How's that encryption coming, buddy? DNS requests routinely spied on, boffins claim Dns Check - BitCoin Wealth 247 News Blog
SUBTOTAL :

Follow Us

Dns Check
How's that encryption coming, buddy? DNS requests routinely spied on, boffins claim Dns Check

How's that encryption coming, buddy? DNS requests routinely spied on, boffins claim Dns Check

Short Description:

Product Description

How to Check DNS Settings WINDOWS $ MAC.

Who wants to read 34 pages about getting VMware Private Cloud to run on NetApp HCI?

Fast food, slow user – techie tears hair out over crashed drive-thru till

Oracle trying hard to make sure Pentagon knows Amazon ain't the only cloud around

Killer performance numbers on software and flash drives, StorONE ...

It's official: Chocolate Factory anoints Tink crypto as Google project

Mozilla changes Firefox policy from ‘do not track’ to ‘will not track’

A decade on, Apple and Google's 30% app store cut looks pretty cheesy

No do-overs! Appeals court won’t hear $8.8bn Oracle v Google rehash

Spies still butthurt they can't get at encrypted comms data

Fourth 'Fappening' celeb nude snap thief treated to 8 months in the clink

Cobalt cybercrooks phry up phishing campaign to phling at phinance orgs

Security bods: Android system broadcasts enable user tracking

We can show you where serverless works ... and where it doesn’t

Google sets Kubernetes free with $9m in its pocket for expenses

Event warning... Serverless Computing London early bird offer about to expire

Dns Check,How's that encryption coming, buddy? DNS requests routinely spied on, boffins claim

OpenWhisk, Kubeless, Dns Check , let us teach

Surprise: Sage Group head honcho has left the building

Two years later and it still sucks: Privacy Shield progress panned

Golden State passes gold-standard net neutrality bill by 58-17

US government upends critical spying case with new denial

BlackBerry KEY2 LE: Cheaper QWERTY, but not for what's inside

BlackBerry, Sony, Honor and LG flash their new phones for all to see

‘Very fine people’ rename New York as ‘Jewtropolis’ on Snapchat, Zillow

Dns Check,How's that encryption coming, buddy? DNS requests routinely spied on, boffins claim

Fruit flies use the power of the sun to help them fly in straight lines Dns Check

Space station springs a leak while astronauts are asleep, but don't panic

New Horizons eyeballs Kuiper Belt object Ultima Thule, its next flyby goal

Russian volcanoes fingered for Earth's largest mass extinction

Huawei's Alexa-powered AI Cube wants to squat in your living room too

Huawei first to preview its 7nm phone SoC – the HiSilicon Kirin 980

AI sucks at stopping online trolls spewing toxic comments

Dns Check,How's that encryption coming, buddy? DNS requests routinely spied on, boffins claim
Dns Check , declares AI biz

You can buy Cisco CEO Chuck Robbins' mansion for a cool $13m

Don't let Google dox me on Lumen Database, nameless man begs

Experimental 'insult bot' gets out of hand during unsupervised weekend

Quit that job and earn $185k... cleaning up San Francisco's notoriously crappy sidewalks

How's that encryption coming, buddy? DNS requests routinely spied on, boffins claim

Most people's DNS queries – by which browsers and other software resolve domain names into IP addresses – remain unprotected while flowing over the internet.

And that's because, you may not be surprised to know, the proposed standards to safeguard DNS traffic – such as

– have yet to be fully baked and aren't yet widely adopted.

DNSSEC, for one, aims to prevent miscreants tampering with intercepted domain-name lookups by digital signing the answers – making any forgeries obvious to software. DNS-over-TLS and DNS-over-HTTPS aim to do this, too, and encrypt the queries so eavesdroppers on the network can't snoop on what sites you're visiting.

Without these safeguards in wide (or any) use, DNS traffic remains unencrypted and unauthenticated, meaning they can be potentially spied on and meddled with to redirect people to malicious websites masquerading as legit sites.

Researchers from universities in China and the US recently decided to check whether or not this is actually happening, and found that traffic interception a reality for a small but significant portion of DNS queries – 0.66 per cent of DNS requests over TCP – across a global sample of residential and cellular IP addresses.

The boffins – Baojun Liu, Chaoyi Lu, Haixin Duan, and Ying Liu from Tsinghua University in China; Zhou Li and Shuang Hao from the University of Texas at Dallas; and Min Yang from Fudan University in China – describe the results of their inquiry in a paper presented at this week's USENIX Security Symposium.

, "Who Is Answering My Queries: Understanding and Characterizing Interception of the DNS Resolution Path," describes how the researchers set up a system to measure DNS interception across 148,478 residential and cellular IP addresses around the world.

Internet users may choose their own DNS resolvers, by manually pointing their applications and operating systems at, say, Google Public DNS (8.8.8.8) or Cloudflare (1.1.1.1). Usually, however, people accept whatever DNS resolver the network or their ISP automatically provides.

