Technology Sectors

Market Sectors

DNSSEC still mystery to many

Rod Rasmussen

An Internet technology aimed at making access to websites more secure is a mystery to many corporate IT security experts.

That's what surveyors from Internet Identity (IID), of Tacoma, WA, and the Online Trust Alliance discovered when they polled security pros about domain name system security (DNSSEC), a standard designed to protect Internet users from getting misdirected to unintended Net destinations by ensuring domain names remain unchanged in transit.

Some 50 percent of security experts surveyed between January 17 and March 28 had never heard of DNSSEC or didn't understand it.

“This survey provides key insight into the market’s knowledge (or lack thereof) regarding DNSSEC, and what the future may hold with the security standard,” IID President and CTO Rod Rasmussen said in a statement.

“Perhaps unsurprisingly," he continued, "about half of all respondents do not have a clear understanding of the technology or its benefits, indicating the industry still has its work cut out. However, those who have familiarity with DNSSEC seem to understand its key benefits and current challenges, which is promising for eventual adoption.”

For DNSSEC to work, it needs to be embraced by the online ecosystem—browser makers, registrars and business community, maintained Online Trust Alliance Director and President Craig Spiezle.

 “We are encouraged by the adoption of leading government sites and look forward to working with industry leaders including IID to develop tools, resources and prescriptive advice to accelerate adoption with leading banking and ecommerce sites,” he added.

The Internet’s root servers at the top of the DNS hierarchy added DNSSEC support last July. More than 25 top-level domains—including .gov, .org, .edu and .net—have enabled DNSSEC since then. On March 31, DNSSEC was enabled on the .com top level domain (TLD), which has more than 80 million registered names, according to its operator, VeriSign.

Among the champions of DNSSEC is the operator of Europe's TLD, EURid. It is launching a new service in this year's third quarter that will make it easier for registrars to implement the standard. It's also conducting complementary training seminars across Europe to boost the registrars' confidence in working with the system.

That's not to say that DNSSEC doesn't have its detractors. Melih Abdulhayoglu, CEO of Comodo, which issues certificates used by web browsers to authenticate websites, argued that DNSSEC "is a '90s idea that didn't even work in the '90s and is not practical today."

Last year, Comodo submitted to the Internet Engineering Task force a security scheme called Certification Authority Authorization (CAA), which Abdulhayoglu argues will address some of the problems DNSSEC was created to address.

"The Certification Authority Authorization (CAA) DNS Resource Record allows a DNS domain name holder to specify the certificate signing  certificate(s) authorized to issue certificates for that domain," the task force explained in a document posted online March 9. "CAA resource records allow a public Certification Authority to implement additional controls to reduce the risk of unintended certificate misissue."

 

Upcoming Events

Event Details Dates of Event
Mission Command Jun 10 - 12
Cyber Securty Brainstorm Jun 11 - 11
EDGE Summit 2013 Jun 11 - 11
IPv6 Summit 2013 Jun 14 - 16
SANSFIRE 2013 Jun 15 - 22
Oak Ridge National Laboratory's 2nd Biosurveillance Symposium Jun 17
Biodetection Technologies 2013 Jun 18 - 19
Southwest Microwave Seminar Jun 18 - 18
Cyber Defense and Network Security Summit Jun 24 - 26
Vanguard Security & Compliance 2013 Jun 24 - 27
SANS Canberra 2013 Jul 1 - 13
Border Management & Technologies Summit Jul 2 - 5
SANS Rocky Mountain 2013 Jul 15 - 20
SANS Mumbai 2013 Jul 22 - 27
Cyber Security Brainstorm Jul 24 - 24
SANS San Francisco 2013 Jul 29 - Aug 3
SANS Boston 2013 Aug 5 - 10
Cyber Security for Government Aug 12 - 14
SANS Thailand 2013 Aug 19 - 31
SANS Virginia Beach 2013 Aug 19 - 30
Maritime Security 2013 West Aug 19 - 21
930gov: Strategic Buying at Year-End Showcase Aug 21 - 21
SANS Melbourne 2013 Sep 2 - 7
SANS Capital City 2013 Sep 3 - 8
US/Canada Border Conference Sep 12 - 13
Network Security 2013 Sep 14 - 23
Cyber Intelligence Europe Sep 17 - 19
EnergySec 9th Annual Security Summit Sep 17 - 19
iFSO International Facility Security Officer Conference Sep 17 - 19
International Facility Security Officer Conference Sep 17 - 19
DefendUSA Sep 19 - 20
ASIS Foundation Golf Tournament Sep 23 - 23
NCT: CBRNe Asia, 24-27 September 2013, Kuala Lumpur Sep 24 - 27
ASIS Foundation Night at ASIS 2013 Sep 26 - 26
SANS Bangalore 2013 Oct 14 - 26
SOS SANS October Singapore 2013 Oct 21 - Nov 2