ie8 fix
madison

Networking

Steven J. Vaughan-Nichols

Practice Safe DNS

By | October 21, 2010, 9:52am PDT

Summary: Domain Name System Security Extensions (DNSSEC) is finally being rolled out by major ISPs like Comcast, so it’s high time to start using it.

Misery is when you head to one of your usual Web site hangouts and find yourself somewhere nasty instead because of Domain Name System (DNS) poisoning. DNS cache poisoning doesn’t happen often, but when it does happen, it can make large parts of the Internet unusable. The answer to this potential poison problem? Domain Name System Security Extensions (DNSSEC).

DNS poisoning works like this. The DNS is the master address list for the Internet. With it, instead of writing out an IPv4 address like “http://209.85.135.99/,” one of Google’s many addresses, you can simply type in “http://www.google.com” and you’ll be you on your way. But, how can your browser be sure that “209.85.135.99″ is a correct address for Google? By itself, it can’t. It relies on DNS and, here’s the kicker, with plain Jane DNS, the system doesn’t have any built-in way to make sure that the information it’s feeding your browser is the real deal.

DNSSEC attempts to prevent DNS cache poisoning attacks by requiring Web sites to verify their domain names and corresponding IP addresses with DNS servers. To make sure this information isn’t compromised DNSSEC uses digital signatures and public-key encryption for this information exchange. That, in turn, makes it much harder for a cracker to effectively attack a DNS server since for an attack to work it needs to compromise the DNS information for popular Web sites.

The Internet’s 13 root name servers , the master DNS servers, began supporting DNSSEC on July 15. Today, DNSSEC is supported by 55 of the Internet’s 294 top-level domains (TLDs). This includes the TLDs in charge of all the non-profit .org domain and education institutions’ .edu domain. VeriSign is scheduled to start supporting DNSSEC on the .net domain by early 2011.

For most of us, changes at that level really don’t matter. We’re not likely to call on the root name servers or the TLDs for our DNS resolution. Now the switchover to DNSSEC is starting to affect us though. On October 18th, Comcast became the first major ISP to deploy DNSSEC. Indeed, if you want to start using it today, you can. Comcast customers, or anyone else for that matter, can set their DNS servers point to the IP addresses 75.75.75.75 and 75.75.76.76. For more on how to do this, see this Comcast DNSSEC video. If you want to know more about why using DNSSEC is a good idea, the new Web site Practice Safe DNS is chock-full of information.

So, if DNSEC is such a good idea why hasn’t everyone already done it? Well, you see, like any major Internet improvement, some legacy programs and hardware will have trouble with DNSSEC.

The chief problem is that some routers, switches, and firewalls won’t handle DNSSEC packets properly. DNS traffic uses User Datagram Protocol (UDP) and the usual DNS UDP packets are under 512 bytes in size. Thus, the default on a lot of network hardware and software is to reject any UDP packet over 512 bytes. Unfortunately, DNSSEC packets are always bigger than 512 bytes.

On some systems, this will cause DNS failures. Others will fail-over to Transmission Control Protocol (TCP). The downside of using TCP is that it uses significantly more bandwidth than UDP. It’s not a lot, but if you’re in charge of an enterprise network, it can add up to a noticeable increase in latency. And, no one likes a slow Internet.

In addition, some ISPs and DNS servers rewrite DNS answers to redirect their customers to customized search pages when they’re trying to find a non-existent website. For example, I use OpenDNS because it provides faster DNS service than my ISP. But, if I try to go to a domain that doesn’t exist, it pops me into an OpenDNS search page. What would happen if I were using DNSSEC and OpenDNS tried to do this? I don’t know, but I’ve a bad feeling it won’t be good.

OpenDNS, by the by, has elected to go with an alternative way of managing DNS security: DNSCurve. How will DNSCurve work with DNSSEC? Well, it won’t. They try to handle DNS security in rather different ways. What this is likely to mean for users is that you’ll still be able to use DNS, regardless of the security safeguard on the other side, but if they’re not using the same technology, you won’t get any security benefits.

The best thing you can do, as I see it, is to update your in-house DNS software and firmware to the latest DNSSEC-compliant version. You can also check to see if your upstream DNS is DNSSEC ready by following the DNS-OARC guidelines For those of you who aren’t network administrators, you can also run a Java application that will give you a quick, easy-to-understand answer.

If it turns out your ISP isn’t using DNSSEC, send them a note to get on the bandwagon. DNSSEC is coming and the sooner your ISP and you are protected with it, the better.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Steven J. Vaughan-Nichols, aka sjvn, has been writing about technology and the business of technology since CP/M-80 was the cutting edge, PC operating system

Disclosure

Steven J. Vaughan-Nichols

Steven J. Vaughan-Nichols is a freelance writer. He does not own stocks or other investments in any technology company.

Biography

Steven J. Vaughan-Nichols

Steven J. Vaughan-Nichols, aka sjvn, has been writing about technology and the business of technology since CP/M-80 was the cutting edge, PC operating system; 300bps was a fast Internet connection; WordStar was the state of the art word processor; and we liked it.

His work has been published in everything from highly technical publications (IEEE Computer, ACM NetWorker, Byte) to business publications (eWEEK, InformationWeek, ZDNet) to popular technology (Computer Shopper, PC Magazine, PC World) to the mainstream press (Washington Post, San Francisco Chronicle, BusinessWeek).

13
Comments

Join the conversation!

Just In

RE: Practice Safe DNS
JACOBSONR 14th Oct
Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.
0 Votes
+ -
Re: Practice Safe DNS
JT82 21st Oct 2010
I wonder how business class customers with static IP addressess will be handled...
0 Votes
+ -
Contributr
RE: Practice Safe DNS
sjvn@... 21st Oct 2010
@JT82 Like everyone else. DNSSEC is meant to eventually cover all things DNS.
0 Votes
+ -
RE: Practice Safe DNS
MACKENZI 11th Sep
I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate! nccma cooler
0 Votes
+ -
RE: Practice Safe DNS
PEARLINEI 12th Sep
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post. this thread is amazing i like your work and i appreciate you that you have share a useful stuff thanks for sharing the i shop abatwa
0 Votes
+ -
RE: Practice Safe DNS
RHIANNONA 13th Sep
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post.Bookmarking now thanks please consider a follow up post. power sa shop
0 Votes
+ -
RE: Practice Safe DNS
kaigui 5th Oct
@RHIANNONA I recently came across your blog and have been reading along. I thought I would leave my first comment. I don???t know what to say except that I have enjoyed reading. Nice blog, I will keep visiting this blog very often.. hghoslsgd hdf hkokxjgos jhs jgosighmi
0 Votes
+ -
RE: Practice Safe DNS
SATURNINA 14th Sep
I think the representation of this article is actually superb one. This is my first visit to your site. Thanks a lot and keep sharing the information. Keep updating the information for all of us. Thanks ZDNet Government was launched as the brand's first industry vertical, with a mission to cater to IT professionals in the public secto I agree with your post. However, do you have any sources I can cite for my paper wheel car com bury
0 Votes
+ -
RE: Practice Safe DNS
flypig0089 22nd Sep
This is an affecting point of view on this topic. I am happy you shared your ideas and I find myself agreeing. Steel Pipe Supplier
0 Votes
+ -
RE: Practice Safe DNS
TOCCAR 25th Sep
Well welcome, hopefully you can become a vital member of the community and really help to push far ahead of google. Which Im sure the development team would love. This will of course earn you alot points too and get you on the leaders board. z d n e t t h a n k Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas.
0 Votes
+ -
RE: Practice Safe DNS
MCKNIGH 26th Sep
Thanks nice info z d n e t I really liked your current article write more..let me add you to its favorite The articles you have on zdnet s i t e are always so enjoyable to read. Good work and I bookmarked it.
0 Votes
+ -
RE: Practice Safe DNS
loriawillie 30th Sep
I recently came across your blog and have been reading along. I thought I would leave my first comment. I don???t know what to say except that I have enjoyed reading. Nice blog, I will keep visiting this blog very often.. Clubmz espy/a
0 Votes
+ -
RE: Practice Safe DNS
MEJIAHA 30th Sep
Fantastic news about the new release.I positively enjoying each little bit of it and I have you b o o k m a r k e d to check out new stuff you weblog post.Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas
0 Votes
+ -
RE: Practice Safe DNS
JACOBSONR 14th Oct
Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix