You are here: silicon.com > Comment & Analysis

Comment & Analysis

The great domain name robbery

The recent hijacking of high-profile domain names has sent shockwaves through the online security industry. But Network Solutions has denied it is solely to blame for the débâcle. As businesses increasingly rely on their online presence to grow and flourish, Polly Raymond tries to discover where the buck stops

By Polly Raymond

Published: 28 April 2000 11:25 BST

Last month, a large number of European companies were horrified to discover that their domain names had been hijacked, with all traffic to their sites being redirected to a page containing messages about the war in Kosovo.

In a time where online presence is a business necessity, this was a major disaster for the companies concerned - which included Adidas and Manchester United.

All global domain names are stored and managed by one company: Network Solutions (NSI). The individuals in this case managed to spoof email addresses from a variety of sites. The hijackers then sent NSI an email appearing to come from the 'correct' domain, requesting that the registration details and DNS server be changed. The DNS servers for these sites were then switched to another provider.

So these Serbian 'cybervandals' caused chaos simply by sending a hoax email to NSI. Without checking on the authenticity of the requests, it duly complied.

WebDNS - another domain name outfit - issued a damning statement soon after the incident last week, blaming Network Solutions itself. "Network Solutions has serious security issues pertaining to the manner in which domain names are maintained and changed using their automated email system," the statement read.

But NSI has rejected such criticisms. The domain name registrar has a range of security options available to companies when they register: the more stringent the security you want, the more you have to pay. The company says the victims of the attacks are to blame because they didn't opt for a strong enough security option.

Cheryl Regan, head of corporate communications at Network Solutions, said: "Emphasis needs to be made here that the domain names that had been attacked or 'hijacked' were those whose registrations had subscribed to 'Mail-From' - the lowest protection scheme available for a domain name record."

NSI offers higher levels of protection, including encrypted passwords and pretty-good-privacy (PGP) cryptography systems. Troublemakers trying to redirect domain names by pretending to send an email from within the company would be foiled if the company had registered a domain name with these 'four-star' security options.

But Paul Cronin, head of testing at security company CenturyCom, says this is not good enough. "It's the responsibility of Network Solutions to look after the security of domain names registered with them no matter what. Their existing security measures are very sloppy."

But not everyone thinks Network Solutions should be solely to blame. Jonathan Robinson, CEO of one of the UK's largest domain name companies, NetBenefit, said it's as much up to the domain name owners to protect their online territory.

"Everyone thinks that domain names are a simple area. We've obviously always been aware that it's essential to have the highest security protection on domain names. There has been a proliferation of new companies registering theirs independently - they are not so aware of the dangers," said Robinson.

He concluded that the recent spate of 'email hijacking' will serve as a wake-up call to all involved in registering domain names.

The question of who should shoulder responsibility is still undecided. Obviously the idea that Network Solutions should provide a security option so void of protection that a simple hoax involving a bogus email can shatter a company's Web presence seems absurd.

But on the other hand companies, when registering their addresses, should be more aware of the dangers. Don't wait for Network Solutions to get their act together - you may have to do it yourself.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Cognos Applications Support Analyst - Massive Pharma name

A massive new in the field of Pharmaceuticals has just opened a new role for an IS Business Support Analyst to based in from their headquarters in ...

SAS Credit risk analyst - Huge insurance name - Hampshire

Credit risk analyst needed for major insurance group based in Hampshire! This role will see you part of a specialised team of SAS analyst, working on ...

Senior Systems Engineer (Project Lead)- Active Directory, Windows 2003, Exchange, Sharepoint, LCS - Abingdon, Oxfordshire, South

MCSE2000/2003 highly preferable) Why you should work for us: - Recently awarded UKs Top IT Employer beating many very well known names - Large, ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: