Feeds

Nominet pilots .co.uk domain security pump-up

Lays an egg, hopes chicken will ensue

Beginner's guide to SSL certificates

Dot-UK registry Nominet has started piloting a free service designed to help UK businesses boost the security of their websites' domains.

The DNSSEC Signing Service "will allow registrars to quickly and easily implement DNSSEC by relying on Nominet to manage the cryptographic signing process, management of keys and publishing records to nameservers and zone files," Nominet said.

The organisation said the hosted service will be free to use for .co.uk domains until January 2013, after which it will start charging an extra fee, probably 50p per domain per year.

DNSSEC, for Domain Name System Security Extensions, adds a hierarchy of cryptographic signatures to domain records, enabling browsers to verify that internet addresses have not been tampered with by phishing or cache poisoning attacks.

It's complex to deploy, however, requiring ongoing management of the cryptographic keys used to sign the domains. For the registrars targeted by Nominet, it could also require infrastructure upgrades.

Matt Mansell, CEO of registrar DomainMonster, said he doubts his company will sign up to Nominet's service – it likes to keep its DNS infrastructure in-house – but suggested it could be of value to smaller Nominet registrars, which comprise the majority.

"Registrars have no choice but to participate in DNSSEC," said Mansell. "It's going to be in demand, whether from a small subset of customers or from all customers remains to be seen."

He said he expects large corporate customers to be early adopters, but that others will be slow to embrace the technology, a view shared by other registrars.

While the security community by and large thinks blanket DNSSEC deployment would be a Good Thing, it currently faces a chicken and egg adoption problem.

Due it its cost and complexity, ISPs, browser makers and registrars don't want to support it unless their customers demand it, and customers currently don't know about it and aren't asking for it.

"Customers don't care about DNSSEC. They don't give a damn," Michele Neylon, managing director of the Irish registrar Blacknight said during an ICANN workshop in Singapore last month.

Out of 50,000 customers, only one had requested a signed domain, he said. Without a compelling business case, adoption is likely to be sluggish, he indicated.

Mansell said DomainMonster, which does not currently support DNSSEC, would be likely to do so as part of a premium-price package including extra security measures such as two-factor authentication.

That's a similar model to that offered by Go Daddy in the US.

VeriSign started supporting DNSSEC for .com sites this March, and to date the number of signed domains is believed to be in the low thousands.

VeriSign executives said at the ICANN workshop that 26 of its 900-plus approved registrars, including seven of the top 10, have signed at least one domain. But no registrar had more than 1,000 domains. ®

Providing a secure and efficient Helpdesk

More from The Register

next story
Brits: Google, can you scrape 60k pages from web, pleeease
Hey, c'mon Choc Factory, it's our 'right to be forgotten'
Of COURSE Stephen Elop's to blame for Nokia woes, says author
'Google did have some unique propositions for Nokia'
FCC, Google cast eye over millimetre wireless
The smaller the wave, the bigger 5G's chances of success
It's even GRIMMER up North after MEGA SKY BROADBAND OUTAGE
By 'eck! Eccles cake production thrown into jeopardy
Mobile coverage on trains really is pants
You thought it was just *insert your provider here*, but now we have numbers
Don't mess with Texas ('cos it's getting Google Fiber and you're not)
A bit late, but company says 1Gbps Austin network almost ready to compete with AT&T
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.