DNS

Sponsored
by

DNS / Most Viewed

ICANN, Ukraine and Leveraging Internet Identifiers

Ukraine's representative to ICANN's Governmental Advisory Committee (GAC) has sent a letter to the Internet Corporation for Assigned Names and Numbers (ICANN) to remove Russian-administered top level domains (.RU, .SU and .рф) from the DNS root zone. In a separate letter, Ukraine's representative also asked RIPE NCC to withdraw the right to use all IPv4 and IPv6 addresses by all Russian members of the regional IP registry for the European region. more

Why More Registries Should Be Talking About DNS Security

I've been incredibly lucky in my time at Neustar to lead both the exceptional Registry and Security teams. While these divisions handle their own unique product and service offerings, it's clear that they have some obvious crossovers in their risks, opportunities and challenges. Having been closely involved in the strategy of both these teams, it strikes me that there is more we as Registry Operators and service providers can and should be doing to align the world of cybersecurity with that of domain names. more

The Introduction of New Domain Name Services: “Due Process” and Innovation

For those interested in encouraging innovation in the domain name space -- which presumably includes the ICANN community currently convening in Dakar -- the recent episode in which VeriSign proposed, and then quickly withdrew, a bundle of new services (the VeriSign anti-abuse domain use policy) raises important issues that will be revisited as new gTLDs are introduced. Some of those issues are referenced in a recent blog post by Milton Mueller, but his emphasis on "due process" suggests a regulatory framework that is not friendly to innovation. more

Trusted Notifier Arrangements Require Trust: Why Unpacking Misunderstandings Around Trusted Notifiers Is Important for Dealing With DNS-related Abuse

Domain Name System (DNS) Operators (Registries and Registrars) receive notices asking them to take action on a wide range of alleged technical and content-related abuses. However, there is a fundamental question of when it is appropriate to act at the DNS level and the evaluation of whether the alleged abuse meets a sufficient threshold for action at the DNS level. Additionally, given the volume of abuses occurring on the internet, existing resources, mechanisms, and protocols available in-house to Operators are in many cases insufficient to address abuses in a timely fashion. more

ICANN Releases Fourth Version of the New gTLD Draft Applicant Guidebook

A fourth draft of ICANN's New gTLD Draft Applicant Guidebook has been released. In addition to the Applicant Guidebook, ICANN has also published summaries and analysis of the public comment period. The latest version includes... more

Senate and House Hearings on New Top Level Domains Not Likely to Delay Launch

Yesterday, the US Senate Committee on Commerce, Science and Transportation held hearings on ICANN's expansion of top level domains. Next week the House Energy and Commerce committee will also conduct their hearings on this same topic. more

US House Committee Announces Oversight Hearing on DNS and Search Engine Blocking

House Committee on Oversight and Government Reform Chairman Darrell Issa today announced that the Full Committee will hold a hearing on January 18 to examine the potential impact of Domain Name Service (DNS) and search engine blocking on security, jobs and the Internet community. The Committee will hear testimony from cybersecurity experts and others from the technology community. more

U.S. Government Announces Intent to Transition DNS Functions to Global Community

U.S. Commerce Department's National Telecommunications and Information Administration (NTIA) took a historic step today announcing "its intent to transition key Internet domain name functions to the global multistakeholder community." more

Supporting New DNS RR Types with dnsextlang, Part II

Previous article introduced my DNS extension language, intended to make it easier to add new DNS record types to DNS software. It described a new perl module Net::DNS::Extlang that uses the extension language to automatically create perl code to handle new RRTYPEs. Today we look at my second project, intended to let people create DNS records and zone files with new RRTYPEs. more

An ITU Cut and Paste Job for New TLDs Could Cost $150k

It was with great interest that I read a recent announcement about a plan by the International Telecommunications Union (ITU) to publish template answers on a wiki for the 22 questions relating to registry technical operations contained within ICANN's new Top-Level Domain Applicant Guidebook. As someone who has spent the best part of six years following the development of the program (witnessing first-hand each evolution of the Applicant Guidebook) my first thought was one of bemusement... more

Can We Really Blame DNSSEC for Larger-Volume DDoS attacks?

In its security bulletin, Akamai's Security Intelligence Response Team (SIRT) reported on abuse of DNS Security Extensions (DNSSEC) when mounting a volumetric reflection-amplification attack. This is not news, but I'll use this opportunity to talk a bit about whether there is a trade-off between the increased security provided by DNSSEC and increased size of DNS responses that can be leveraged by the attackers. more

Wither WHOIS!: A New Look At An Old System

No, that title is not a typo. The WHOIS service and the underlying protocol are a relic of another Internet age and need to be replaced. At the recent ICANN 43 conference in Costa Rica, WHOIS was on just about every meeting agenda because of two reasons. First, the Security and Stability Advisory Committee put out SAC 051 which called for a replacement WHOIS protocol and at ICANN 43, there was a panel discussion on such a replacement. The second reason was the draft report from the WHOIS Policy Review Team. more

IANA Contract Extended by One Year, Announces Department of Commerce

United States Department of Commerce on Monday announced the official date for privatization of the DNS to be September 30, 2016 -- formerly set to expire on September 30, 2015. more

ICANN, NTIA, Verisign and ANA Weighing In on ‘Name Collisions’ and the Readiness of New gTLD Program

Gregory S. Shatan of Reed Smith writes: "Last week, ICANN (the organization that oversees the domain name system of the Internet) was busy with nothing less than the security and stability of the Internet. At ICANN's recent meeting in Durban, those of us attending heard a drumbeat of studies, presentations and concerns regarding "name collisions": the conflicts that will arise when new gTLDs go live and conflict with existing top-level extensions in private networks..." more

DNSSEC Activities at ICANN 57 in Hyderabad on 4-7 November 2016

Friday marks the beginning of the ICANN 57 meeting in Hyderabad, India. As per usual there will be a range of activities related to DNSSEC or DANE. Two of the sessions will be streamed live and will be recorded for later viewing. Here is what is happening. All times below are India Standard Time (IST), which is UTC+05:30. Please do join us for a great set of sessions about how we can work together to make the DNS more secure and trusted! more