Re: SA Internet security issues
Daniel Schroder <[email protected]> Tue, 4 Jul 2017 12:19:13 +0200
| Newsgroups | gmane.org.operators.ioz |
|---|---|
| Message-ID | <CAMvWrAti6o+Tu5FacCz-KOijY0rj5+-5p-SXB9dw3TL=2JmSxg@mail.gmail.com> |
Just want to point out the obvious, DNSEC helps finding sources of DNS
spoofing, which is often used by high tier ISPs to redirect traffic, or on
compromised hardware. It's useful to have a DNS server that chases DNS
queries, and have some form of trusting the reply, if you do your online
banking, from a co.za second level domain, you can't do the query via
dnsec, so your only other option is using other open dns servers, however
it's easy to spoof or hijack queries from there as well.
Also I have a feeling Ipv6 is also going to become a problem. Especially in
terms of routing, the primaries for za do not all route locally, so dns
queries can sometimes take a while to answer, and again you are not sure of
all the networks it transverses. DNSEC queries can take a while. (eg
disa.tenet.ac.za)
Dnsec does not solve all problems, but it does make things easier if you
need security on a network you admin. DNS is step one.
Below is queries on an unbound dns server with no query forwarding, with
the default trust anchor.
--Daniel
Ps. I've given up on all linuxes crap, gone back to FreeBSD.
drill -TD za ns
Works
drill -TD web.za ns
Works
drill -TD www.web.za
Does'nt
drill -TD co.za
[T] Existence denied: co.za. DS
successful answer:
Key is now trusted!
[T] web.za. 3600 IN DS 52115 8 2
71c7a043c3852da4af98fbd62d4c0ef8cd0420c19d9cc1afa5ad8e29a1417b90
;; Domain: web.za.
[T] web.za. 3600 IN DNSKEY 256 3 8 ;{id = 14499 (zsk), size = 1024b}
web.za. 3600 IN DNSKEY 257 3 8 ;{id = 52115 (ksk), size = 2048b}
[T] web.za. 86400 IN A 206.223.136.163
;;[S] self sig OK; [B] bogus; [T] trusted
On Mon, Jul 3, 2017 at 8:18 PM, Nishal Goburdhan <[email protected]>
wrote:
> On 04 Jun 2017, at 09:04, ox <[email protected]> wrote:
>
> > For myself, whether my ISP uses dnssec would (and should) be a business
> > factor - a competitive advantage, etc.
>
> what competitive advantage is there, in ensuring that you return the
> correct answer to a question asked?
>
>
> > Technically, DNSSEC is no silver bullet, but it will improve Internet
> security for
> > the small guy, the guy at home and the small business (and for you)
>
> so, there are two parts here; first, the signing, and then, validation.
> while you’re waiting for to get your zone signed, are you validating?
> does your ISP validate? have you asked them to?
>
> here’s some useful data : https://stats.labs.apnic.net/dnssec/ZA
>
> —n.
> _______________________________________________
> IOZ mailing list
> [email protected]
> http://lists.internet.org.za/mailman/listinfo/ioz
>
_______________________________________________
IOZ mailing list
[email protected]
http://lists.internet.org.za/mailman/listinfo/ioz