Recent Posts
- ICANN staffing up for next new gTLD round
- Radix premium revenue hits $3.8 million in first half
- GoDaddy shutters Twitter accounts after MMX deal
- nickel.com sells for a hell of a lot more than a nickel
- German motoring club dot-brand crashes out
- Verisign to crack down on Chinese domains
- Whois Disclosure System likely over a year away
- Belgium slashes its ICANN funding in “mission creep” protest
- Diversity takes a hit as NomCom replaces two ICANN directors with newcomers
- RDNH loser files second appeal
- Group crowdfunding crypto to apply to ICANN for blockchain gTLD
- Buyer “phasing out” domain “bought for $2.2 million”
- ShortDot drops premium fees on millions of domains
- Tucows’ domains business stagnates again in Q2
- Malaysia relaxes travel restrictions ahead of ICANN 75
- GMO to sell Unstoppable’s crypto domains
- More rules, but cozier ICANN 75 expected
- India offers dollar regs to celebrate independence
- auDA updates on 2LD .au sales
- At $15 million, nfts.com becomes second-biggest domain sale ever
- Now Nokia scraps a dot-brand
- InternetNZ appoints new CEO
- Looks like XYZ bought another gTLD
- Bugatti dumps dot-brand under new owners
- In pictures: from tuk-tuks to cheese wheels, every ICANN national stereotype 2016-2022
- Did ICANN pay for most meeting attendees to show up in The Hague?
- Verisign announces ANOTHER price increase as regs slide
- CentralNic signs Greenland deal
- Early “dot-brand” adopter wants to scrap its gTLD
- Verisign to mandate 2FA for .com registrars
- Unstoppable valued at over $1 billion after huge new investment
- ICANN staffer to referee closed generics fight
- Covid vaccine maker takes RDNH loss to ICANN board
- Guy asks ICANN to shut down prostitution site
- No smoking! Rules laid down as .kids reveals launch dates
- Nominet sold security unit for a dollar after blowing $23.5 million
- CentralNic revenue almost doubles
- Feds warn of Covid risk from “dark” Whois
- ICANN names NomCom chairs
- ICANN’s top brass get pay raises
- New gTLD prep work delayed until December
- New gTLDs WILL be delayed by Whois work
- ICANN backtracks on legal waiver for ICANN 75
- Community tells ICANN to walk and chew gum at the same time
- Five things I learned from UK prime minister candidates’ domain names
- Universal unacceptance? ICANN lets XYZ dump languages from UNR gTLDs
- ICANN terminates these three deadbeat registrars
- .xyz kicks France out of the top 10 TLDs — Verisign
- ICANN puts blockchain on the agenda for good
- New gTLD in trouble as largest registrar gets suspended
- ICANN picks comms firm for new gTLDs outreach
- Donuts goes with bland, forgettable, for new company name [rant]
- Broker says it will sue after DNS abuse sting operation
- Unstoppable targets another city gTLD with free domains
- Dynadot takes down its own web site after apparent breach
- The slow crawl to closed generics at ICANN 74
- Controversial Chinese firm among two newly revealed UNR gTLD buyers
- Over 900 people show up for ICANN 74
- Verisign and Afilias spar over .web delays
- Hamburg selected for next year’s ICANN AGM
- Amazon governments not playing ball with Amazon’s .amazon
- High fives, or elbows only? ICANN 74 intros traffic light system for socializing
- NetBeacon goes live for DNS abuse reporting
- As registration closes, many ICANN 74 sessions at bursting point
- Belarusian domains to change hands
- As GoDaddy shutters URL shortener, could x.co come back on the market?
- Nominet opens directorship nominations
- GoDaddy acquires two education-themed gTLDs
- Crypto domains: a feminist issue?
- Turkey name change could free up gTLD string
- Porkbun offering free .gay domains for Pride month
- DNSAI to name most-abused registries, registrars
- NameSilo profitable in Q1
- Meds regulator won’t say why it gets domains suspended
- Porkbun hits a million domains
- Porn names to feature at NamesCon Global
- Pizza company suffers from penisland syndrome
- Seat reservations and waiting lists on the cards for ICANN 74
- New gTLDs or Whois access? What’s more important?
- Domain sales down even as revenue booms at CentralNic
- ICANN kicks the can on .web yet again
- ALAC’s brutal takedown of that “aggressive” ICANN 74 coronavirus waiver
- .link gTLD buyer revealed
- After 10 months, ICANN board “promptly” publishes its own minutes
- China yanks Daily Stormer domain after Buffalo mass shooting
- Fewer domain companies closing down than expected
- ICANN highlights “not getting things done” risk
- Another single-TLD brand protection service planned
- Dot Hip Hop slashes prices 80% in relaunch
- Three gTLDs to lose Donuts trademark protection
- Tucows to reanimate Tucows brand as sales flatten
- Blockchain domains pose “significant risks” to internet, says ICANN
- Russian registry hit with second breach notice after downtime
- Two countries could lose registrar competition after breach notices
- .tattoo — another UNR gTLD auction winner emerges
- Neustar now linked to scandal in the Catholic church
- SSAD: Whois privacy-busting white elephant to be shelved
- ICANN reports shocking increase in pandemic scams
- Kaufmann selected for ICANN board
- Secondary market fluffs GoDaddy amid slowdown concerns
- Washington DC picked for ICANN 77
- UDRP suspended in Ukraine
- Gee, thanks. auDA cuts price of .au names by five cents
- ICANN salary porn: 2021 edition
- A sign of things to come? Verisign slashes outlook in post-pandemic slowdown
- UDRP comments reveal shocking lack of trust in ICANN process
- CentralNic sees 51% growth in Q1
- Ukraine won’t delete domains until war is over
- Covid surge scuppers ICANN LA meetings
- Vox Pop defends its favorite cybersquatter
- ICANN picks recipient of $1 million Ukraine aid
- More friction over closed generics
- ICANN’s Covid-19 waiver formally appealed
- GoDaddy and XYZ sign away rights after UNR’s crypto gambit
- Verisign wipes free TLDs from the world stats
- ICANN picks 28 registries for abuse audit
- TMCH turning off some brand-blocking services
- Bye-bye Alice’s Registry
- .kids goes live, plans to launch this year
- ICANN suggests its Covid waiver may be worthless
- Domain sales exempt from US sanctions on Russia
- African Union can’t register .africa domain
- Microsoft seizes domains Russia was using to attack Ukraine
- Blacknight objects to ICANN 74 Covid waiver
- DNS Abuse Institute names free tool NetBeacon, promises launch soon
Reports: .gov fails due to DNSSEC error
The .gov top-level domain suffered a DNSSEC problem today and was unavailable to some internet users, according to reports.
According to mailing lists and the SANS Internet Storm Center, it appeared that .gov rolled one of its DNSSEC keys without telling the root zone about the update.
This meant that anyone whose DNS servers do strict DNSSEC validation — a relatively small number of networks — would have been unable to access .gov web sites, email and other resources.
As a matter of policy, all second-level .gov domains have to be DNSSEC-signed.
The problem was corrected quite quickly — looks like within an hour or two — but as SANS noted, caching issues may prolong the impact.
Both .gov and the root zone are managed by Verisign, which isn’t on the best of terms with the US government at the moment.
Related posts (automatically generated):
Who runs the internet? An ICANN 49 primer
Verisign confirms .gov downtime, blames algorithm
ICANN to flip the secret key to the internet
It is ironic that the very initiatives that are supposed to help security have introduced errors into the system, while those that are identified as likely to produce errors — for instance, the introduction of new gTLDs, in the context of name collision issues — have produced none.
