Internet upgraded to foil cyber crooks
Thursday 29 July 2010
The Internet has undergone a key upgrade that promises to stop cyber criminals from using fake websites that dupe people into downloading viruses or revealing personal data.
The agency in charge of managing Internet addresses teamed with online security services firm VeriSign and the US Department of Commerce to give websites encrypted identification to prove they are legitimate.
"This is, by any measure, an historic development," ICANN chief executive Rod Beckstrom said while breaking the news at a premier Black Hat computer security conference in Las Vegas on Wednesday.
"This security upgrade matters to everyone who uses a computer, and that means most of us."
The Domain Name System Security Extensions, referred to as DNSSEC, basically adds a secret, identifying code to each website address.
The domain name system is where the world's Internet addresses are registered and plays a key role in enabling computers around the world to speak with one another online.
Applications commonly used on the Internet can be tailored to essentially check the ID of a website to make certain it is what it claims to be, according to Dan Kaminsky, a hacker turned computer security specialist.
For example, web browser software such as Google or Bing could be adapted to tell whether a bank log-in page is authentic.
"When a user receives an email from a bank they should know it came from a bank," Kaminsky said. "This is something we needed as engineers to make this a reality."
A frightening structural flaw in the foundation of the Internet revealed by Kaminsky at Black Hat here two years earlier led to the "biggest structural" upgrade to Web in decades, according to Beckstrom.
"I can't say I really knew what I was getting into when I broke that whole DNS thing," Kaminsky quipped as he took part in a press conference announcing the Internet improvement.
Kaminsky is chief scientist at New York start-up Recursion Ventures and worked with ICANN and VeriSign on the the Internet upgrade.
Internet engineers have been toiling on DNSSEC for 18 years, but technical and political obstacles stalled progress, Internet Engineering Task Force chairman Russ Housely said in a video call from a meeting of the group in the Netherlands.
"It can be thought of as tamper-proof packaging for the domain name structure," Housely said.
"The whole Internet engineering community is excited by this development."
He added that IETF members at the meeting toasted the announcement with champagne which "I assure you is not a common occurrence at a gathering of engineers."
It will take time for Internet firms to take advantage of DNSSEC and for it to be applied to local domains in every country, according to Kaminsky.
"We are on Day One of a multi-year journey," Kaminsky said.
DNSSEC strips cyber criminals of being able to do attacks that involve manipulating code to redirect people from legitimate websites to fake pages rigged with malicious code or asking for passwords and other valuable data.
"This provides a high level of protection with minimal disruption," said VeriSign chief executive Mark McLaughlin.
"It is not a panacea for everything, but it is a good start."
Life & Style blogs
WWE 2K15 gameplay trailer: First look at Sting, Triple H and Daniel Bryan in next-gen graphics
iOS 8 apps and features: eight iPhone settings you need to look at after you install the update
iPhone 'Wave': iOS 8 hoax claims you can charge your iPhone in the microwave - you can't
First day of Autumn: Google Doodle celebrates 2014 Autumn equinox
What are your fingerprint words?
Scotland could still declare independence – even without referendum, says Alex Salmond
Scottish referendum results: Cross-party consensus collapses amid Tory-Labour spat on the 'English question'
Hilary Mantel 'should be investigated by police' over Margaret Thatcher assassination story, says Lord Bell
Scottish independence: David Cameron is becoming the 'George Bush of Britain'
Plebgate MP Andrew Mitchell called officer a 'little s**t', claim court documents 'exposing ex-Chief Whip's 'record of abusing police'
Archbishop of Canterbury admits doubts about existence of God
- 1 Rihanna 'nude pictures' claims emerge on 4Chan as hacking scandal continues
- 2 Kim Kardashian 'nude photos' leaked on 4chan weeks after Jennifer Lawrence scandal
- 3 'F*ck it, I quit': KTVA reporter Charlo Greene quits live on air in spectacular fashion
- 4 What are your fingerprint words?
- 5 Gary Lineker involved in Twitter row after presenter rubbishes claims he will be warned by BBC over foul-mouthed tweets
iJobs Gadgets & Tech
£40000 - £45000 per annum + pension, healthcare,25 days: Ashdown Group: An est...
£24000 per annum: Ashdown Group: An established and growing IT Consultancy fir...
£18000 per annum: Ashdown Group: An established and growing IT Consultancy fir...
£40000 - £45000 Per Annum + benefits: Clearwater People Solutions Ltd: Project...