At the end of last week, US company VeriSign announced the roll-out schedule for the authentication of.com and .net zones. From the 9th of December, .net domains are to be authenticated via keys that are based on the new DNSSEC (Domain Name System Security Extensions) protocol and stored in the Domain Name System (DNS). . Responses that don't originate from the server that was authorised for a domain will be detected when signatures are validated. Signatures for .net domains have been available since the 29th of October, but they cannot be validated yet. Signatures for the .com zone are to follow in March; users will be able to protect their own .com domains with DNSSEC signatures shortly afterwards. This is mainly designed to prevent future cache-poisoning attacks. The link for this article located at H Security is no longer available. . VeriSign's DNSSEC implementation enhances security for .com and .net zones, protecting against cache poisoning and ensuring users access authentic DNS data. DNSSEC Implementation,Domain Authentication,Network Security Enhancements. . Alex
Two researchers have separately uncovered flaws in the way domain names are verified on the Internet that could allow attackers to impersonate a site and steal information from unsuspecting Web surfers.. Dan Kaminsky, who discovered a serious flaw in the Domain Name System (DNS) last year, and Moxie Marlinspike gave presentations at the Black Hat security conference on Wednesday about how someone could acquire certificates for domains they don't own and thus trick people into visiting those illegitimate sites or inadvertently sharing information. Marlinspike, an independent researcher, said a flaw in the way browsers and mail clients implement Secure Sockets Layer (SSL) allows for so-called man-in-the-middle attacks in which an attacker could trick browsers into presenting the site as legitimate. The link for this article located at CNET is no longer available. . Examining SSL protocol vulnerabilities uncovers major risks to domain verification, compromising user security and trust in online transactions.. Domain Authentication, SSL Flaws, Man-in-the-Middle Attack, Internet Security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.