5 years after major DNS flaw is discovered, few US companies have deployed long-term fix

By , Network World |  Security, DNS flaw, DNSSEC

  • Secure64 found that 65% of the 359 agencies it tested were signing their domains and that 80% of these organizations had fully deployed DNSSEC standards.
  • Similarly, NIST found that 76% of the 1,396 U.S. government domains tested had operational DNSSEC, and another 5% were in progress of deploying this standard.

"We've helped government agencies deploy DNSSEC in a matter of weeks, once the decision of vendor is made," Beckett says. "I'm hopeful that at least within the banking sector some of the major banks will cross this threshold in 2013 and will have deployed DNSSEC by January 2014."

Comcast says it has experienced few technical problems with its DNSSEC deployment, which covers all of its residential customers.

"Within our online forums and other public places and in the DNSSEC community, we've received very positive reviews of our DNSSEC service and the lack of issues associated with it," Griffiths says. "It's been well received within the DNSSEC community and our customer base."

However, Griffiths notes that while Comcast's residential customers are protected by DNSSEC, few of its small or midsize business customers are asking for the add-on security measure.

"We're certainly investigating products and services to support that," Griffiths says. "We want to roll out something that ... adds automation to help them roll this out themselves, so they are getting the benefit of using our DNS cache resolvers but are signing their own domains."

Griffiths says he sees momentum for DNSSEC among top-level domains; for example, Canada in January began signing its .ca top-level domain. But he expects it to take several years before DNSSEC is widely deployed by U.S. corporations.

"I absolutely expect banks, other companies and ISPs to take advantage of it," Griffiths says. "It takes time and planning, and I would expect it to roll out slowly. ... We've proven that DNSSEC can be rolled out at scale, and we hope people will follow our lead."

[ MORE: 6 signs that the U.S. is overtaking the world at IPv6 ]

One barrier to DNSSEC deployment is that it is extremely difficult for content delivery networks (CDNs) to sign data dynamically as is required by the standard. That's why popular CDNs such as Akamai and Limelight haven't fully deployed DNSSEC yet.


Originally published on Network World |  Click here to read the original story.
Join us:
Facebook

Twitter

Pinterest

Tumblr

LinkedIn

Google+

Answers - Powered by ITworld

ITworld Answers helps you solve problems and share expertise. Ask a question or take a crack at answering the new questions below.

Join us:
Facebook

Twitter

Pinterest

Tumblr

LinkedIn

Google+

Ask a Question