The Internet has undergone a key upgrade that promises to stop cyber criminals from using fake Web sites that dupe people into downloading viruses or revealing personal data.
The agency in charge of managing Internet addresses teamed with online security services firm VeriSign and the US Department of Commerce to give Web sites encrypted identification to prove they are legitimate.
“This is, by any measure, an historic development,” Internet Corp for Assigned Names and Numbers (ICANN) chief executive Rod Beckstrom said at a premier Black Hat computer security conference in Las Vegas on Wednesday.
“This security upgrade matters to everyone who uses a computer, and that means most of us,” he said.
The Domain Name System Security Extensions (DNSSEC) basically adds a secret, identifying code to each Web site address.
The domain name system is where the world’s Internet addresses are registered and plays a key role in enabling computers around the world to speak with one another online.
Applications commonly used on the Internet can be tailored to essentially check the ID of a Web site to make certain it is what it claims to be, according to Dan Kaminsky, a hacker turned computer security specialist.
For example, Web browser software such as Google or Bing could be adapted to tell whether a bank log-in page is authentic.
“When a user receives an e-mail from a bank they should know it came from a bank,” Kaminsky said. “This is something we needed as engineers to make this a reality.”
A frightening structural flaw in the foundation of the Internet revealed by Kaminsky at Black Hat here two years earlier led to the “biggest structural” upgrade to the Web in decades, Beckstrom said.
“I can’t say I really knew what I was getting into when I broke that whole DNS thing,” Kaminsky quipped as he took part in a press conference announcing the Internet improvement.
Kaminsky is chief scientist at New York start-up Recursion Ventures and worked with ICANN and VeriSign on the upgrade.
Internet engineers have been toiling on DNSSEC for 18 years, but technical and political obstacles stalled progress, Internet Engineering Task Force chairman Russ Housely said in a video call from a meeting of the group in the Netherlands.
“It can be thought of as tamper-proof packaging for the domain name structure,” Housely said.
“The whole Internet engineering community is excited by this development,” he said.
IETF members at the meeting toasted the announcement with champagne, which “I assure you is not a common occurrence at a gathering of engineers,” he said.
It will take time for Internet firms to take advantage of DNSSEC and for it to be applied to local domains in every country, Kaminsky said.
“We are on Day One of a multi-year journey,” he said.
DNSSEC strips cyber criminals of being able to use attacks that involve manipulating code to redirect people from legitimate Web sites to fake pages rigged with malicious code or asking for passwords and other valuable data.
‘IN A DIFFERENT PLACE’: The envoy first visited Shanghai, where he attended a Chinese basketball playoff match, and is to meet top officials in Beijing tomorrow US Secretary of State Antony Blinken yesterday arrived in China on his second visit in a year as the US ramps up pressure on its rival over its support for Russia while also seeking to manage tensions with Beijing. The US diplomat tomorrow is to meet China’s top brass in Beijing, where he is also expected to plead for restraint as Taiwan inaugurates president-elect William Lai (賴清德), and to raise US concerns on Chinese trade practices. However, Blinken is also seeking to stabilize ties, with tensions between the world’s two largest economies easing since his previous visit in June last year. At the
UNSETTLING IMAGES: The scene took place in front of TV crews covering the Trump trial, with a CNN anchor calling it an ‘emotional and unbelievably disturbing moment’ A man who doused himself in an accelerant and set himself on fire outside the courthouse where former US president Donald Trump is on trial has died, police said yesterday. The New York City Police Department (NYPD) said the man was declared dead by staff at an area hospital. The man was in Collect Pond Park at about 1:30pm on Friday when he took out pamphlets espousing conspiracy theories, tossed them around, then doused himself in an accelerant and set himself on fire, officials and witnesses said. A large number of police officers were nearby when it happened. Some officers and bystanders rushed
Beijing is continuing to commit genocide and crimes against humanity against Uyghurs and other Muslim minorities in its western Xinjiang province, U.S. Secretary of State Antony Blinken said in a report published on Monday, ahead of his planned visit to China this week. The State Department’s annual human rights report, which documents abuses recorded all over the world during the previous calendar year, repeated language from previous years on the treatment of Muslims in Xinjiang, but the publication raises the issue ahead of delicate talks, including on the war in Ukraine and global trade, between the top U.S. diplomat and Chinese
RIVER TRAGEDY: Local fishers and residents helped rescue people after the vessel capsized, while motorbike taxis evacuated some of the injured At least 58 people going to a funeral died after their overloaded river boat capsized in the Central African Republic’s (CAR) capital, Bangui, the head of civil protection said on Saturday. “We were able to extract 58 lifeless bodies,” Thomas Djimasse told Radio Guira. “We don’t know the total number of people who are underwater. According to witnesses and videos on social media, the wooden boat was carrying more than 300 people — some standing and others perched on wooden structures — when it sank on the Mpoko River on Friday. The vessel was heading to the funeral of a village chief in