If an intermediary intercepts a DNS request, that isn't necessarily nefarious, but it could lead to undesirable consequences. At the very least, it deprives those using the internet of choice and privacy.

The researchers looked for providers spoofing the IP addresses of users' specified DNS resolvers to intercept DNS traffic covertly. They designed their study to focus on registered domains and to omit sensitive keywords, to avoid the influence of content censorship mechanisms.

They found DNS query interception in 259 of the 3,047 service provider AS collections tested, or 8.5 per cent. (The research paper uses the term "ASes," which stands for

Dns Check,How's that encryption coming, buddy? DNS requests routinely spied on, boffins claim
Dns Check , networking terminology for a collection of IP address blocks assigned to ISPs and other organizations.)

In terms of packets sent to Google Public DNS, 27.9 per cent of UDP-based packets were intercepted, compared to about 7.3 per cent of data sent over TCP, it is claimed. (Most of DNS requests are sent over UDP and intercepting UDP traffic is easier from a technical perspective, the researchers explain.)

Google DNS appears to be particularly appealing as an interception target for service providers. "We also discover 82 ASes are intercepting more than 90 per cent of DNS traffic sent to Google Public DNS," the researchers observed in their paper.

DNS ad-hocracy in peril as ICANN advisors mull root server shakeup

Comcast Cable Communications in the US is cited as the controller of AS7922, which was found intercepting a small portion of Google Public DNS traffic.

"Among our 13,466 DNS requests sent from this AS to Google DNS, 72 (0.53 per cent) are redirected, with alternative resolvers outside Google actually contacting our authoritative nameservers," the paper stated.

The researchers speculate that on-path devices handling interception are only deployed in a limited number of sub-networks for this AS and allow that it's possible a Comcast customer rather than the company itself deployed these devices.

Providers in China were cited as conducting the most interception. China Mobile, for example, gets singled out for alleged involvement in DNS tampering for profit.

"As an example, 8 responses from Google Public DNS are tampered in AS9808 (Guangdong Mobile), pointing to a web portal which promotes an APP of China Mobile," the paper stated.

, Nick Sullivan, head of cryptography at Cloudflare, said that the lack of encryption and authentication in DNS is widely seen as one of the internet's biggest unpatched bugs.

"This bug is known to be exploited by networks for various reasons, but the extent to which networks are intercepting DNS queries is not well known," he said. "This paper is significant because it is one of the most widespread measurement studies done on the prevalence of DNS interception is on the internet."

Sullivan said it was surprising to see just how high the rate of interception is in some instances.

"The researchers found that interception rates for DNS queries directed to popular public DNS resolvers are high overall, and in some networks as high as 100 per cent," he said. "Not all the intercepted DNS queries were modified or recorded, but they could be, which has huge implications for privacy and security online. These findings accelerate the need to patch this bug by transitioning DNS from an unencrypted protocol to one that is protected by strong encryption and authentication technologies." ®

No need to code your webpage yourself, says Microsoft – draw it and our AI will do the rest

Dns Check,How's that encryption coming, buddy? DNS requests routinely spied on, boffins claim

VMware 'pressured' hotel to shut down tech event close to VMworld,

VMware 'pressured' hotel to shut down tech event close to VMworld Dns Check

Hackers faked Cosmos backend to hoodwink bank out of $13.5m

Google sets Kubernetes free with $9m in its pocket for expenses

HTC U12 Life: Notchless, reasonably priced and proper buttons? Oh joy

Flash Storage: Growth, Acceptance, and the Rise of NVMe

At a high level, solid-state storage continues to experience high levels of adoption while delivering a myriad of technical, operational, and financial benefits.

Ransomware is Increasing the Risks and Impact to Organizations

Ransomware is gaining traction in the criminal community.

AWS HPC solutions leverage the power of the latest Intel technologies and flexible configuration options to help companies across nearly every industry achieve their HPC results.

The Spectrum Data Protection Portfolio from IBM Is a ‘Must See’

Spectrum CDM is a new addition to the IBM Spectrum data protection portfolio. It is designed to enable non-protectionrelated use cases for secondary data.

Batten down the ports: Linux networking bug SegmentSmack could remotely crash systems

HPE to gobble software defined data fabric networking startup

Beware VMware! Nutanix sprays all over Virtzilla's networking territory

VMware's GM for networking and security jumps to Google

Veteran Jeff Jennings to get the band back together with VMware founder Diane Greene

This is how Azure just hit 30Gbps of throughput – and how clouds are being built now

HPE primes storage networking pipes for NVMe-oF data deluge

FC director module and switch cranked up to 32Gbit/s

Cisco's 'Hybrid Information-Centric Networking' gets a workout at Verizon

The ten-year odyssey from concept to product continues

Linux Foundation puts all its networking eggs in one basket

‘LF Networking Fund' is like the Cloud Native Computing Foundation, but for SDN

Get The Register's Headlines in your inbox daily - quick signup!

- Independent news and views for the tech community. Part of Situation Publishing

Join our daily or weekly newsletters, subscribe to a specific section or set

0 Reviews:

Post Your Review