This week at LWN: Details of the DNS flaw revealed

  2008-08-27 13:00:04
Dan Kaminsky spoke to a packed house at Black Hat on 6 August to outline the fundamental flaw he found in the Domain Name System (DNS). Contrary to his hopes, though, the flaw was discovered and publicized before his presentation. The vulnerability is interesting in its own right, but the implications of what can be done with it are staggering. In addition, the"fix" has well understood shortcomings that can still potentially be exploited to poison DNS caches. We reported on the vulnerability in early July, including Kaminsky's request that security folks not publicly speculate about the flaw. As one might guess, that request was largely ignored. When security researcher Halvar Flake published his speculation, another researcher, who was known to have the details of the flaw, publicly confirmed it, but just as quickly removed the confirmation. While it sounds a bit like a security community soap opera, it was fairly clearly caused by the attempt to contain the vulnerability information. 
  PNG Image  PNG Image  PNG Image
  Related tags  


This particular article has been collected via RSS syndication. We apologize if it's too brief.
If You wish to publish articles on LinuxStreet.net please contact us.


  Similar articles found on LinuxStreet  
ImageMajor DNS flaw: details likely to be revealed at Black Hat
ImageResearcher Spills Beans on DNS Flaw Specs
ImageSecurity Flaw Discovered in Google's G1 Mobile Phone
ImageFirefox Password Flaw Still Open?
ImageSap, mySQL patch critical database flaw
ImagePatched Flaw Could Have Broken Internet Backbone
ImageThe DNS Bug: Why You Should Care
ImageVote-Dropping Software Bug Could Gum Up Elections
ImageExploring the technical details of Nokia's N810 operating system
ImagePlans for the next Linux kernel revealed

Leave a comment on this article


Captcha

  
Check this if the code you see is not readable and resubmit the form.
(Data you entered will be preserved)



  

Comments (0)