Renesys Blog: Securing the Root

You're looking at a discussion in babbledog. Babbledog collects news that fits your interests; vote on this story and we'll make better recommendations in the future.

 

 

what's happening right now...

Post Post and share your thoughts, questions, movies, pictures, websites, etc.
Renesys Blog: Securing the Root
While there is no evidence of foul play with regard to the bogus L root servers, the duration of this event, the potential for mayhem, and the complete absence of any controls whatsoever should give us all reason for concern. Just think for a minute about what you could do with a root name server if you had evil intent. How about ...
  • Provide a new list of all root name servers when asked
  • Provide new NS records for any or all TLDs
  • Set TTL = 0 for all answers
  • Perform recursion by default
  • Log everything
  • Censor or misdirect as desired
Badness!
Posted 89 days ago
Responses to this thread:
todd: This story is still poorly understood by technical people that I talk to. The attitude seems to be: Manning is a good guy and wasn't doing anything wrong. That misses the point badly. If it were not manning and it were a bad guy, no one *still* would have noticed and they could have done really, really bad things. No one is watching this stuff closely enough.
Posted 89 days ago

Jim Cowie: It's weird that D-root is only advertised as a /16. The much smaller /24 is obviously preferable, because /24 is the smallest block that you can generally trust to be globally routable (not filtered as "too small to propagate"). The obvious attack is to advertise the /24 to a provider who doesn't filter, get it globally propagated, hoka hey, D-root pwn3d.
Posted 89 days ago

Jim Cowie: All of the suggestions Earl gives are spot-on. Simple due diligence.
Posted 89 days ago

Send Reply
You will be prompted to register a name or log in before your comment is posted.
help   Sign In OR Register
What's This?
Your current score: ?
SHARE
close
SHARE
close
INVITE
close
WIDGET
close
close

Create a new account:

Required Screen Name:

(a-z, A-Z, 0-9, _, -, or spaces allowed)



 
 
Recommended... so you can sign in again later. Email:

Password:

Password (again):

Sign in with
existing account:

Email:

Password:

Forgot password?
 
close

Don't go, None!

You haven't registered your email or chosen a password, so if
you log out now, you'll never be able to log back in as None.
That means you won't be able to edit your profile, post messages
as None, or otherwise enjoy the privileges that go along with
the great name of None.

Email:

Password:
Password (again):

Upgrade my Account    or    Forget it, logout forever

close

Sign into Babbledog!

Sign In
Email
Password   ( forgot it? )
close