jim_duffy
Managing Editor

Despite patch by Cisco, Microsoft, others, DNS is not secure, researcher says

Analysis
Feb 19, 20092 mins

The Kaminsky Bug, a DNS cache poisoning attack, remains a threat, despite the fact that vendors such as Cisco, Sun and Microsoft joined together to release patches that temporarily fix the flaw. So said Dan Kaminsky at the Black Hat conference, reports Network World. The prominent security researcher told attendees that holes in DNS make the Internet vulnerable. DNS’s problems are limiting other important, dependent security technologies as well.

He advocates DNS Security Extensions, which attempt to prevent spoofing attacks by allowing Web sites to verify their domain names and corresponding IP addresses using digital signatures and public-key encryption.

The article says:

“One roadblock to DNSSEC adoption is that it isn’t easy to implement, Kaminsky admits, and calls for coordination by many parties. DNSSEC requires domain name registrars, domain name registries, ISPs and users to upgrade their software.”

More from Cisco Subnet: * Vyatta beats out Cisco, Juniper for New Mexico winDetails of “Project California” revealed* Largest coordinated ATM Rip-off ever nets $9+ million in 30 minutesCisco adds new online questions module to CCIE lab examCisco in the home: Anonymous or poised for domination?OSPF puzzle: Analyzing OSPF metrics, human styleGetting Started with the CCNA WirelessGo to Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, training/book giveaways, and more. 

*

*