4

votes

Vote

internet-networking in Internet & Networking Channel,
Written by: Cedric Voisin on Apr 14 2010, 4:35am

Will DNSSEC kill your internet?

Internet users face the risk of losing their Internet connections on 5 May when the domain name system switches over to a new, more secure protocol.

So what is DNSSEC?

DNSSEC adds digital signatures to normal DNS queries, substantially reducing the risk of falling victim to man-in-the-middle attacks such as the Kaminsky exploit, which caused widespread panic in July 2008.


The standard is currently being rolled out cautiously to the internet's DNS root servers. In May, when all 13 roots are signed, anybody with an incompatible firewall or ISP will know about it, because they won't be able to find websites or send email.

You can test whether your current DNS resolver is capable of handling DNSSEC, by following the instructions at DNS-OARC or running a Java app that can be downloaded from RIPE.

Home users using residential hubs should not panic if these tests return scary results. According to Mitchell, it currently only matters that the ISP supports DNSSEC. A dodgy Netgear box is not enough to kill your internet... cross fingers!

What will DNSSEC brings you?


By adding signature to DNS zone and DNS servers, you'll ensure data integrity and queris integrity, which means that DNS cache poisoning would be more than tricky to perform.

Another good point for IT, DNSSEC will allow a better spam fight, as well as SPF, it will allow to verify that you are really who pretend to be.

I have been waiting a long time for this to be release, Internet will really be cleaner after that. Soon we will enjoy a more trustable network!

 

More details about this can be found here

Citizens Comments

Support SoftCity says:

Any initiative to reduce SPAM has my vote! Thanks for the info Cedric.

1

Vote

Vote
Apr 14 2010, 1:54pm | Report

Paul Bamberger says:

When I heard about the change I expected lots of issues. It shouldn't be a year 2000 type problem, but we'll see.

1

Vote

Vote
Apr 14 2010, 6:41pm | Report

Post your comment

default Avatar

You might be interested in these related contributions

SoftCity Promotion

About the Author

Cedric Voisin

Paris, Ile-de-France, FR

115 contributions

I'm working in IT for almost 10 years now.

Very interested in Open Source technology, I'm still trying to improve my skills and discover new project i can work on.

To be short I'm an ITcoholic!

Recent contributions

Popular contributions

software social commerce