VeriSign: Major internet security update by 2011

NEWS

VeriSign has said a significant outstanding internet security vulnerability will be closed by 2011, after delays caused by technical aspects of the implementation.

The problem is that DNS, the Domain Name System that translates internet addresses such as website URLs into numerical values, can be seeded with false values and used to misdirect users. VeriSign told ZDNet on Friday that it will put in place DNSSEC, a protocol which will guarantee the origin and integrity of DNS data, for the .com and .net domains by the first quarter of 2011.

"Both .net and .com are very large domains," said Pat Kane, VeriSign vice president of naming services.

Kane added that ".net alone has more than 12 million domain names. Our first priority is to safely and securely implement DNSSEC, as it impacts the Domain Name System, one of the core building blocks of the internet".

VeriSign is currently working with Educause, an association that promotes higher education IT use, and the Department of Commerce (DoC), to deploy DNSSEC within the .edu top level domain (TLD). VeriSign said on Friday that it was progressively increasing the size of TLDs with DNSSEC deployed, to learn from that deployment.

VeriSign has been working with Icann, the internet naming co-ordinator, to bring security to DNS since Icann's inception in 1998. Kane said that the stumbling blocks for signing the DNSSEC root had been "mainly technical".

"Because of the large size of .com and .net, it would not have been practical to deploy DNSSEC with earlier versions of the DNSSEC protocol: signing would have increased the size of these DNS zones dramatically, making them unwieldy," said Kane. "VeriSign utilises a DNSSEC extension known as NSEC3, which is documented in RFC 5155 with a VeriSign Labs engineer as a co-author."

Kane said that the DNS vulnerability publicised by researcher Dan Kaminsky in August 2008 had speeded recognition that .com and .net needed to be signed.

"The vulnerability publicised by Kaminsky had been known earlier; Kaminsky showed how easy it was to exploit," said Kane. "The ease with which DNS 'cache poisoning' attacks could be made was a significant factor in raising awareness for the need for DNS security. When fully and properly implemented, DNSSEC stops cache poisoning and closes a significant attack vector."

Cache poisoning in when an attacker corrupts the cache data in a DNS server, replacing a valid internet address with a rogue address.

Kane said that VeriSign will create and manage the zone-signing key (ZSK) for the root zone, and sign the root zone, for .net and .com. Icann will create, manage and publish the root zone key-signing key (KSK).

Talkback

This leave all the other domain prefix's? ie; .org, .co.uk, .de, .fr, etc and not to mention the recently announced new non English dot domain prefix's now on sale.

Is they any secured options available for them?

CA 19 November, 2009 01:34 Reply

Post your comment

In order to post a comment you need to be registered and logged in

Log in or create your ZDNet UK account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

ZDNet UK Live

nikeshoes998

Oracle signs Solaris deals with HP and Dell: Find the answers in the Community FAQ free shipping wholesale product... http://bit.ly/bcjQtY

mensapparel2010

Oracle signs Solaris deals with HP and Dell: Find the answers in the Community FAQ free shipping wholesale product... http://bit.ly/9GWZRh

womensapparel20

Oracle signs Solaris deals with HP and Dell: Find the answers in the Community FAQ free shipping wholesale product... http://bit.ly/bPLHL8

lisabarnes001

Oracle signs Solaris deals with HP and Dell: Find the answers in the Community FAQ free shipping wholesale product... http://bit.ly/bVw3F2

KC616

Oracle signs Solaris deals with HP and Dell: Find the answers in the Community FAQ free shipping wholesale product... http://bit.ly/cDUyaj

KC616

free shipping wholesale products: Read more »h handbags,NIKE shoes, jewelry, watches, and jacket and so on. We gua... http://bit.ly/cWcW1e

SpyScroll

Cyberwar defence plan is essential, says former CIA head: Michael Hayden, former head of the CIA and the National ... http://bit.ly/beLpKQ

Droid_News

SAP leads businesses into augmented reality http://bit.ly/9eMWYp | #Droid #Android

wholesalegurru

free shipping wholesale products: We mainly supply top mirror quality brand name products, such as wholesale handb... http://bit.ly/cWcW1e

CNSInstructor

Cyberwar defence plan is essential, says former CIA head: Michael Hayden, former head of the CIA and the N... http://bit.ly/9sn6ax #pdln4nx

AllAboutFashion

Oracle signs Solaris deals with HP and Dell http://bit.ly/9KVeqD

Droid_Phone

SAP leads businesses into augmented reality http://bit.ly/9eMWYp | #Droid #Android

AllAboutFashion

free shipping wholesale products http://bit.ly/c7cpX4

Droid_Phone

TalkTalk to sell mobile services via Vodafone deal http://bit.ly/bLVfxI | #Droid #Android

wholesalegurru

Oracle signs Solaris deals with HP and Dell: Find the answers in the Community FAQ free shipping wholesale product... http://bit.ly/cDUyaj

wholesalegurru

free shipping wholesale products: Read more »h handbags,NIKE shoes, jewelry, watches, and jacket and so on. We gua... http://bit.ly/cWcW1e

felixsprisci

DoJ joins whistleblower in Oracle fraud suit http://bit.ly/bMT3SJ

actatrudy

Update: free shipping wholesale products - ZDNet UK (... http://www.actahandbags.com/trends/free-shipping-wholesale-products-zdnet-uk-blog/

lisabarnes001

free shipping wholesale products: Read more »h handbags,NIKE shoes, jewelry, watches, and jacket and so on. We gua... http://bit.ly/bRvFgG

mensapparel2010

free shipping wholesale products: Read more »h handbags,NIKE shoes, jewelry, watches, and jacket and so on. We gua... http://bit.ly/9CXYG9

Featured white papers

The need for email archiving

Without an effective system for archiving emails, organisations can find themselves unable to recover vital business records, leaving them open..

Download now

Dell Data Storage Summary

This study was conducted in the United States amoung IT decision makers with involvement in data centre purchases at companies..

Download now

Datasheet: Infrastructure as a Service

'Infrastructure as a Service' gives enterprises the flexibility to subscribe to the compute power and storage they require today with 'pay..

Download now