DNS inventor tackles flaw
The inventor of the internet’s addressing system is working towards new measures designed to plug recently revealed security flaws.


The original designer of the internet's Domain Name System (DNS) is in the UK to discuss industry responses to security flaws recently uncovered in its handling of internet protocol (IP) addresses.
The DNS vulnerability, first proven by researcher Dan Kamsinky in July 2008, highlighted how criminals can potentially redirect unsuspecting victims to fake websites, even when they type in a genuine web address.
The flaw has since been exploited to poison the servers that translate domain names into internet protocol (IP) addresses, giving malware another attack vector to infect user PCs with malicious code or intercept and edit email.
But Dr Paul Mockapetris - who is now chairman and chief scientist at IP address infrastructure software developer, Nominum - told IT PRO work to tackle the flaw was reaching well beyond the scope of patching the flaw itself.
"Our focus has moved onto additional security measures beyond DNS," said Mockapetris. "It was never meant to be the only security mechanism for naming data on the internet, but was intended for additional security measures to be added to it later."
He said the time was right for the introduction of digital signature technology, along the lines of the work being carried out by the European Network and Information Security Agency (ENISA) to implement new standards, like Domain Name System Security Extensions (DNSSEC). Several European and US Country Code Top Level Domain Registries have already adopted the use of the protocol's origin authentication capability.
"In the DNSSEC era of the future, we will look to digital signatures to distribute the reputation of a web address into the filters used by email and virus filters to remove spam and block spam sites," he added.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"And we're seeing the work of ENISA and some political movement towards making this part of the expectation of users who want to have a trusted experience on a website."
Mockapetris will give a keynote presentation in Brussels later this week at the ENISA "Resilience of Public e-Communication Networks" workshop. "Half of all DNS systems are not yet using DNSSEC," he said. "So I'll be urging that we work on interfacing such technologies to as many internet applications as possible."
Click here to read how ENISA is trying to protect European networks, and here for background on the DNS flaw.
A 25-year veteran enterprise technology expert, Miya Knights applies her deep understanding of technology gained through her journalism career to both her role as a consultant and as director at Retail Technology Magazine, which she helped shape over the past 17 years. Miya was educated at Oxford University, earning a master’s degree in English.
Her role as a journalist has seen her write for many of the leading technology publishers in the UK such as ITPro, TechWeekEurope, CIO UK, Computer Weekly, and also a number of national newspapers including The Times, Independent, and Financial Times.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
DNS loophole could allow hackers to carry out “nation-state level spying”
News Sensitive data could be accessed from corporate networks using vulnerability
By Rene Millman
-
What is DMARC and how can it improve your email security?
In-depth Protect your customers and brand rep with this email authentication protocol for domain spoofing
By Gabriella Buckner
-
Cloudflare and Apple launch privacy-focused DNS protocol
News Oblivious DNS-over-HTTPS safeguards users' browsing habits from third parties
By Sabina Weston
-
What is DNS?
In-depth We explain what DNS is, how it works, and how outages can be avoided
By Dale Walker
-
D-Link routers under siege from months-long DNS hack
News The attackers are running malicious IPs through a Google Cloud Platform virtual machine
By Connor Jones
-
SMBs warned over corrupted SOHO router risk
News Team Cymru researchers claim 300,000 routers may have had their DNS settings changed by cyber criminals.
By Caroline Donnelly
-
Will the FBI close down your online business this March?
In-depth In tackling the DNSChanger botnet, the FBI may take a load of businesses offline. Davey Winder is, unsurprisingly, anxious...
By Davey Winder
-
DNS Changer botnet smashed in major cyber crime bust
News A botnet that is thought to have earned its controllers $14 million is dismantled.
By Tom Brewster