Advertisement
Promo

Security management Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Icann: Coders and ISPs vital to net security

Tom Espiner ZDNet.co.uk

Published: 08 Jun 2009 17:17 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Developers and internet service providers will need to participate if the encryption of a fundamental internet protocol is to succeed, according to Icann.

Icann is the US-based organisation responsible for running the domain-name system (DNS), which is the addressing system used to route information packets on the internet. The DNS has long been known to have numerous critical vulnerabilities, and the use of Domain Name System Security Extensions (DNSSEC), an encrypted protocol, would mitigate many DNS flaws.

Paul Twomey, the president and chief executive of Icann, told ZDNet UK on Friday that it was "important to get the application-layer community involved and to recognise that DNSSEC should move through all applications".

ISPs will also be vital to the next stage of the deployment, said Twomey, who anticipates that initially there will be a two-tier internet system, with one tier encrypted.

"It's going to take some time to deploy and further discussions, as there are a lot of implementation issues for ISPs in how they support DNSSEC," said Twomey. "[Users] will have to have access to both signed and unsigned roots. It's not like we can turn DNSSEC on tomorrow."

Icann announced last Wednesday that, in an interim measure, VeriSign will sign DNSSEC at the root zone of the internet.

Twomey said DNSSEC deployment would mitigate DNS cache poisoning, in which users are unwittingly redirected to fake internet sites.

"It means that users will have confidence that content comes from that site, not from some man-in-the-middle attack," said Twomey. "DNSSEC itself is not a new protocol, but moving towards having it deployed is a major step. This deployment will be seen as major milestone in addressing fundamental security issues in a system designed 35 years ago."

DNSSEC deployment has been discussed since at least 2005, and has in part been held up by political issues as to who should sign the root. Twomey said that agreement between different organisations and stakeholders had now been achieved.

"This really points out the value of the Icann model," said Twomey. "We are a community-based organisation, and that brings a series of understandings."

Twomey said technical people in the internet security and stability community have had discussions globally, including within countries that do not historically have political affiliations with the US.

"We had discussions in Russia as to how DNSSEC could work," said Twomey. "That has been a positive outcome."

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
0 out of 1 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

5 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

Featured Talkback

In association with Network Liberation Movement
It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters