DNS

Sponsored
by

DNS / Recently Commented

An Authenticated Internet

Discussions around DNSSEC are so often focused on the root, the attacks, what DNSSEC does and doesn't do and so on -- and these are all valid and important points. But there is far less attention focused on the opportunities that will surface from an authenticated internet. ...DNSSEC is becoming more of a reality now -- rather than a technical discussion which has been stuck in the mud for 15 years. We can now begin to think about new opportunities to build from a secure DNS, opportunities that build on the certainty that you have arrived at the correct website. Today, you can't be sure. more

The US as Keeper of a ‘Free’ Internet?

The imminent expiration date (September 30) of the joint project agreement between ICANN and the US government, establishing the US as unilateral supervisor over Internet's addressing and Domain Name System (DNS) operations, has rejuvenated the call for an internationalization of Internet oversight. The average Internet user, however, is unlikely to benefit from a change in the current status quo as both alternatives, full privatization and intergovernmental oversight, are bound to affect both the Internet's innovative power and the personal liberties enjoyed by its users. more

On New Domains and ICANN Accountability, More Questions than Answers

The Internet Corporation for Assigned Names and Numbers (ICANN) went before a Congressional panel this week to defend its plan to create an unlimited number of new Internet domains (like .web, .food, etc.) I was a witness at the hearing, which made one thing clear: the "consensus" on new Internet domains is not as strong as ICANN would have us think. more

Threats to Internet Oversight Mount as Key Protection Expires

Before the US Government abdicates its oversight of the Internet Corporation for Assigned Names and Numbers (ICANN) it should take a long, hard look at the mounting efforts by world governments to assume greater power over the Internet's addressing system. If those efforts meet no further resistance, the once-theoretical threat of "capture" could become a reality. At the end of September, the Joint Project Agreement (JPA) between ICANN and the US Government is set to expire. The JPA is part of a decade-long agreement where the US transitions control of Internet addressing to ICANN. more

Choosing the Right Path to a Permanent Accountability Framework for ICANN

Over the next month, the ICANN Board will consider its options for ensuring that some framework is in place to ensure ICANN's accountability to the global Internet community after the approaching expiration of its Memorandum of Understanding and Joint Project Agreement (MOU/JPA) with the U.S. Department of Commerce. We analyze these options in our new paper... more

Forget TLDs, Keep Dot Suffix and Move On

I have been working on URL, Web address, ID's and Namespace since quite a long time and I have my reservations about the present set up being a complete network. generic Top-Level Domains (gTLDs), country codes (cc), .co are all complicating the network, add to that the problem of address shortage plus other problem mentioned in comments and blogs at CircleID. It's time for out of the box thinking. more

Just Say No, to Your ISP Subverting Your DNS Queries

Over the past few weeks I have been seeing reports that some ISP's are actually subverting DNS queries to their own DNS server. Oh the humanity! What this means is that when you (your computer) does a UDP or TCP Port 53 DNS query the ISP is intercepting that and directing it to their own servers. Has anyone been told by their ISP that they are doing this? No? I didn't think so... more

DNS, My God It’s Full of Stars…

Since my last post about DNS subversion we have had some good feedback. We had 29 responses, I agree a small sample, but what we found is very interesting. Let's remind ourselves of what we are looking at? Does your ISP redirect DNS queries? Specifically, if you try to make a port 53 UDP or TCP connection to a server outside of your ISP's network does it get there? more

Comcast Unleashes Trial DNS Redirection in Select States

In a post today on Comcast's blog, Chris Griffiths, DNS Engineering Manger, has informed customers that they have begun to role a DNS redirection service -- a controversial service offered by several other ISPs over the years to redirect mistyped URLs to ad-based pages instead of a typical 404 error page. The service called "Domain Name Helper Service" is being launched as a market trial in Arizona, Colorado, New Mexico, Oregon, Texas, Utah, and Washington according to the company. more

Are Click Fraud Numbers Being Exaggerated by the Traditional Media?

As you certainly noticed, a lot of traditional media has recently been focusing on click fraud. Is it as big of an issue as it is made out to be, compared to traditional advertising? Unfortunately Eytan Elbaz of Google will not answer this question with statistics, but he lets us know that Google has the problem under control. Here are some notes based on the Click Fraud Session at the Targeted Traffic Conference in Hollywood, Florida last week. more

Most Popular Invalid TLDs Should Be Reserved

Some of the root server operators post public statistics for their domain name traffic at the top-level. For example, the graph (which can take a bit of time to generate, given ICANN's slow servers) for the L-root server's most popular Top-Level Domain (TLD) queries demonstrates, to no one's surprise, that .com is king. What's more interesting, though, especially given the new generic Top-Level Domain (gTLD) debate, is to look at the most popular invalid (non-existent) TLDs. more

Help! My Domain Name Has Been Hijacked!

They are out there. In Internet Cafes and dark rooms from New York to Hong Kong to Iran, the domain name hijackers are plotting to steal your domain names. Fortunately, there are some steps that you can take to protect yourself against losing your domain names. ...Registrars are often skeptical of claims of domain hijacking, and the hijackers often "launder" the domain names to look as if they have sold them to third parties... By the time you discover that your domain name has been stolen, it may be at its third or fourth different registrar in the name of a completely different party... more

Why DNS Is Broken, Part 2: DoS Target

Before we get into what DNSSEC is and the benefits of it, let's talk about some of the other potential pitfalls of DNS. One of the most significant issues we have to deal with are denial-of-service (DoS) attacks. While DoS attacks are not specific to DNS we have seen DNS be a frequent target of these attacks. more

DNS Attack Takes Down Internet in Five Northern and Coastal Provinces of China

According to Shanghai Daily, there has been an "organized Internet attack on Tuesday night which caused serious congestion in several provinces [in China] and left millions of users unable to gain access to the Internet." This is the first time the regulator has published news about an investigation into an online attack in China within 24 hours, says Shanghai Daily. ..."It was an attack on DNS (Domain Name System) and the carriers and related firms should do more back-up to avoid similar incidents," the ministry said in a statement. more

EU Calls For Full Privatization of ICANN, Commissioner Calls Sept 30 Moment of Truth

In a video posted on her website this morning, Viviane Reding, EU Commissioner for Information Society and Media, has called for greater transparency and accountability in Internet Governance. She outlines a new Internet Governance model which includes a fully private and accountable ICANN, accompanied by an independent judicial body, as well as a "G12 for Internet Governance" -- a multilateral forum for governments to discuss general internet governance policy and security issues... more