o s t s F i l e E n g i n e F o r M a c O S . z i p

    Yields more security/speed/reliability/anonymity vs. any 1 solution (99% of threats use hostnames vs. IP address most firewalls use) more efficiently/FASTER + NATIVELY 4 less!

    Vs. "Bolt on 'MoAr' illogic-logic" slowing you hosts speed u up 2 ways: Adblocks + Hardcode fav. sites u spend most time @ vs. competition loaded w/ security bugs (DNS/AntiVir) + overheads slowing u (messagepass 'souled-out' to advertisers easily detected & blocked addons + firewall filtering drivers) & their complexity leads to exploitation!

    * ONLY 1 of its kind in GUI 4 MacOS!

    (Better vs. Windows model in speed/efficiency)

    APK

    P.S.=> Protects against ALL known & unknown vulnerabilities. Now supports port filters in hosts. My work is world-class & China copied it because they can't do better. I am God's gift to Slashdot... apk

  14. IMPERSONATING me AGAIN? apk by Anonymous Coward · · Score: 0

    MacOS model's not done: Stop IMPERSONATING me lying & proof portfilter err's can't happen in my work https://news.slashdot.org/comm...

    HILARIOUS u ADMIT u have a /. acct & STALK me by UNIDENTIFIABLE ac https://hardware.slashdot.org/... - YOU have ISSUES, lunatic.

    See subject & that's the "best ya got"? It proves You WISH you were ME (as your POOR imitation = the sincerest form of flattery).

    * LASTLY - the ONLY time you start IMPERSONATING me vs. STALKING me by UNIDENTIFIABLE anon posts is WHEN YOU ARE OUT OF "downmodpoints" I can easily NULLIFY by REPOSTING my posts RUNNING YOU DRY of them after you ABUSE them - I must've already, lol!

    APK

    P.S.=> I know WHY you do it though (out of "butthurt angst", lol): I've BLOWN YOU AWAY so many times under your MANY alter-ego SOCKPUPPET /. accounts FAKENAMES you're out for "revenge" only to have EGG ON YOUR FACE yet again... apk

    1. Re: IMPERSONATING me AGAIN? apk by Anonymous Coward · · Score: 0

      Have you just gotten off your shift sucking AIDS infested trucker dicks at the Flying J?

  15. Re: How I get the best hosts file on MacOS... apk by Anonymous Coward · · Score: 0

    How do I put in a hosts file entry to make your dumb ass go away?

  16. MacOS version now available, too... apk by Anonymous Coward · · Score: 0

    See subject: APK Hosts File Engine 1.0++ 64-bit for MacOS h t t p : / / a p k . i t - m a t e . c o . u k / A P K H o s t s F i l e E n g i n e F o r M a c O S . z i p

    Yields more security/speed/reliability/anonymity vs. any 1 solution (99% of threats use hostnames vs. IP address most firewalls use) more efficiently/FASTER + NATIVELY 4 less!

    Vs. "Bolt on 'MoAr' illogic-logic" slowing you hosts speed u up 2 ways: Adblocks + Hardcode fav. sites u spend most time @ vs. competition loaded w/ security bugs (DNS/AntiVir) + overheads slowing u (messagepass 'souled-out' to advertisers easily detected & blocked addons + firewall filtering drivers) & their complexity leads to exploitation!

    * ONLY 1 of its kind in GUI 4 MacOS!

    (Better vs. Windows model in speed/efficiency)

    APK

    P.S.=> Protects against ALL known & unknown vulnerabilities. Now supports port filters in hosts. My work is world-class & China copied it because they can't do better. I am God's gift to Slashdot... apk

  17. IMPERSONATING me yet AGAIN? apk by Anonymous Coward · · Score: 0

    MacOS model's not done: Stop IMPERSONATING me lying & proof portfilter err's can't happen in my work https://news.slashdot.org/comm...

    HILARIOUS u ADMIT u have a /. acct & STALK me by UNIDENTIFIABLE ac https://hardware.slashdot.org/... - YOU have ISSUES, lunatic.

    See subject & that's the "best ya got"? It proves You WISH you were ME (as your POOR imitation = the sincerest form of flattery).

    * LASTLY - the ONLY time you start IMPERSONATING me vs. STALKING me by UNIDENTIFIABLE anon posts is WHEN YOU ARE OUT OF "downmodpoints" I can easily NULLIFY by REPOSTING my posts RUNNING YOU DRY of them after you ABUSE them - I must've already, lol!

    APK

    P.S.=> I know WHY you do it though (out of "butthurt angst", lol): I've BLOWN YOU AWAY so many times under your MANY alter-ego SOCKPUPPET /. accounts FAKENAMES you're out for "revenge" only to have EGG ON YOUR FACE yet again... apk

  18. IMPERSONATING me still YET AGAIN? apk by Anonymous Coward · · Score: 0

    MacOS model's not done: Stop IMPERSONATING me lying & proof portfilter err's can't happen in my work https://news.slashdot.org/comm...

    HILARIOUS u ADMIT u have a /. acct & STALK me by UNIDENTIFIABLE ac https://hardware.slashdot.org/... - YOU have ISSUES, lunatic.

    See subject & that's the "best ya got"? It proves You WISH you were ME (as your POOR imitation = the sincerest form of flattery).

    * LASTLY - the ONLY time you start IMPERSONATING me vs. STALKING me by UNIDENTIFIABLE anon posts is WHEN YOU ARE OUT OF "downmodpoints" I can easily NULLIFY by REPOSTING my posts RUNNING YOU DRY of them after you ABUSE them - I must've already, lol!

    APK

    P.S.=> I know WHY you do it though (out of "butthurt angst", lol): I've BLOWN YOU AWAY so many times under your MANY alter-ego SOCKPUPPET /. accounts FAKENAMES you're out for "revenge" only to have EGG ON YOUR FACE yet again... apk

  19. Still IMPERSONATING me JEALOUS "Lil' Jowie"? by Anonymous Coward · · Score: 0

    MacOS model's not done: Stop IMPERSONATING me lying & proof portfilter err's can't happen in my work https://news.slashdot.org/comm...

    HILARIOUS u ADMIT u have a /. acct & STALK me by UNIDENTIFIABLE ac https://hardware.slashdot.org/... - YOU have ISSUES, lunatic.

    See subject & that's the "best ya got"? It proves You WISH you were ME (as your POOR imitation = the sincerest form of flattery).

    * LASTLY - the ONLY time you start IMPERSONATING me vs. STALKING me by UNIDENTIFIABLE anon posts is WHEN YOU ARE OUT OF "downmodpoints" I can easily NULLIFY by REPOSTING my posts RUNNING YOU DRY of them after you ABUSE them - I must've already, lol!

    Instead of WASTING your life STALKING me by UNIDENTIFIABLE anonymous posts OR IMPERSONATING me (since you WISH you were me)? Make a Wheel https://isc.sans.edu/forums/di... as I have that gives users more speed/security/reliability & anonymity NATIVELY doing more for less vs. ANY single 'solution' out there!

    APK

    P.S.=> I know WHY you do it though (out of "butthurt angst", lol): I've BLOWN YOU AWAY so many times under your MANY alter-ego SOCKPUPPET /. accounts FAKENAMES you're out for "revenge" only to have EGG ON YOUR FACE yet again... apk

  20. Have YOU Made a wheel yet? No... apk by Anonymous Coward · · Score: 0

    See subject & https://isc.sans.edu/forums/di... & you can't STALKING me by UNIDENTIFIABLE anonymous WEEZIL posts being the "ne'er-do-well" CLEARLY uneducated & UNSKILLED obsessed LOON you are, lol!

    * YOU WISH YOU WERE ME!

    APK

    P.S.=> But then, you never CAN be since you are of LOW GRADE STOCK (lol)... apk

    1. Re:Have YOU Made a wheel yet? No... apk by Anonymous Coward · · Score: 0

      Nobody wishes they were you. Debilitating mental illness and severe mental retardation are not good things. Seek the professional help you so desperately need.

    2. Re:Have YOU Made a wheel yet? No... apk by Anonymous Coward · · Score: 0

      You wish you were APK. You impersonated APK trying to be him https://tech.slashdot.org/comm... as he said his MacOS model isn't ready yet. Your bs link doesn't work either. Proof enough with your imitation of him being the sincerest form of flattery possible.

