Technology: The business and culture of our digital lives, from the L.A. Times

| Main |

Internet security flaw described as worst in 10 years

2:43 PM, August 6, 2008

Black_hatAcclaimed Internet security researcher Dan Kaminsky detailed a flaw in the current architecture of the Internet today, firing the starting gun for a race between hackers who can now take advantage of the vulnerability and the big companies who have yet to patch their systems.

Speaking to hundreds of technology security professionals and enthusiasts at the annual Black Hat conference in Las Vegas, Kaminsky said that a majority of the Fortune 500 have protected their machines with a series of fixes developed in secret since March.

Kaminsky coordinated an industry-wide effort that brought out patches from Microsoft, Cisco, Sun Microsystems and other major technology vendors, and customers began applying them after he issued a public warning a month ago.

The hole lies in the Domain Name System, which steers Internet users seeking a site by title, such as www.google.com, to a numerical address. Kaminsky showed today how hackers could corrupt the process, taking users to an imitation site that could install malicious programs.

He called the problem the worst discovered since 1997. The standing-room only crowd gave Kaminsky two ovations, in part for the technical significance of the find and in part for his handling of the crisis. Microsoft, Google, Yahoo, Facebook, MySpace, EBay and many Internet service providers have secured their machines.

"We got lucky with this bug," Kaminsky said in his talk, saying other profound flaws are lurking that will be just as hard to resolve. "We have to have disaster-recovery planning. The 90-days-to-fix-it thing isn't going to fly."

DankaminskyKaminsky also showed how the flaw could be used to attack places that some professionals had believed immune.

The Secure Sockets Layer, signified by "https://" at the beginning of a website address, could be circumvented, as one example. Impostors could fool the authentication companies, such as Verisign, and so get an approved digital certificate shown to site visitors, though Kaminsky said those companies have revamped their procedures. A large number of firms simply sign their own certificates, which an impostor could do, without dissuading consumers from continuing.

"Everywhere you look, SSL shoots itself in the face," Kaminsky said.

Corporate firewalls can likewise be thwarted through computers connecting to outside partners, such as payment processors.

Other scary scenarios include intercepted and manipulated e-mail coming from trusted parties and the fact that automatic software updates, which are a key way to get security fixes installed automatically, can easily be hijacked.

There are so many different ways for malicious actors to try to use the flaw that Kaminsky said it marked the start of a new era of hacking.

"DNS is the Achilles' heel of the Internet," agreed Joris Evers, a spokesman for security company McAfee Inc. "There's a lot of attention that's been focused on this -- and that's good."

In an interview, Kaminsky said that more than 120 million home broadband users have already been protected, and that workplace systems might be more at risk. Some attacks have already occurred, and Kaminsky said he was most worried about the tens of millions of sites that have a link to click on if users forget their passwords. A hacker could pretend to be specific users and get the passwords sent to them.

Ordinary computer users can't do much to patch their own machines, though they can prod their employers or Internet service providers to act. They can check to see if patches have been applied by visiting www.doxpara.com and clicking on "Check my DNS."

-- Joseph Menn

Black Hat company logo from richardmasoner via Flickr; photo of Kaminsky courtesy of the subject.


TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8341c630a53ef00e553d238008833

Listed below are links to weblogs that reference Internet security flaw described as worst in 10 years:

Comments

That is one massive flaw. This is one of the reasons why users should try to avoid having identical passwords to all of the websites they access, just in case such exploits are taken advantage of. Ideally, the websites we visited would manage to rectify any errors involving this flaw soon, but given how many of them operate, this will likely not be the case.

Kudos to everyone who found this flaw and worked on patching it up before releasing the information to the public.

I do have to wonder though... The title of the article says it's the worst flaw in ten years... What was the flaw discovered ten years ago?

Post a comment
If you are under 13 years of age you may read this message board, but you may not participate.
Here are the full legal terms you agree to by using this comment form.

Comments are moderated, and will not appear until they've been approved.

If you have a TypeKey or TypePad account, please Sign In





@latimes Tech, always on...


Follow @latimestech for <140c updates.
Recent Comments
Appiphilia: Apps that help with the summer schlep
Have you tried out the free LBS applicat...
comment by Dan Durbeck
Feature on new iPhone 3GS: battery iDrain
We benchmarked battery performance on th...
comment by Jeremy Horwitz
AT&T's GPS service for iPhone: Would you pay $9.99 a month?
I would not pay the monthly fee. GPS d...
comment by lit
TECHNOLOGY REVIEWS
Depending on the model, your device features either a hard drive or flash drive that allows you to read and write files to it just like an external drive.
More from KTLA.com