DNSSEC

IP-based networks, including the Internet, route information between computers based on their IP address (such as 208.77.188.166). Directly using these numbers would cause many problems, so Domain Name System (DNS) is a critical service of such networks. DNS accepts a domain name (such as www.example.com) and responds with information about that name, such as its matching IP address. DNS can also perform reverse look-ups (given an IP address, return the corresponding name). Unfortunately, DNS was not designed to be secure. DNSSEC was designed to protect Internet resolvers (clients) from forged DNS data. It is widely believed that deploying DNSSEC is critically important for securing the Internet as a whole, but deployment has been hampered by some difficulties. Some of these problems are in the process of being resolved, and deployments in various domains have begun to take place. Read the full background at DNSSEC Wikipedia

DNSSEC / Industry Updates

DNSSEC FUD Buster: DNSSEC is Not Necessary?

.ORG, The Public Interest Registry is pleased to announce the next guest blogger for our DNSSEC FUD Buster series. Ram Mohan is the Executive Vice President, & Chief Technology Officer of Afilias Limited. Ram has led the strategic growth initiatives at Afilias Limited in registry services and security as well as new product sectors such as RFID/Auto-ID, global DNS and Internationalized Domain Names (IDNs). more»

DNSSEC "FUD" Buster: Don't Panic

.ORG, The Public Interest Registry is pleased to announce of first guest blogger for our DNSSEC FUD series. John Kristoff works as a research analyst for Team Cymru, a Internet Security Research company based in Chicago specializing in the 'who' and the 'why' of Internet crime. more»

.ORG Talks with Dan Kaminsky on DNSSEC

The following post is based on a recent discussion .ORG had with Dan Kaminsky, a DNS expert best know for discovering a serious DNS bug, about DNSSEC and how it is a critical step toward bolstering Internet security. more»

.ORG Applauds US Government on DNSSEC

.ORG applauds the US Government's decision last week to require all users of the .GOV domain to implement DNSSEC, and even more importantly, to sign the .GOV root. .ORG is the first generic Top Level Domain authorized by ICANN to implement DNSSEC, and we are hard at work putting together a comprehensive plan to roll it out. more»

On the Pressing Need for a Signed Root

Attacks on the security of the Internet have been much in the news lately, and there is an increased urgency to take the technical steps to combat these attacks. .ORG has been doing its part to lead this process by taking introductory steps to implement DNSSEC (Domain Name System Security Extensions)... In order to make DNSSEC effective, there is one additional step that is needed -- "signing the root". more»

.ORG Becomes the First Generic Top level Domain to Start DNSSEC Implementation

A request by .ORG, The Public Interest Registry to bolster Internet security via the implementation of Domain Name Security Extensions (DNSSEC) was unanimously approved by ICANN at the recent Paris meeting. As the first generic Top Level Domain authorized to implement DNSSEC, .ORG also is preparing an education and adoption plan within the Internet infrastructure community. more»

ISC Launches DLV Registry to Kick Off Worldwide DNSSEC Deployment

ISC, working with accredited ICANN domain name registrars such as TUCOWS, is making available to the world a mechanism to allow domain holders to secure their domain information using the DNSSEC protocol extension to DNS in advance of a signed root or TLD zone. more»

ICANN Concludes 24th International Public Meeting in Vancouver

During the meeting, productive discussion took place between ICANN's Board and the Governmental Advisory Committee (GAC) concerning the role of the GAC in light of the WSIS discussions. more»

Most Popular