The DNSSEC problem — that of needing a chain of trust to make it effective — has been frequently raised by registrars and others. This shouldn’t have been a surprise to anyone.
What is does show is that *if* there is a problem, it can be addressed quickly and without major repercussions. That is true of DNSSEC or of name collision. The ICANN staff obsession with risk — that is, in preventing *all* risk, rather than assessing its probability, severity, and ease of mitigation — seems to be limited to those areas where the ICANN corporation faces some liability. In contrast, ICANN appears to be blandly unconcerned in areas where they could have done something (I’m thinking of better planning and communication rolling out DNSSEC), but where they unlikely to be identified as a culprit.
ICANN needs some real risk assessment capabilities, instead of relying on risk assessment from a legal perspective, which typically is satisfied only with 0% risk — which is not a real-world position to take, especially in a field as fast moving, and as filled with so many unknowns as the Internet. They would then be able to communicate honestly to the world as to why they take certain positions, instead of pointing helplessly at nebulous unknowns. If ICANN *really* wants to secure the security and stability of Internet, it’s going to need to take risks — calculated ones. There is no zero-risk scenario where ICANN is effective.
Antony
Problem started somewhere between 2013-08-14 08:51:41 UTC and 2013-08-14 12:26:40 UTC. It persisted at least until 2013-08-14 13:49:03 UTC.
.gov DNSSEC snapshots:
http://dnsviz.net/d/gov/UgtFHg/dnssec/
http://dnsviz.net/d/gov/Ugt3gQ/dnssec/
http://dnsviz.net/d/gov/UguK0A/dnssec/
http://dnsviz.net/d/gov/UguRGg/dnssec/
Everything involves risk. Crossing the street involves risk. We humans are constantly assessing the risk vs the benefit.
Shall I cross this slightly trafficked street (very small probability but risk of very bad event happening – death) to make my meeting on time (some benefit)?
We have to assess not only 1) the risk (chance of it happening) but 2) the magnitude of the potential harm, and 3) the magnitude of the benefit.
In the DNSSEC case, the probability of a negative event happening is non-zero (as this event shows), the magnitude of the bad event is medium and the benefit is medium.
The benefits to DNSSEC outweigh the risks. But make no mistake, there are risks to implementing DNSSEC. In fact, comparing DNSSEC and new TLDs, the change DNSSEC imposed on the DNS is much much larger than the change that new TLDs impose on the DNS.
Therefore the risks to implementing DNSSEC is much larger than the risk of new TLDs.
Comparing the benefits of the two, there are net benefits that DNSSEC brings to the world (more security), but the net benefits that new TLDs bring are even larger (competition, innovation, etc).
So we, the ICANN community, implemented DNSSEC even thought the risks are more (more change to the DNS) and the benefits are less than new TLDs.
“Name collisions” have a non-zero probability of happening, true (they happen every day in .com for example). But the consequence of a “name collision” is small (in my opinion very small, which is why we allow them to happen in .com) and the benefits brought by new TLDs, such as .home and .corp are big.
The v6 and DNSSEC evangelicals successfully added their pet causes as mandatory-to-implement by new gTLD operators, even if (a) located where native v6 is not available and/or (b) for use models lacking valuable targets (e.g., community-based applications).
These new operators are compelled to waste resources on v4 exhaustion & security theater, and are likely to make more mistakes than experienced, highly capitalized operators.
I differ from Antony and Paul, who offer specific comparisons of argued risk, and offer, as a general error of staff the insertion of the v6 and DNSSEC requirements for new registry operators, for which little value at start-up (years 1-5) can be offered.
There is a chicken-and-egg situation happening with both IPv6 and DNSSEC that requires the industry to adopt those even its numbers would indicate otherwise. I think ICANN was right in requiring those to be deployed, but it could have lessened such burden by indicating that IPv6 tunneling was OK (it’s possible to get tunneled-IPv6 for free) and providing DNSSEC capacity building as another avenue of applicant support.