[dnssec-deployment] change "real threats" slide

Mike StJohns Mike.StJohns at nominum.com
Mon Oct 18 12:44:03 EDT 2004


At 11:19 AM 10/18/2004, Rob Austein wrote:
>stock data.  very weak.  this is a proposed cool new use for dns and
>   dnssec, not a "real threat" in the current operational environment
>   that operators are going to care about.  this one has to go, wrong
>   audience.

Actually, stock data was just one of the items.  General idea is that there 
is a lot of data unprotected by things like SSL that could be spoofed to 
advantage.  Stock data - could cause people to buy/sell on a 
mistake.  Google - imagine someone intercepting and replacing that 
data.   Or better yet Froogle - being redirected to a site that actually 
has the product you want for a higher price.  In DC - redirecting 
www.wtop.com/closings when there's the threat of snow - either replacing 
the open with closed or vice versa.  Keeping people off of ticketmaster.com 
on the day tickets are supposed to go on sale (Ticket master protects the 
credit card transactions with SSL, but not necessarily the rest of the site)

I actually think this class of attacks needs a slide of its own.  I came up 
with the above last three in about 5 minutes, I'm sure we can come up with 
some others. 




More information about the Dnssec-deployment mailing list