Feeds

Nominet pilots .co.uk domain security pump-up

Lays an egg, hopes chicken will ensue

Next gen security for virtualised datacentres

Dot-UK registry Nominet has started piloting a free service designed to help UK businesses boost the security of their websites' domains.

The DNSSEC Signing Service "will allow registrars to quickly and easily implement DNSSEC by relying on Nominet to manage the cryptographic signing process, management of keys and publishing records to nameservers and zone files," Nominet said.

The organisation said the hosted service will be free to use for .co.uk domains until January 2013, after which it will start charging an extra fee, probably 50p per domain per year.

DNSSEC, for Domain Name System Security Extensions, adds a hierarchy of cryptographic signatures to domain records, enabling browsers to verify that internet addresses have not been tampered with by phishing or cache poisoning attacks.

It's complex to deploy, however, requiring ongoing management of the cryptographic keys used to sign the domains. For the registrars targeted by Nominet, it could also require infrastructure upgrades.

Matt Mansell, CEO of registrar DomainMonster, said he doubts his company will sign up to Nominet's service – it likes to keep its DNS infrastructure in-house – but suggested it could be of value to smaller Nominet registrars, which comprise the majority.

"Registrars have no choice but to participate in DNSSEC," said Mansell. "It's going to be in demand, whether from a small subset of customers or from all customers remains to be seen."

He said he expects large corporate customers to be early adopters, but that others will be slow to embrace the technology, a view shared by other registrars.

While the security community by and large thinks blanket DNSSEC deployment would be a Good Thing, it currently faces a chicken and egg adoption problem.

Due it its cost and complexity, ISPs, browser makers and registrars don't want to support it unless their customers demand it, and customers currently don't know about it and aren't asking for it.

"Customers don't care about DNSSEC. They don't give a damn," Michele Neylon, managing director of the Irish registrar Blacknight said during an ICANN workshop in Singapore last month.

Out of 50,000 customers, only one had requested a signed domain, he said. Without a compelling business case, adoption is likely to be sluggish, he indicated.

Mansell said DomainMonster, which does not currently support DNSSEC, would be likely to do so as part of a premium-price package including extra security measures such as two-factor authentication.

That's a similar model to that offered by Go Daddy in the US.

VeriSign started supporting DNSSEC for .com sites this March, and to date the number of signed domains is believed to be in the low thousands.

VeriSign executives said at the ICANN workshop that 26 of its 900-plus approved registrars, including seven of the top 10, have signed at least one domain. But no registrar had more than 1,000 domains. ®

Next gen security for virtualised datacentres

More from The Register

next story
Déjà vu: Virgin Media jacks up broadband prices
Screw copper phone lines, we're UNIQUE, bleats telco
UK fuzz want PINCODES on ALL mobile phones
Met Police calls for mandatory passwords on all new mobes
Netflix swallows yet another bitter pill, inks peering deal with TWC
Net neutrality crusader once again pays up for priority access
Fifteen zero days found in hacker router comp romp
Four routers rooted in SOHOpelessly Broken challenge
EE: STILL Blighty's best mobe network, says 'Frappucino' Moore
Fresh round of network stats fisticuffs possibly on the cards here
New Sprint CEO says he will lower axe on staff – but prices come first
'Very disruptive' new rates to be revealed next week
US TV stations bowl sueball directly at FCC's spectrum mega-sale
Broadcasters upset about coverage and cost as they shift up and down the dials
UK mobile coverage is BETTER than EVER, networks tell Ofcom
Regulator swallows this line and parrots it back out at us. What are they playing at?
What's the nature of your emergency, Vodafone?
Oh, you've dialled the wrong number for ad fibs, rules ASA
EE network whacked by 'PDP authentication failure' blunder
Carrier is 'aware' of cockup, working on a fix NOW
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.