Tighter security coming for .org names
Network World - The Public Interest Registry will add an extra layer of security known as DNS Security Extensions (DNSSEC) to the .org domain in June -- a move that will protect millions of non-profit organizations and their donors from hacking attacks known as cache poisoning.
(Comcast launches first public U.S. trial of advanced DNS security)
In a cache poisoning attack, traffic is redirected from a legitimate Web site to a fake one without the Web site operator or end user knowing. Cache poisoning attacks are the result of a serious flaw in the DNS that was disclosed by security researcher Dan Kaminsky in 2008.
DNSSEC is an emerging Internet standard that prevents cache poisoning attacks by allowing Web sites to verify their domain names and corresponding IP addresses using digital signatures and public-key encryption
The Public Interest Registry said today that it will support DNSSEC for first and second-level .org domain names. With nearly 8 million registered domain names, the .org domain is one of the Internet's largest generic top-level domains to deploy DNSSEC.
"When we first announced last year the signing of our zone, we showed that DNSSEC was not a utopian vision, but that it was needed for the future of the Internet," says Alexa Raad, CEO of The Public Interest Registry. "Everything runs on DNS. If you believe that there are going to continue to be more and more applications that run on DNS, then you have to think about DNSSEC."
Raad expects operators of .org Web sites to rapidly deploy DNSSEC.
"There are credit unions that use .org ... and there are nonprofit organizations that are in fundraising and have been targets for attacks, some of them quite public," Raad says. DNSSEC "will allow our customers who require security to have it."
The Public Interest Registry and its back-end services provider Afilias have been testing DNSSEC since last summer. They are working with 10 registrars to sign DNS queries. Several high-profile Web sites including www.ietf.org run by the Internet Engineering Task Force and www.isoc.org run by the Internet Society are signing their domains as part of the .org domain's ongoing DNSSEC trial.
"There have not been any significant problems," says Jim Galvin, director of strategic partnerships and technical standards with Afilias. "Testing has done for us what it's supposed to do. We've been engaging with all of the parties in terms of deploying DNSSEC and ensuring that it's ready for the broader community."
DNSSEC is being deployed across the Internet infrastructure, from the root servers at the top of the DNS hierarchy to the servers that run .org and other top-level domains, down to the servers that cache content for individual Web sites. All of these pieces must be in place for DNSSEC to protect an individual Web site.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts