nanog mailing list archives
Re: A Deep Dive on the Recent Widespread DNS Hijacking
From: "John Levine" <johnl () iecc com>
Date: 24 Feb 2019 23:29:45 -0500
In article <B7DF0851-C5A3-4366-8ADF-501D1418F9E1 () nist gov> you write:
You are right, if you can compromise a registrar that permits DNSSEC to be disabled (without notification/confirmation to POCs etc), then you only have a limited period (max of DS TTL) of protection for those resolvers that have already cached the DS.
As far as I can tell, that's roughly all of them. If you have the credentials to log in and change the NS, you can change or remove the DS, too. As someone else noted, the only reason DNSSEC made any difference was that the script kiddies sometimes forgot to turn it off or install their own DS. If you are actually interested in preventing this stuff, 2FA will be orders of magnitude more effective than messing with DNSSEC. There are certainly threats that DNSSEC addresses, but getting your registrar account pwned isn't one of them. R's, John
Current thread:
- RE: A Deep Dive on the Recent Widespread DNS Hijacking Montgomery, Douglas (Fed) via NANOG (Feb 24)
- RE: A Deep Dive on the Recent Widespread DNS Hijacking Keith Medcalf (Feb 24)
- Re: A Deep Dive on the Recent Widespread DNS Hijacking Montgomery, Douglas (Fed) (Feb 24)
- Re: A Deep Dive on the Recent Widespread DNS Hijacking Ca By (Feb 24)
- Re: A Deep Dive on the Recent Widespread DNS Hijacking Mark Andrews (Feb 24)
- Re: A Deep Dive on the Recent Widespread DNS Hijacking John Levine (Feb 24)
- Re: A Deep Dive on the Recent Widespread DNS Hijacking Töma Gavrichenkov (Feb 24)
- Re: A Deep Dive on the Recent Widespread DNS Hijacking Paul Ebersman (Feb 25)
- Re: A Deep Dive on the Recent Widespread DNS Hijacking Paul Ebersman (Feb 25)
- Re: A Deep Dive on the Recent Widespread DNS Hijacking Sander Steffann (Feb 25)
- Re: A Deep Dive on the Recent Widespread DNS Hijacking Owen DeLong (Feb 25)
- Re: A Deep Dive on the Recent Widespread DNS Hijacking Eric Kuhnke (Feb 25)
- Re: A Deep Dive on the Recent Widespread DNS Hijacking Paul Ebersman (Feb 25)
- Re: A Deep Dive on the Recent Widespread DNS Hijacking valdis . kletnieks (Feb 25)
- Re: A Deep Dive on the Recent Widespread DNS Hijacking Paul Ebersman (Feb 25)
- Re: A Deep Dive on the Recent Widespread DNS Hijacking valdis . kletnieks (Feb 25)
- Re: A Deep Dive on the Recent Widespread DNS Hijacking Montgomery, Douglas (Fed) (Feb 24)
- RE: A Deep Dive on the Recent Widespread DNS Hijacking Keith Medcalf (Feb 24)
