Cybersecurity |
Sponsored by |
|
Former CIA Director, George J. Tenet recently called for measures to safeguard the United States against internet-enabled attacks. "I know that these actions will be controversial in this age when we still think the Internet is a free and open society with no control or accountability, but ultimately the Wild West must give way to governance and control." Mr. Tenet seems about as confused about the internet as the ITU... more
In an article by MSNBC called "Fort N.O.C.'s" [Network Operating Center] Brock N. Meeks reports: "The unassuming building that houses the "A" root sits in a cluster of three others; the architecture looks as if it were lifted directly from a free clip art library. No signs or markers give a hint that the Internet's most precious computer is inside humming happily away in a hermetically sealed room. This building complex could be any of a 100,000 mini office parks littering middle class America." ...It is hardly the "most precious computer"!!! more
On Saturday, November 29, 2003 a post on the GNSO mailing list indicated that the .name registry website had been hacked. As reported by George Kirikos, "The .name registry's main website www.nic.name has been hacked, as of Saturday evening in North America. According to Netcraft, they're running Linux. They must not have kept up to date with all security updates, or someone cracked a password. Hopefully offsite backups were made, to ensure data integrity." Although, due to this emergency, the .name web servers have been pulled down as of this writing, just a short few hours ago, visitors to the .name registry home page would find a mysterious black screen upon visiting the site, including the following text... more
A few days ago, Eric Goldman wrote an interesting thinkpiece in CircleID regarding users' feeling about privacy. He seems to conclude that the existent regulations and policies on the matter are unnecessary, since Privacy doesn't "really" matters to the consumer. Eric based his argumentation on a number of surveys, stating that, even when the user expresses concerns about their privacy, on line behavior shows a different reality. We don't want to discuss here the soundness of surveys as a reliable source of information, but the author could be assuming too much in his analysis. more
Later today, Senator Conrad Burns, who chairs the U.S. Senate subcommittee responsible for supervising ICANN, will be holding a hearing on a number of issues.
At the beginning of the year, a press release called "Burns Unveils NexGenTen Agenda For Communications Reform and Security in the 21st Century", had reported:
"U.S. Sen. Conrad Burns (R-Mont.) announced his top priorities for his chairmanship of the Senate Communications Subcommittee during the 108th legislative session. The ten items, called the Burns NexGenTen Tech Agenda, aim to strengthen security and usher reform for 21st Century Communication... more
G7 cybersecurity agencies are pressing governments and organizations to inventory cryptographic dependencies and accelerate post-quantum migration as long transition timelines and future quantum attacks threaten Internet security infrastructure. more
Authorities disrupted the decades-old Sality botnet by targeting its decentralized peer-to-peer network and supporting domains, cutting infected machines off from malicious payloads while beginning the longer task of identifying and remediating compromised systems. more
Dangling DNS records can expose trusted corporate subdomains to takeover, while AI-assisted reconnaissance makes abandoned resources easier to find, increasing the need for continuous DNS monitoring rather than periodic audits. more
FulcrumSec claims it stole 86 GB from Manchester Airports Group, including detailed booking and travel data, while the operator has confirmed a breach but not the group's account of its scale or method. more
ICANN has terminated two registrar accreditation agreements after unresolved compliance failures, citing Trustname's handling of DNS abuse and IPIP's failures involving RDAP, registration data escrow, accreditation fees, and access to non-public registration data. more
More than 100 organizations are calling for wider use of AI in cyber defense, urging governments, technology providers and AI developers to expand funding, tools, model access and practical support for under-resourced critical infrastructure operators. more
IPv6 solves the Internet's address shortage and simplifies networking, but its technical elegance may carry a hidden cost: shifting privacy protections from architectural constraints toward policies controlled by Internet providers, corporations and governments. more
Britain's cyber agency warns that attackers are increasingly targeting internet-exposed industrial systems, routers and other edge devices, with some intrusions causing real-world disruption and highlighting the growing risks of poorly secured operational technology worldwide. more
Publishing a DMARC record is only the beginning. New data show that many domains lack enforcement or reporting, exposing a gap between adopting email authentication and operating it effectively enough to detect problems and deter impersonation. more
Project Jake aims to bridge the divide between internet protocols and policy, offering registries, law enforcement and rights holders a decentralised framework for accessing domain-registration data securely while navigating privacy laws and institutional gridlock. more