Security

Internet security is the prevention of unauthorized access and/or damage to computer systems via internet access. Internet security practices are primarily focused in four major areas: penetration testing, intrusion detection, incidence response, and legal compliance. Read the full background at Security Wikipedia

Featured Blogs

The Proxy Fight for Iranian Democracy

If you put 65 million people in a locked room, they’re going to find all the exits pretty quickly, and maybe make a few of their own. In the case of Iran’s crippled-but-still-connected Internet, that means finding a continuous supply of proxy servers that allow continued access to unfiltered international web content like Twitter, Gmail, and the BBC... more»

No Honor Among Thieves on the Internet

Apple's Wordwide Developers Conference may have just ended, but already, the conference release of Mac's OS X 10.6 — a beta build previewed for developers — has been leaked onto torrent sites. It borders on irony: for years, Mac lovers have touted the superior security of the Mac operating system over Windows, but earlier this year, it was torrent sites — the very sites where OS X 10.6 is now being freely copied — that caused more than 25,000 Mac users to fall victim to the iServices Trojan. Some Macs never learn. more»

Why Not an Interim Step Until DNSSEC is Ready?

I'm interested in CircleID community's take on NeuStar's recent announcement of Cache Defender. While only effective for domains the company is authoritative for, that does cover a large number of big Internet brands and financial institutions. Why wouldn't an ISP deploy this now, while waiting for all the myriad issues involved in DNSSEC to be resolved? more»

ICANN 35: What's Going Down, Down Under (Want the Low Down?)

As I've been getting ready to catch my plane for ICANN 35 (Sydney), I can't help but thinking that there are a lot of things going down these days that will dramatically affect makeup of the Internet for years to come. Next year at this time, the root could be a very, very different place. A few of the items that will be getting deconstructed, discussed, debated Down Under are outlined below... more»

Fight Phishing With Branding

Phishing, stealing personal information by impersonating a trusted organization, is a big problem that's not going away. Most antiphishing techniques to date have attempted to recognize fake e-mail and fake web sites, but this hasn't been particularly effective. A more promising approach is to brand the real mail and real web sites. more»

DKIM for Discussion Lists

There's a pernicious meme floating around that DomainKeys Identified Mail (DKIM) doesn't work with discussion lists, particularly those hosted on common open source software packages like MailMan. It's particularly odd to see this claim after I set it up successfully on a stock Debian server in less than half an hour, just a few weeks ago. Here's how it can, should, and does work. more»

How a Resilient Society Defends Cyberspace

Seventy-five years ago today, on May 29th, 1934, Egyptian private radio stations fell silent, as the government shut them down in favor of a state monopoly on broadcast communication. Egyptian radio "hackers" (as we would style them today) had, over the course of about fifteen years, developed a burgeoning network of unofficial radio stations... It couldn't last. After two days of official radio silence, on May 31st, official state-sponsored radio stations (run by the Marconi company under special contract) began transmitting a clean slate of government-sanctioned programming, and the brief era of grass-roots Egyptian radio was over... more»

Thoughts on IPv6 Security, Take Two

A few months ago, I made a post about IPv6 security. I've caught some flak for saying that IPv6 isn't a security issue. I still stand by this position. This is not to say that you should ignore security considerations when deploying IPv6. All I claim is that deploying IPv6 in and of itself does not make an organization any more or less secure. This point was made by Dr. Joe St. Sauver, of the University of Oregon... more»

Why DNS Is Broken, Part 2: DoS Target

Before we get into what DNSSEC is and the benefits of it, let's talk about some of the other potential pitfalls of DNS. One of the most significant issues we have to deal with are denial-of-service (DoS) attacks. While DoS attacks are not specific to DNS we have seen DNS be a frequent target of these attacks. more»

Hannaford Data Breach Plaintiffs Rebuffed in Maine

A US District Judge in Maine largely granted a motion to dismiss brought by Hannaford in a big data breach case... According to the court, around March 2008, third parties stole up to 4.2 million debit and credit card numbers, expiration dates, security codes, PIN numbers, and other information relating to cardholders "who had used debit cards and credit cards to transact purchases at supermarkets owned or operated by Hannaford." more»

News Briefs

US Teaming Up With Italy to Combat Cybercrime

Trojans Fastest Growing Category of Data-Stealing Malware

US Continues to Lead As Top Country Hosting Phishing Attacks

Gary Warner: We Are Well Past Time to Declare a Spam Crisis in China

SPECIAL: Updates from the ICANN Meetings in Sydney

UK to Get Its Own Cyber Czar

ICANN to Work With VeriSign, US Government, to Address Core Internet Security Issue

Google Reveals Top 10 Malware Sites From Its Index

Security Experts Criticize Obama's New Cybersecurity Plan, Say It's Full of Holes

Mass Hacker Attack Reported on 40,000 Legitimate Websites

Obama: From Now On Digital Infrastructure Treated As Strategic National Asset

Survey Finds "Complexity" as Most Common Challenge in Deploying DNSSEC

New Research Finds Over 80% of Domain Names Used by Phishers Are Legitimate Domains

Obama Expected to Announce "Cyber Czar" in a Few Days

A US Military-Funded Program Now Seeking High School and College Hackers

Most Viewed

Most Commented

Industry Updates

Latest Brandjacking Index Examines How Fraudsters Abuse Financial Brands

MarkMonitor, the global leader in enterprise brand protection, today released the company's latest Brandjacking Index that studies how fraudsters are abusing major financial brand names and topical subjects like refinancing or unemployment to lure unsuspecting consumers to questionable websites. ›››

NeuStar Addresses DNS Vulnerability with Cache Defender, a Secure DNS Authentication System

This vulnerability, brought to public attention last year by security researcher Dan Kaminsky, allows criminal elements to engage in "DNS cache poisoning" for the malicious hijacking of domain names and results in consequent damage from large-scale identity theft, among other illegal activities. ›››

A Seemingly Overwhelming Number of Important Documents Released by ICANN

The Internet Corporation for Assigned Names and Numbers (ICANN) has recently released a number of important documents. This post includes brief synopses of these newly released documents. ›››

.ORG First Open Top-Level Domain to be Signed with DNSSEC

Today, .ORG, The Public Interest Registry, the company behind the .ORG domain name, is the first open generic Top-Level Domain to successfully sign the .ORG zone file with Domain Name Security Extensions (DNSSEC). To date, the .ORG zone is the largest domain registry to implement the security measure. ›››

DNSSEC Industry Coalition Symposium is Announced

The DNSSEC Industry Coalition Symposium is announced today in collaboration with Google, Nominum, Inc. and ICANN and will be held June 11-12, 2009, in Washington, DC. The purpose will be to discuss and identify potential and perceived issues with the Domain Name System (DNS) and DNSSEC deployment due to signing the DNS root zone. ›››

SPIL GAMES Chooses MarkMonitor for Global Domain Management

MarkMonitor today announced that SPIL GAMES, the world's ultimate online game destination, will be using MarkMonitor Domain Management to centrally manage SPIL GAMES' key domains. ›››

Facebook Selects MarkMonitor Antifraud Solutions to Combat Malware

MarkMonitor, the global leader in enterprise brand protection, today announced Facebook has selected MarkMonitor AntiFraud Solutions to supplement its own in-house security efforts in protecting users against malware attacks. ›››

MarkMonitor AntiFraud Solutions, Combining Proven Antiphishing and Expert Antimalware Capabilities

MarkMonitor announces AntiFraud Solutions, offering patented technology to enable brand owners to prevent, detect and respond to phishing and malware attacks. Service leverages the extensive MarkMonitor network of relationships and technology designed to thwart phishing attacks in order to combat the rapidly expanding problem of malware targeting brands. ›››

DNSstuff.com Offers Trusteer Rapport Product to Help Users Boost Their Defenses Against Online Fraud

DNSstuff.com has announced in partnership with Trusteer that it is offering Rapport, a tool that protects your transactions from being tampered with and private information from being stolen, through its website, dnsstuff.com.
Rapport is an easy-to-use browser plug-in that provides users with a secure connection to any online site they log into, protecting their most valuable online assets — login credentials. ›››

MarkMonitor AntiFraud Solutions Combine Proven Antiphishing and Expert Antimalware Capabalities

MarkMonitor has announced AntiFraud Solutions, offering patented technology to enable brand owners to prevent, detect and respond to phishing and malware attacks. MarkMonitor AntiFraud Solutions leverage the extensive MarkMonitor network of relationships and technology designed to thwart phishing attacks in order to combat the rapidly expanding problem of malware targeting brands.
 ›››