The 24th DNS-OARC meeting was held last week in Buenos Aires -- a two-day DNS workshop with amazingly good, consistent content. The programme committee are to be congratulated on maintaining a high quality of presentations. Here are my picks of the workshop. They fall into three groups, covering themes I found interesting... These presentations related to the ongoing problem of DNS as a source of reflection attacks, or a victim of attempted DDoS... more
Last month, the Government of Malta published a White Paper for public consultation, proposing the introduction of four so-called "digital rights" in the Constitution of Malta. The proposal is indeed a step in the right direction but lacks punch where it matters most. While the government's efforts are commendable, the White Paper is riddled with misconceptions and does not go far enough. more
At the start of the year, many responsible for managing domain name portfolios may be considering spring cleaning! Traditionally, such a task consists of a review to check that all domains in the portfolio serve a purpose either from a commercial or defensive perspective. The aim is to ensure budget isn't wasted on domains of little to no value. It's fair to say that for many organizations, this is a difficult process - almost as feared as actually spring cleaning our own homes. more
Internet demand remains at a rate which could outpace capacity within the next two to four years, according to "Internet Interrupted: Why Architectural Limitations Will Fracture the 'Net," a new report today from Nemertes Research. ...If left unaddressed, the development of next generation applications, from software to interactive video, will likely be stifled as users find Internet infrastructure incapable of efficiently delivering quality content. more
Thirty years ago, on April 30, 1993, a groundbreaking announcement was made by CERN that would irrevocably transform our world. Walter Hoogland and Helmut Weber, who held the positions of Director of Research and Director of Administration at CERN, respectively, released to the public a revolutionary tool initially proposed by Tim Berners-Lee in 1989. more
The IDN ccTLD Fast Track program is moving along rapidly, with ICANN's announcement that both the Simplified and Traditional Chinese script versions of .china have passed the string evaluation phase of the IDN ccTLD Fast Track Program. Alongside this, ICANN have also announced the release of a proposed implementation plan for 'Synchronised IDN ccTLDs' that will create the rules by which these variant IDN ccTLDs will coexist. more
U.S. regulators on Wednesday blocked some Obama administration rules on the eve of implementation, regulations that would have subjected broadband providers to stricter scrutiny than web sites face to protect customers' private data. more
Each SANSFIRE, the Handlers who can make it to DC get together for a panel discussion on the state of information security. Besides discussion of the hot DNS issue, between most of us there is a large consensus into some of the biggest problems that we face. Two come to mind, the fact that "users will click anything" and that "anti-virus is no longer sufficient". These are actually both related in my mind... more
All newly built residences located in counties and cities where a public fiber optic telecom network is available, have to be equipped with fiber network connections, according to new Chinese government policy from its Ministry of Industry and Information Technology. "The standards will take effect from April 1, 2013, and will also require residences to offer equal connections to services from various telecom companies allowing customers to choose which service they want," reports the China Daily. more
In part three of this series of posts looking at emerging internet content relating to coronavirus, we turn our attention to mobile apps - another digital content channel that can be used by criminals to take advantage of people's fears about the health emergency for their own gain.One of the most common attack vectors we have found in our analysis is the use of apps purporting to track global progression of COVID-19, or provide other information, but which instead incorporate malicious content. more
The importance of online presence continues to grow exponentially. More and more of our personal and professional endeavors are conducted online. Because of this, the ability to ensure a good experience for our online friends and customers also is increasing rapidly. At its core, load testing is nothing more than ensuring your online presence is ready for the number of visitors you expect. It's simple to explain, but historically it's been anything but simple, or easy to afford. more
The National Security Agency has obtained direct access to the systems of Google, Facebook, Apple and other US internet giants, according to a top secret document obtained by the Guardian. The NSA access is part of a previously undisclosed program called PRISM, which allows officials to collect material including search history, the content of emails, file transfers and live chats, the document says. more
Kevin Murphy reporting in DomainIncite: "Japanese electronics giant Hitachi has emerged as the second big consumer brand to officially announce it will apply for a '.brand' top-level domain. GMO Registry, also based in Japan, is the company's back-end provider of choice, according to this news release..." more
Straightforward out-of-court domain name proceeding can provide efficient relief against fraudulent websites and email. Google has seen a steep rise amid the Coronavirus pandemic in new websites set up to engage in phishing (i.e. fraudulent attempts to obtain sensitive information such as usernames, passwords and financial details). Companies in all industries - not just the financial sector - are at risk from this nefarious practice. But one relatively simple out-of-court proceeding may provide relief. more
As one of the earliest protocols in the internet, the DNS emerged in an era in which today's global network was still an experiment. Security was not a primary consideration then, and the design of the DNS, like other parts of the internet of the day, did not have cryptography built in. Today, cryptography is part of almost every protocol, including the DNS. And from a cryptographer's perspective, as I described in my talk at last year's International Cryptographic Module Conference (ICMC20), there's so much more to the story than just encryption. more