DNS Flaw Is A Serious Security Threat

from the patch-those-servers dept

Aaron Massey has a good write-up of the DNS vulnerability that was discovered by security researcher Dan Kaminsky and leaked onto the Internet this week. In a nutshell, a flaw in the design of the DNS protocol (which translates domain names like “techdirt.com” to IP addresses) will make it possible for malicious individuals to invisibly redirect web traffic from legitimate sites to sites of the attacker’s choosing. This is a huge deal because a ton of online applications and services depend on reliable DNS for their security. You might think you’re visiting your bank’s website, but if your DNS server isn’t patched you could really be sending your password to hackers in Russia. Kaminsky tells Wired that fewer than half of the DNS servers on the Internet were patched when the details of the vulnerability leaked, so it’s a real problem. If your ISP hasn’t patched its DNS servers, you can protect yourself by switching to OpenDNS until they do so.

There’s a long-running argument in computer security circles about the best way to release information about security vulnerabilities, with a lot of security professionals favoring immediate, public disclosure of all vulnerabilities. Kaminsky chose not to go the public disclosure route because he felt this bug was too serious to take the risk of its being misused. Kaminsky approached the major DNS vendors in March, and managed to keep the details secret long enough for them to develop fixes for their products. Then, on July 8, Kaminsky announced the simultaneous release of these fixes, while still keeping the details of the vulnerability secret. (The fixes worked in a general enough way that they didn’t give away the details of the vulnerability.) He had been intending to keep it secret until August 8, so that systems administrators would have a full month to prepare their networks. Unfortunately, the information leaked out on Monday, leading to a scramble to patch the remaining DNS servers before exploits start showing up. Given the scope of the patching effort (16 people from various organizations were invited to the secret March summit among DNS vendors), I think it’s pretty impressive that the details didn’t leak out earlier.

Filed Under: , ,

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “DNS Flaw Is A Serious Security Threat”

Subscribe: RSS Leave a comment
fubar says:

yes, but ssl certificates should still offer some protection

If joe hacker poisons your dns so the ip address for your bank is hijacked, I guess SSL certificate issued by verisign that supports your https authentication relies on the dns reporting that it really is your bank’s web site name, so even https is no protection? Eeek. We really are in deep shit.

Killer_Tofu (profile) says:

Main Article

Tim, well written.
I just read this article this morning over at wired:
It is another post by one of the more favored security gurus, Bruce Schneier.

The basic points of the articles you guys have about the attack are similar. Bruce almost makes a couple of good points that I feel are worth mentioning here. As you guys have had a few articles in the past noting, shooting the messanger is a BAD IDEA. People should not be saying anything bad about Kaminsky or harboring him any ill will. He did go about it in a very good manner trying to help people for the good of the cause. I recall at least a few articles (although not the specifics) on Techdirt about people trying to sue those who were trying to help. I am sure that at least one of them had to do with those little secure cards that the company wanted the US to use for national id cards. There was a flaw pointed out in them, and the company threatened to sue the guy if he released the details. With regards to shooting the messanger, I must say that I have not seen anyone make bad comments about Kaminsky yet, but I do not doubt somebody has in their misdirected rage. This is a topic that Bruce mentions in the article, and Techdirt has as well in the past.

Another topic Techdirt has covered many times, that Bruce mentions in his article, is that these systems are naturally insecure. They would be far better if they were designed from the ground up with security in mind. Include security experts from the start of design so that security is innately part of the system. As Bruce so adequetly puts it, “Stop assuming that systems are secure unless demonstrated insecure; start assuming that systems are insecure unless designed securely.” He even mentions voting machines and ID cards right before that. And I know you guys have covered them before many times.

Payday Loans (user link) says:

Normally, with up front terms and far more disclosure than you’d get from any bank, a payday advance loan seems like a safe thing. With all the payday advance loan store robberies, it may not be quite so safe. Payday lenders have been robbed with increasing frequency lately, with armed theft occurring in Washington, Indiana, and now Tennessee. Many stores are considering installing security cameras to deter criminal activity on their premises, which is surely a good investment. Why risk it? It’s always safe to get your payday loan online.

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...