  21. Re:Can't happen to hosts file users... apk by Anonymous Coward · · Score: 0

    Good job APK. /. do nothings are jealous of your accomplishment wishing they were capable of it like you but they aren't. That or they are redirect poisoning DNS themselves for ill gotten gain. Your program foils them so they try to minus moderate hide your valuable posts and program. They also try to bury your posts by impersonating you flooding this reply section to no avail either way. They are losers that always lose.

  22. Re:You should see mine & how it's built... apk by Anonymous Coward · · Score: 0

    You unidentifiable anonymous stalkers of APK should read this as you are breaking laws stalking him https://yro.slashdot.org/story...

  23. Thanks & agreed 110%... apk by Anonymous Coward · · Score: 0

    You're probably as "spot-on right" as possible considering how EFFETE/WEAK their impersonating me OR stalking me is, lol!

    * :)

    APK

    P.S.=> They make me laugh @ them (which seeing how useless they are, @ least they're good for that & FAILING vs. me to make ME look GOOD & themselves like the "ne'er-do-well" DO-NOTHINGS they are)... apk

    1. Re:Thanks & agreed 110%... apk by Anonymous Coward · · Score: 0

      Stop having conversations with yourself. It doesn't make you look sane or smart.

  24. Security pros etc. QUOTED on hosts by Anonymous Coward · · Score: 0

    "classic Windows hosts trick to block the Coinhive or Crypto-Loot domains" - https://www.bleepingcomputer.com/news/security/a-new-player-joins-coinhive-on-the-browser-cryptojacking-scene/ - BLEEPING COMPUTER

    ZD NET http://www.zdnet.com/article/how-to-use-a-hosts-file-to-improve-your-internet-experience/ "Hosts files really shine by letting you block ads, spyware sites, malware sites, & tracking sites"

    SANS ("A related approach to the DNS issue is to create a hosts file on each system that sends requests for spyware to some place else" hosts by myself & RAMU right @ START of "malware explosion" mid 2005 on) https://isc.sans.edu/forums/di...

    Aryeh Goretsky/ESET/NOD32: hosts = good security https://it.slashdot.org/comments.pl?sid=7442373&amp.cid=49747129/

    Oliver Day (SYMANTEC/SECURITYFOCUS) http://www.securityfocus.com/columnists/491/

    Spybot S&D uses hosts!

    APK

    P.S.=> Malwarebytes' hpHosts hosts & RECOMMENDS my program forum.hosts-file.net/viewtopic.php?f=5&t=4290

  25. Even CHINA copied me (vs. DNS down/redirected) by Anonymous Coward · · Score: 0

    Who did it 1st: China or me? I did - dates are my proof https://theregister.co.uk/2017... w/ the FACT China rampantly STEALS U.S. Intellectual properties & military secrets!

    * IMITATION truly IS the SINCEREST FORM of FLATTERY!!!

    (... & proves hosts work vs. DNS faults in tracking you via dns request logs (since you avoid it & resolve FASTER locally using hosts) + DNS being downed OR Kaminsky REDIRECT security flaw misdirected poisoned (or vs. DNSChanger))

    US DHS issues DNS redirect is HUGE danger (not w/ hosts vs.) https://threatpost.com/gov-war... & ICANN ISSUES SAME WARNING https://tech.slashdot.org/stor...

    APK

    P.S.=> Folks, It's NOT EASY being "World-Class" like me (lol - 200,000++ users prove it for me) - enjoy the fruits of my labors for FREE + going FASTER/SAFER/MORE RELIABLY online (w/ a bit more anonymity too via my program)... apk

  26. Registered /.ers disagree w/ you #1/5 by Anonymous Coward · · Score: 0

    Your software is just fine - well written, functional... I'm going to continue using the Host File Engine by mmell February 17, 2017

    Your premise that hostfiles are a good way to deal with advertising and malvertising is quite valid - by JazzLad April 20, 2016

    his hosts program is actually pretty good by xenotransplant August 10 2015

    his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources by alexgieg September 25 2015

    I like your host file system by Karmashock September 09 2015

    that APK guy, I use his host file by rogoshen1 Tuesday March 03, 2015

    I personally use a HOSTS file blocker produced from a genius called APK by 110010001000 October 27 2017

    * SEE SUBJECT & TELL US: How does EATING YOUR WORDS taste?

    APK

    P.S.=> You're already VASTLY OUTNUMBERED but many more are coming (you haven't done better)

  27. Registered /.ers disagree w/ you #2/5 by Anonymous Coward · · Score: 0

    Apk has the answer for that - really... kill automatic updates by adding a hosts file entry setting updates.steam.com or whatever to 127.0.0.1. You have to find the right hostname for each software you want to block updates on by raymorris (2726007) on Friday July 06, 2018

    APK your posts on this and the hosts file posts, and more, have never been in error and/or bad advice by BlueStrat (756137) on Wednesday June 21, 2017

    I support APK's stand on the hosts file and can't see why it's not used more than it is. My hosts file is 144247 lines long (4,332 Kb) it & a firewall serves me very well - by Trax3001BBS (2368736)

    ABP is insufficient as a solid hosts file does everything APK reminds us about fast turtle September 17 2013

    You need APK's hosts file - by Teun (17872) on Wednesday August 06, 2014

    APK

    P.S.=> You EATING YOUR WORDS != GOOD NUTRITION... apk

  28. Registered /.ers disagree w/ you #3/5 by Anonymous Coward · · Score: 0

    APK is totally right on this count. Adblock Plus on Firefox mobile is a dog on older, or lower end, phones. A hostfile based adblocker makes for a much better experience in this context. Of course, your phone has to be rooted, which isn't the case with Firefox + adblock." - by chihowa on Saturday May 16, 2015

    APK solution STILL relevant Thud457 June 11 2015

    In a footnote, I would like to note that I find your hosts file admirable - by vel-ex-tech (4337079) on Tuesday November 24, 2015

    APK's monolithic hosts file is looking pretty good at the moment - by Culture20 on Thursday November 17

    you're right about hosts files - by drinkypoo (153816) on Thursday May 26

    APK, I know people give you a lot of shit regarding hosts, but please don't ever stop - by nasredin (958927) on Friday June 12, 2015 @03:34PM

    APK

    P.S.=> Are you ENJOYING the taste of EATING YOUR WORDS yet?... apk

  29. Registered /.ers disagree w/ you #4/5 by Anonymous Coward · · Score: 0

    APK is kinda right... I've given up on JS based adblocking and gone to blackholing in /etc/hosts, just like it was back in the 90s. The computational load has gotten intolerable for any ad-blocking using JS. I've tried his hosts file generating software. It works. - by bmo (77928) on Thursday October 15, 2015

    get around to 'installing' a hosts file list, not sure which one, likely the one from someonewhocares.org. If it works as well as what I used for a while about ten years ago, I'll be happy. And grateful to APK for the lesson and the reminder. - by kermidge (2221646) on Wednesday March 27

    I actually went and downloaded a 16k line hosts file and started using that after seeing that post, you know just for trying it out. some sites load up faster. - by gl4ss (559668) on Thursday November 17

    dammit MS, you proved APK right about something by lgw

    APK

    P.S.=> Your words YOU'RE EATING: You choking on them yet?... apk

  30. Registered /.ers disagree w/ you #5/5 by Anonymous Coward · · Score: 0

    (APK) is still right a hosts file really does work. It even blocked a some of the video ads that were inserted into a stream OrangeTide February 10 2016

    the Host File Engine performs exactly as promised - by mmell (832646) on Thursday February 16, 2017

    I do use APK's host file on all my systems at home by OrangeTide December 01 2017

    I've never tried to belittle (APK's work), I've flat out said it's good - by BronsCon (927697) on Thursday February 11, 2016 @06:48PM (#51491263)

    * Toss on 100,000++ users worldwide too!

    APK

    P.S.=> You still haven't said how EATING YOUR WORDS tastes? apk

  31. It's impolite to talk w/ your mouth full, lol! by Anonymous Coward · · Score: 0

    It's impolite to talk w/ your mouth FULL of your WORDS YOU HAD TO EAT lol https://tech.slashdot.org/comm...

    * :)

    QUESTION: Tell us, won't you - HOW DID EATING YOUR WORDS TASTE vs. FACTS I extolled vs. your bullshit?

    APK

    P.S.=> That "fine 'TASTY FLAVOR'" perhaps of YOUR FOOT IN YOUR MOUTH ramming them back DOWN your CHICKEN-NECK troll? Washing 'em DOWN w/ the BITTER taste of Your SELF-defeat you ALWAYS experience vs. me & FACTS I use to BLOW YOU AWAY, "ne'er-do-well" DO-NOTHING w/ no real skills on your part, lol... apk

  32. That's not I you replied to: It's an imposter by Anonymous Coward · · Score: 0

    See subject & my PLEASURE making him have his MALNUTRITION DIET of EATING HIS WORDS https://tech.slashdot.org/comm...

    * :)

    APK

    P.S.=> Yes, folks - it's NOT easy being "world-class" (lol, like ME) & it's good to be the "Lord of hosts" (so-to-speak)... apk

    1. Re: That's not I you replied to: It's an imposter by Anonymous Coward · · Score: 0

      I am reliably informed (by your doctor) that you have a micro penis

  33. The NSA is attacking DNS = your tax dollars owning by Anonymous Coward · · Score: 0

    The NSA is attacking the DNS system. Your tax dollars are paying to take down the internet :)

    Good deal huh? Since the USA are a subject of great Britannia again, your taxes can be used at the bakers of Great Britian's will. Great houses owning you :)

    Can't wait until the next bloody revolution hits :) My militia and I will be completely prepared to defend the white race at all costs.

  34. Re:You should see mine & how it's built... apk by Anonymous Coward · · Score: 0

    Serious question, do you have schizophrenia?

  35. BETTER QUESTION for you (you run from) by Anonymous Coward · · Score: 0

    QUESTION: HOW DID EATING YOUR WORDS TASTE vs. FACTS I extolled vs. your bs https://tech.slashdot.org/comm... ?

    REMEMBER: It's impolite to talk w/ your mouth FULL of your WORDS YOU HAD TO EAT lol!

    * :)

    APK

    P.S.=> That "fine 'TASTY FLAVOR'" perhaps of YOUR FOOT IN YOUR MOUTH ramming them back DOWN your CHICKEN-NECK troll? Washing 'em DOWN w/ the BITTER taste of Your SELF-defeat you ALWAYS experience vs. me & FACTS I use to BLOW YOU AWAY, "ne'er-do-well" DO-NOTHING w/ no real skills on your part, lol... apk

    1. Re: BETTER QUESTION for you (you run from) by Anonymous Coward · · Score: 0

      Nobody (including you) has any idea what you are babbling about. We all devoutly wish you would take your ADHD medicine too.

  36. Can't happen to hosts file users... apk by Anonymous Coward · · Score: 0

    See subject: Via APK Hosts File Engine 2.0++ 64-bit for Linux/BSD h t t p : / / a p k . i t - m a t e . c o . u k / A P K H o s t s F i l e E n g i n e F o r L i n u x . z i p

    Yields more security/speed/reliability/anonymity vs. any 1 solution (99% of threats use hostnames vs. IP address most firewalls use) more efficiently/FASTER+NATIVELY 4 less...

    Vs. "Bolt on 'MoAr' illogic-logic" slowing u hosts speed u up 2 ways: Adblocks + Hardcode fav. sites u spend most time @ vs. competition w/ security bugs (DNS/AntiVir) + overheads slowing u (messagepass 'souled-out' to advertisers easily blocked addons + firewall filter drivers) & their complexity leads to exploit!

    * 1 of a kind in GUI 4 Linux!

    (Especially 4 favs hardcoded @ top of hosts resolving faster (which my prog does))

    APK

    P.S.=> Protects vs. scripts/trackers (kernelmode fast vs. usermode slow NoScript vs. 3rd party script)/ads/DNS request tracking + redirect poisoned or DNS down/botnets/malware download/malcript/email malpayload

  37. Can't happen to hosts file users... apk by Anonymous Coward · · Score: 0

    See subject: Via APK Hosts File Engine 2.0++ 64-bit for Linux/BSD h t t p : / / a p k . i t - m a t e . c o . u k / A P K H o s t s F i l e E n g i n e F o r L i n u x . z i p

    Yields more security/speed/reliability/anonymity vs. any 1 solution (99% of threats use hostnames vs. IP address most firewalls use) more efficiently/FASTER+NATIVELY 4 less...

    Vs. "Bolt on 'MoAr' illogic-logic" slowing u hosts speed u up 2 ways: Adblocks + Hardcode fav. sites u spend most time @ vs. competition w/ security bugs (DNS/AntiVir) + overheads slowing u (messagepass 'souled-out' to advertisers easily blocked addons + firewall filter drivers) & their complexity leads to exploit!

    * 1 of a kind in GUI 4 Linux!

    (Especially 4 favs hardcoded @ top of hosts resolving faster (which my prog does))

    APK

    P.S.=> Protects vs. scripts/trackers (kernelmode fast vs. usermode slow NoScript vs. 3rd party script)/ads/DNS request tracking + redirect poisoned or DNS down/botnets/malware download/malcript/email malpayload!

  38. Can't happen to hosts file users... apk by Anonymous Coward · · Score: 0

    See subject: Via APK Hosts File Engine 2.0++ 64-bit for Linux/BSD h t t p : / / a p k . i t - m a t e . c o . u k / A P K H o s t s F i l e E n g i n e F o r L i n u x . z i p

    Yields more security/speed/reliability/anonymity vs. any 1 solution (99% of threats use hostnames vs. IP address most firewalls use) more efficiently/FASTER+NATIVELY 4 less...

    Vs. "Bolt on 'MoAr' illogic-logic" slowing u hosts speed u up 2 ways: Adblocks + Hardcode fav. sites u spend most time @ vs. competition w/ security bugs (DNS/AntiVir) + overheads slowing u (messagepass 'souled-out' to advertisers easily blocked addons + firewall filter drivers) & their complexity leads to exploit!

    * 1 of a kind in GUI 4 Linux!

    (Especially 4 favs hardcoded @ top of hosts resolving faster (which my prog does))

    APK

    P.S.=> Protects vs. scripts/trackers (kernelmode fast vs. usermode slow NoScript vs. 3rd party script)/ads/DNS request tracking + redirect poisoned or DNS down/botnets/malware download/malcript/email malpayload.

  39. You should see mine & how it's built... apk by Anonymous Coward · · Score: 0

    You should see mine & how it's built via https://tech.slashdot.org/comm... multiplatform @ 5,077,520++ known BAD sites/script sources etc. + 100 of my FAVORITE SITES I spend most time @ (avoiding DNS totally & it's requestlog tracking OR BEING REDIRECT POISONED as this article alludes to (or being downed)).

    * :)

    APK

    P.S.=> Glad to meet YET ANOTHER happy hosts file user on /. (you're 1 of 200++ I'm aware of over time here since 2006) ... apk

  40. Price of your MALNUTRITION, lol... apk by Anonymous Coward · · Score: 0

    The price of your MALNUTRITION & bad DIET EATING YOUR WORDS = your weak brain https://tech.slashdot.org/comm... & YOU FAILING vs. FACTS I listed there.

    * YOU LOSE!

    APK

    P.S.=> It's all USELESS dildos like YOU can manage vs. me, lol... apk

  41. Any doctor will tell you YOUR problem (lol) by Anonymous Coward · · Score: 0

    Any doctor will tell you YOUR problem: YOU EATING YOUR WORDS vs. me = bad nutrition https://tech.slashdot.org/comm... & will lead to your starvation (+ death hopefully, lmao) from your "fine diet" (lol, not).

    * You're DYING AS IS vs. me... & WHY won't you answer this question?

    QUESTION: What do your WORDS you are EATING taste like? Your FOOT in your MOUTH ramming them back down your CHICKEN-NECK?? Washed down w/ the BITTER TASTE of SELF-defeat vs. me (everytime, lol)???

    APK

    P.S.=> Such "accomplishment" on YOUR part (not) being a TROLL that STALKS me by UNIDENTIFIABLE anonymous posts like the LOSER do-NOTHING "ne'er-do-well" ZERO you prove yourself to be... apk

  42. Can't happen to hosts file users... apk by Anonymous Coward · · Score: 0

    See subject: Via APK Hosts File Engine 2.0++ 64-bit for Linux/BSD h t t p : / / a p k . i t - m a t e . c o . u k / A P K H o s t s F i l e E n g i n e F o r L i n u x . z i p

    Yields more security/speed/reliability/anonymity vs. any 1 solution (99% of threats use hostnames vs. IP address most firewalls use) more efficiently/FASTER+NATIVELY 4 less...

    Vs. "Bolt on 'MoAr' illogic-logic" slowing u hosts speed u up 2 ways: Adblocks + Hardcode fav. sites u spend most time @ vs. competition w/ security bugs (DNS/AntiVir) + overheads slowing u (messagepass 'souled-out' to advertisers easily blocked addons + firewall filter drivers) & their complexity leads to exploit!

    * 1 of a kind in GUI 4 Linux!

    (Especially 4 favs hardcoded @ top of hosts resolving faster (which my prog does))

    APK

    P.S.=> Protects vs. scripts/trackers (kernelmode fast vs. usermode slow NoScript vs. 3rd party script)/ads/DNS request tracking + redirect poisoned or DNS down/botnets/malware download/malcript/email malpayloads

  43. You WISH you were me, lol... apk by Anonymous Coward · · Score: 0

    See subject: You know - using hosts files avoiding downed OR redirect poisoned DNS + resolving FASTER vs. DNS via hosts cached in local system RAM also avoiding DNS requestlog tracking!

    * :)

    (THERE: Those FACTS ought to do their USUAL & shut YOU up as you show manners & EAT YOUR WORDS, lol...)

    APK

    P.S.=> It's NOT EASY being "world-class" you know (like me) & even CHINA copied me on hardcoded hosts fav sites that proof you vs. this, doing it LONG after I did https://theregister.co.uk/2017... (imitation IS the sincerest form of FLATTERY) proving what I do is 'worldclass scale' + EFFECTIVE vs. DNS shortcomings... apk

  44. Re:You should see mine & how it's built... apk by Anonymous Coward · · Score: 0

    What are you going to do about APK you giant gay baby? Threaten to sue someone because you are gay and act like a fucking baby?

  45. What a cesspool of a comment section by Anonymous Coward · · Score: 0

    Why do I even come here anymore?

  46. Internet ... 3.0? by Anonymous Coward · · Score: 0

    So does this make it time for Internet 3.0? Or was that what IPV6 was about? So a re-invented reinvention refreshed reboot might be 4.0 or 4.1? Maybe "5" to go with the BS of "5G"...?
    scribbletext: outlaws

    1. Re:Internet ... 3.0? by Narcocide · · Score: 1

      Yea, too bad ipv6 is so insecure that you could march a singing army through it unnoticed.

  47. Well MrWaffle... by Anonymous Coward · · Score: 0

    As FF would say:

    Now is the time to migrate away from legacy infrastructure like ICANN and begin using alternative distributed means. Push all your name resolution into Tor/I2P/etc, and use something like namecoin as the authoritative domain service. Anyone can audit it, mitm would be much harder, and the frontend can still appear as DNS without UDP cookies thanks to it run over other transport layers internally. Getting initial seeds in some of these countries could be a problem, but if they are already worried about dns hijacking that will be the least of their worries.

    ICANN has been a plague on the internet for 3 decades now, at an accelerating pace since the addition of new tlds. Let's finally do away with them once and for all.

  48. The 3 letters by Anonymous Coward · · Score: 0
    1. Re:The 3 letters by Anonymous Coward · · Score: 0

      FUQ? It's what you deserve for trolling APK and his valid cure for this problem. Obviously you're a malware creator or advertiser whose ads he stops from infecting, slowing and tracking us.

  49. Internet 3 by Anonymous Coward · · Score: 0

    Those working on Internet 3 are eliminating DNS. At least in it's current form. Any new version will be a heavily encrypted P2P version and may even include a blockchain model to make sure government and other corporations can't de-list a site.

  50. Hahahaha Thor SCHUCK got BLOWN away by Anonymous Coward · · Score: 0

    I never had to sue Thor SCHMUCK - CA rescinded their FALSE POSITIVE err, sold off their shitty av & I said I'd speak to an attorney & I did who advised I go thru their removal process & I won.

    * I don't even have to TRY to WIN - dorks taking potshots via FALSE ACCUSATIONS always LOSE to me - everytime, lol!

    FACT: Fatboy DEFEATED himself for me, RoTfLmAo!

    APK

    P.S.=> LASTLY - Is that YOU SCHMUCK? Sounds it - see the REASON for your "butthurt" above, FATBOY, lol... apk

    1. Re:Hahahaha Thor SCHUCK got BLOWN away by Anonymous Coward · · Score: 0

      You still threatened to sue, you still made a giant ass of your self, and it is recorded for everyone to see with real actual evidence of your acting like a giant fucking gay baby. So in the end you look like a butthurt loser who defeated himself. I guess you really do project your failures onto everyone but then your life is all about the fail.

    2. Re:Hahahaha Thor SCHUCK got BLOWN away by Anonymous Coward · · Score: 0

      Thor Schrock made a fool of himself in making a false accusation against APK.

  51. Hosts efficacy recently vs. threats by Anonymous Coward · · Score: 0
  52. Re: Can't happen to hosts file users... apk by Anonymous Coward · · Score: 0

    you know, you *could* make a RSS feed.
    many torrent programs allow to subscribe to a feed from which they pull data that is needed to download a torrent.
    so if you make your famous hosts file and seed it via a torrent and anounce this via rss ... viola or more correctly voila, you got instant update capabilities without forcing user to download and execute a *exe file.
    ofc you would have to guard the rss feed generator with your life ^_^

  53. Re: Can't happen to hosts file users... apk by Anonymous Coward · · Score: 0

    also if a magnet hash could be predicted ahead of time then one could reference it and the yet not created data it holds in a past magnet hash ... which would solve a big problem ^_^

  54. Nuke Beijing by Anonymous Coward · · Score: 0

    Problem solved.

  55. Using someone elseâ(TM)s hostfile.. by Anonymous Coward · · Score: 0

    While the article is about valid conserns, these comments about using a hosts file that someone else built are most likely scams. It is the same as giving them access to your DNS.

    Only ok ways to do it are to build it yourself or audit every line after every update. Only the completely gullible will use a hosts file from a random guy on the internet.

  56. insecure base by bigtreeman · · Score: 1

    For years I've been saying the base hardware and protocols of the internet are insecure and no amount of security piled on top will save it.
    Rebuild the internet (Internet II) from the hardware up, this time do it right, don't just patch it.

    --
    Go well
    1. Re:insecure base by Obfuscant · · Score: 1

      Rebuild the internet (Internet II) from the hardware up, this time do it right, don't just patch it.

      Internet 2 already exists.

      The most likely result of a rebuilt Internet III with full security is that you won't be able to use it because your access will lessen security. It will be the lesser-used cousin to Internet I, just as Usenet II is the lesser-used cousin of Usenet.

  57. I'll take "Reasons This Won't Work" for 500 please by Narcocide · · Score: 1

    Yawn. You lost me at blockchain. That's not gonna secure shit, but it will waste enough spare computing resources to cure cancer twice.

  58. I won completely you FAT shit... apk by Anonymous Coward · · Score: 0

    See subject: & LMAO @ your FAT disgusting BLOATED imbecile ass stupid no questions asked https://tech.slashdot.org/comm... you "SEO expert" (fucking losers).

    APK

    P.S.=> You NO TALENT fat slob fuck... apk

  59. SSL Certs... by Anonymous Coward · · Score: 0

    Eventually people might actually check the SSL cert to be sure it looks legit!

  60. Note DNSSEC was useless recently by Anonymous Coward · · Score: 0

    The US government shutdown created an open season on website takeovers including DNS hijackings. DNSSEC did exactly zilch to protect against the DNS attacks, which it gets trotted out as a defense for. Don't believe the DNSSEC hype.