Crypto project to lock down Net security

By Tom Espiner, ZDNet UK
Monday, June 08, 2009 11:06 AM

VeriSign will administer encryption for the Internet's Domain Name System, according to the organization that oversees the fundamental Internet address system.

The Internet Corporation for Assigned Names and Numbers (Icann) said last week that VeriSign will sign the Domain Name System Security Extensions (DNSSEC) at the root zone of the Internet. The announcement suggests a resolution to a longstanding political argument about who would have responsibility for such encryption.

The U.S. Department of Commerce's National Telecommunications and Information Administration and National Institute of Standards and Technology are working with Icann and VeriSign on the initiative.

In an interim arrangement between the participating organizations, VeriSign will manage and have operational responsibility for the zone signing key, while Icann will manage the key-signing-key process. Icann said it will work closely with VeriSign regarding the operational and cryptographic issues involved.

"This is very important for the global community of internet users. We will work closely with all participants on this crucial security initiative," Paul Twomey, president and chief executive of Icann, said in a statement.

The Domain Name System (DNS), the addressing system used to route information packets on the Internet, has long been known to have numerous critical vulnerabilities. Due to the open nature of DNS architecture, DNS cache poisoning, which allows an attacker to falsely redirect a user, has been a recurrent problem since at least 2005. In 2008, security researcher Dan Kaminsky outlined a fundamental DNS flaw which forced multiple vendors to scramble to produce a patch.

The use of DNSSEC, an encrypted protocol, would mitigate many DNS flaws, but has so far been unworkable due to political tensions between DNS-using organizations, who have been unable to agree who would sign the root. This was recognized by the DNSSEC Deployment Working Group in 2005.

"Unfortunately, there are political issues," the working group said at the time. "The root is just another trust anchor but it is a 'special' one."

At the time of writing, Icann had not commented as to how these political issues had been resolved. However, Icann said in a statement that it "recognizes the urgency surrounding the issue of electronically signing the Internet's 'root zone'".


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Release management: Unnecessary evil or Holy Grail?

Tech Management

Though organizations may dread these words, release management is an integral step throughout the software development process. Erica Henson explains more.


Read more »



Buying a projector? Try an LED TV instead

Blog thumbnail

If you're thinking of buying a new projector for your office meeting room, why not consider getting an LED TV instead. LED TVs are similar to LCD TVs except that..... by Lee Lup Yuen

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web