Now on ScienceBlogs: The Galaxy's Biggest Valentine

ScienceBlogs Book Club: Inside the Outbreaks

Greg Laden's Blog

Evolution, Life Sciences, Science Education, Human Evolution, and Stuff

Hornbill170.jpg Looking for stuff about birds?

Darwing_Face.jpg Learn more about Charles Darwin and his work.

Lion_mane170.jpg Lean more about lions

Congo_sidebar.jpg An archaeological expedition to the Congo


The Skeptical Search Engine


Nature Blog Network
Climate Defense Fund


The contents of Greg Laden's Blog are copyrighted by Greg Laden.

Recent Comments

Search

Profile


Click on "About" for the big picture, and "Archives" for the details.


Recent Posts

Blogroll

If you don't see yourself on my blogroll, just drop me a line and let me know. I'll add you.*
*Assuming that I'm on your blogroll, of course!

Archives

« Al Franken's Fifty State Strategy: The Movie | Main | Linux One Liners »

More on DNS Bug

Category: Technology
Posted on: August 7, 2008 10:20 AM, by Greg Laden

Remember the earlier discussion of the DNS bug? If the internet is the post office, the DNS is the collection of all of the addresses on all of the envelopes traveling around the system. It is secure, inherently. But caching is used as part of the system to make it more efficient, and the caches are NOT secure. So, this would be like an evil genius making the local postal deliver person always see the Evil Genius Address whenever s/he is about to deliver a check, and NEVER seeing it when s/he is about to deliver a bill. So the checks all go to the evil genius and the bills never do. Or something along those lines.

Dan Kaminsky, the guy who figured this out, now claims that things are worse than thought.

Others are saying it is hype.

So now we have this:

Ken Silva, chief technology officer at Verisign, said: "We have anticipated these flaws in DNS for many years and we have basically engineered around them."

He believed there had been "some hype" around how the DNS flaw will affect consumers. He added that while it was an interesting way to exploit DNS on weak servers, there were other ways to misdirect people that remained.

Mr Silva said he was concerned that people would read too much into the doom and gloom headlines that have surrounded the discovery of the DNS flaw.

"It's been overplayed in a sense. I think it has served to confuse the consumer into believing there is somehow now a way to misdirect them to a wrong site.

VS comments by Dan Kaminsky, who


... said fixes for the flaw in the net's Domain Name System (DNS) had focused on web browsers but it could be abused by hackers in many other ways.

"Every network is at risk," he said. "That's what this flaw has shown."

The DNS acts as the internet's address books and helps computers translate the website names people prefer (such as bbc.co.uk) into the numbers computers use (212.58.224.131).

Mr Kaminsky discovered a way for malicious hackers to hijack DNS and re-direct people to fake pages even if they typed in the correct address for a website.

In his talk Mr Kaminsky detailed 15 other ways for the flaw to be exploited.

Via the flaw hi-tech criminals or pranksters could target FTP services, mail servers, spam filters, Telnet and the Secure Socket Layer (SSL) that helps to make web-based transactions more secure.

"There are a ton of different paths that lead to doom," he said.

bbc

Share on Facebook
Share on StumbleUpon
Share on Facebook
Find more posts in: Technology

TrackBacks

TrackBack URL for this entry: http://scienceblogs.com/mt/pings/78361

Comments

1

If people can be redirected by a hacked DNS server, I presume this could be bypassed by simply typing in the IP address for your commonly visited sites or web merchants? It would only work if they have static IPs, but most internet businesses won't be using dynamic IP addresses will they?

Posted by: Alien | August 7, 2008 2:08 PM

2

Also, many users browse via proxy servers, with the https links to ecommerce sites in proxy exceptions list. These should be IP only if used.

Posted by: eddie | August 9, 2008 5:52 AM

Post a Comment

(Email is required for authentication purposes only. On some blogs, comments are moderated for spam, so your comment may not appear immediately.)





ScienceBlogs

Search ScienceBlogs:

Go to:

Advertisement
Follow ScienceBlogs on Twitter

© 2006-2011 ScienceBlogs LLC. ScienceBlogs is a registered trademark of ScienceBlogs LLC. All rights reserved.