Technology Review - Published By MIT
Advertisement

Internet Security Hole Revealed

Continued from page 1

By Erica Naone

Friday, August 08, 2008

smaller text tool iconmedium text tool iconlarger text tool icon

The problem for the attacker is that the false answer needs to carry the correct authenticating transaction ID--and there are 65,000 possibilities. Moreover, once Facebook's server gets an answer, it will store the domain name server's numerical address for a certain period of time, perhaps a day. The flaw that Kaminsky discovered, however, allows the attacker to trigger requests for the domain name server's address as many times as he wants. If the attacker includes a random transaction ID with each of his false responses, he'll eventually luck upon the correct one. In practice, Kaminsky says, it takes the attacker's computer about 10 seconds to fool a server into accepting its false answer.

Fooling Facebook's server would mean that the attacker could intercept messages that Facebook intended to send to users, which could allow him to get control of large numbers of accounts. The attacker could use similar techniques to intercept e-mail from other sources, or to get forged security certificates that could be used to more convincingly impersonate banking sites. "We haven't had a bug like this in a decade," Kaminsky says.

Because the attack takes advantage of an extremely common Internet transaction, the flaw is difficult to repair. "If you destroy this behavior, you destroy [the domain name system], and therefore you destroy the way the Internet works," Kaminsky says. But the temporary fix that's being distributed will keep most people safe for now. That fix helps by adding an additional random number that gives the attacker a much smaller chance of being able to guess correctly and pull off the impersonation. In the past month, he says, more than 120 million broadband consumers have been protected by patches, as have 70 percent of Fortune 500 companies. "If they're big and vulnerable, and I thought so, I've contacted them and raised holy hell," Kaminsky says. Facebook has applied the patch, as have Apple, LinkedIn, MySpace, Google, Yahoo, and others.

But it's still uncertain how to put a long-term solution in place. Kaminsky calls the current patch a "stopgap," which he hopes will hold off attackers while the security community seeks a more permanent fix. Jerry Dixon, director of analysis for Team Cymru and former executive director of the National Cyber Security Division and US-CERT, says that "longer-term fixes will take a lot of effort." Changes to the domain name system must be made cautiously, he says, adding, "It's the equivalent of doing heart surgery." It would be easy for a fix to cause unintended problems to the system. In the meantime, Dixon says, "if I were asked by the White House to assess this, I would say it's a bad vulnerability. People need to patch this."


Comments

  • Internet Security Revealed
    We at Silacon believe we have an answer or something that would lead to a solution:  NSA and MIT alum, Dr. Roger R. Schell (schellr@alum.mit.edu). He is in the private sector now so can consult or his firm of which he is CEO can help.

    This is worrisome thing as all of perceived enemies will exploit the flaw immediately.  Somewhere out there is a kid with a 180 IQ that is mad the USA or the Google's of the internet and very dangerous.


    Charles G. Nutter, CEO Silacon Corporation
    Rate this comment: 12345

    Silacon
    08/08/2008
    Posts:46
    Avg Rating:
    2/5
  • Get a clue
    I actually find all these “its worse than we thought” articles amusing. DNS is the foundation of the Internet, a vulnerability in it will affect everything build on top of it. Did they just realize that a house would not stand without a foundation? Get a clue.
    Rate this comment: 12345

    zig158
    08/08/2008
    Posts:64
    Avg Rating:
    4/5
    • Re: Get a clue
      It is easy to say 'get a clue'. How about constructive input for a change of heart. Bartering and cash look good after this. Drum signals worked in Africa thousands of years ago. Sideline hecklers are everywhere.  Try to be different.
      Rate this comment: 12345

      Silacon
      08/08/2008
      Posts:46
      Avg Rating:
      2/5
    • Re: Get a clue
      When someone with the reputation and stature in the security community such as Dan Kaminsky speaks, I highly recommend you listen. That this could be a serious problem is proven by the actions taken by the major players to close the hole.
      Rate this comment: 12345

      jal64
      08/08/2008
      Posts:7
      Avg Rating:
      3/5
  • The curse of In-band signalling
    The 'root cause' of all these 'security holes' lies in the fact that all computers using TCP/IP send signalling packets along with end user data packets across the same logical network.

    Until people realize the solution is to adopt a divided architecture (signalling packets run on separate channels from end user packets) the world will always be waiting for the next 'security hole' to be discovered.  I'm surprised it took this long to catch the DNS problem.  Others are coming, too.

    For an alternate approach to signalling security, look at how the ITU uses SS7.
    Rate this comment: 12345

    wjhalverson1...
    08/08/2008
    Posts:1
    Avg Rating:
    5/5

Log In

Forgot your password?     Register »
Advertisement

Videos

Making 3D Maps on the Move
Technology Review November/December 2009

Current Issue

Natural Gas Changes the Energy Map
The United States has vast supplies of this cleaner fossil fuel. But how should we use it?
Featured Content
Sponsored by:
White Papers

Twelve ways to reduce costs with SQL Server 2008
Find out how to reduce costs and get more efficient

Download

Total Economic Impact of SQL Server 2008 Upgrade
Forrester reports on increasing productivity and management capabilities

Download 

Achieving Cost and Resource Savings with UC
How Office Communications Server R2 and Exchange Server can make your business smarter and more efficient

Download 

The Compelling Case for Conferencing
Read how you can improve workload support and find IT efficiencies

Download

How Windows Server 2008 R2 Helps Optimize IT and Save you Money
Read how you can improve workload support and find IT efficiencies

Download

Windows Server 2008 R2 Hyper-V Live Migration
See how Windows Server 2008 R2 and Hyper-V enable virtualization and Live Migration

Download
Advertisement
Subscribe to Technology Review's daily e-mail update. Enter your e-mail address

TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology © 2009 Technology Review. All Rights Reserved.