LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Non-*NIX Forums > General
User Name
Password
General This forum is for non-technical general discussion which can include both Linux and non-Linux topics. Have fun!

Notices


Reply
  Search this Thread
Old 04-05-2007, 08:09 PM   #1
Furlinastis
Member
 
Registered: Dec 2004
Location: Ball of Confusion
Distribution: Artix,Arch,Slackware,Bluewhite64
Posts: 261

Rep: Reputation: 40
DHS wants key to DNS root zone


http://www.dailykos.com/story/2007/3/31/1828/16663
http://www.heise.de/english/newsticker/news/87655

"The key will play an important role in the new DNSSec security extension, because it will make spoofing IP-addresses impossible. By forcing the IANA [Internet Assigned Numbers Authority] to hand out a copy of the master key, the US government will be the only institution that is able to spoof IP addresses and be able to break into computers connected to the Internet without much effort."

I'm a little confused as to what exactly this implies. Does this mean that if the Department of Homeland Security actually gets its grubby little hands on this "master key" they will have the ability to hack into any website they feel dissents from their policies and essentially wipe the site off the face of the internet?
 
Old 04-05-2007, 09:25 PM   #2
Crito
Senior Member
 
Registered: Nov 2003
Location: Knoxville, TN
Distribution: Kubuntu 9.04
Posts: 1,168

Rep: Reputation: 53
It means only they can spoof IP addys. And that's why no one will implement DNSSec.
 
Old 04-05-2007, 10:09 PM   #3
Furlinastis
Member
 
Registered: Dec 2004
Location: Ball of Confusion
Distribution: Artix,Arch,Slackware,Bluewhite64
Posts: 261

Original Poster
Rep: Reputation: 40
OH, so they're not even implementing it? Guess I got all hot and bothered for nothing then. Lol... reading it over, the word, "new" didn't quite register.
 
Old 04-05-2007, 11:42 PM   #4
Crito
Senior Member
 
Registered: Nov 2003
Location: Knoxville, TN
Distribution: Kubuntu 9.04
Posts: 1,168

Rep: Reputation: 53
No, they are implementing it. It's not just a new DNS server/service though. It's a complete change to the DNS protocol itself. As such they're going to need other people's cooperation to get it implemented in a timely manner. And that just doesn't appear to be happening outside the USA, where many anycast root servers reside.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
DNS Zone x-fer - From one zone to another / Debian 3.1 + BIND9 kenwoodgt Linux - Software 0 11-01-2006 10:28 AM
BIND DNS -- Zone inescapeableus Linux - Networking 17 10-08-2006 03:46 PM
Guide to DNS Zone tsaravan Linux - Networking 1 08-29-2006 09:50 AM
dns zone transfers how to lord_zoo Linux - Networking 2 12-11-2005 02:28 PM
DNS, authority zone mrpc_cambodia Red Hat 3 01-18-2005 09:19 PM

LinuxQuestions.org > Forums > Non-*NIX Forums > General

All times are GMT -5. The time now is 03:50 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration