<html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">Thanks for brining this up, Sam. Some of this is sort of around the edges of ICANNs remit, but I think very useful for the DNS community to discuss. <div class=""><br class=""></div><div class="">These are issues for US infrastructure of  course, but the same attacks, and the same mitigations, apply to all DNS use. It is important for all registrar services to include secure authentication, multi-factor authentication, etc. And supporting Certificate Transparency is definitely outside ICANNs direct remit, but a very interesting topic for discussion. </div><div class=""><br class=""></div><div class="">A valuable reminder that DNS security is a real, and complex, issue even if many aspects of it are at the edges of ICANNs mission, and not all DNS SSR issues can be tackled solely at the ICANN level. </div><div class=""><br class=""></div><div class="">David<br class=""><div class=""><br class=""><div><br class=""><blockquote type="cite" class=""><div class="">On 23 Jan 2019, at 9:44 am, Sam Lanfranco <<a href="mailto:lanfran@YORKU.CA" class="">lanfran@YORKU.CA</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><div class=""><font face="Tahoma" size="2" class=""><div class=""><font size="3" class="">Excuse me if this is too far off base. It does serve as a quick primer on the kinds of threats that the DNS system is up against on a daily basis. </font><br class=""></div><div class=""><br class=""></div><div class="">As we work within the ICANN remit it might be useful to on occasion look out there at the ongoing daily threats to the security and stability of the DNS system. We are keenly aware of when various actors "turn off" the Internet but most of us are less aware of the other forms of attack on DNS security and stability. Here is a link to, and a few words from, the U.S. Department of Homeland Security on recent attacks on the DNS system. <br class=""></div><div class=""><br class=""></div><div class=""><font size="3" class=""><a href="https://cyber.dhs.gov/ed/19-01/" class="">https://cyber.dhs.gov/ed/19-01/</a><br class=""></font></div><div class=""><font size="3" class=""><br class=""></font></div><div class=""><br class=""><font size="3" class="">This page contains a web-friendly version of the Cybersecurity and Infrastructure Security Agency’s <a href="https://cyber.dhs.gov/assets/report/ed-19-01.pdf" class="">Emergency Directive 19-01</a>, “<em class="">Mitigate DNS Infrastructure Tampering</em>”.</font></div><div class=""><font size="3" class=""><br class=""></font></div><div class="rss_title" style="font-weight: bold; font-size: 120%; margin: 0 0 0.3em; padding: 0;"><i class=""><b class=""><font size="3" class="">Excerpts: </font></b></i><a href="https://www.us-cert.gov/ncas/current-activity/2019/01/22/CISA-Emergency-Directive-DNS-Infrastructure-Tampering" class="">CISA Emergency Directive on DNS Infrastructure Tampering</a></div><div class="">
<div class="rss_pub_date" style="font-size: 90%; font-style: italic; color: #666666; margin: 0 0 0.3em; padding: 0;">01/22/2019 06:48 PM EST</div>
<br class="">
Original release date: January 22, 2019<br class=""><p class="">The U.S. Department of Homeland Security (DHS) Cybersecurity and
Infrastructure Security Agency (CISA) issued an emergency directive to
address ongoing incidents associated with global Domain Name System
(DNS) infrastructure tampering. CISA is aware of multiple executive
branch agency domains that were impacted by the tampering campaign and
has notified the agencies that maintain them. The directive requires
Federal agencies to take specific steps and comply with reporting
procedures to mitigate risks from undiscovered tampering, prevent
illegitimate DNS activity, and detect unauthorized certificates.</p><p class="">Federal agencies should review <a href="https://cyber.dhs.gov/ed/19-01/" class="">Emergency Directive 19-01</a> for required actions and reporting procedures. <br class=""></p><h3 id="background" class="">Background</h3><p class="">In coordination with government and industry partners, the Department
 of Homeland Security (DHS) Cybersecurity and Infrastructure Security
Agency (CISA) is tracking a series of incidents<sup id="fnref:1" class=""><a href="https://cyber.dhs.gov/ed/19-01/#fn:1" class="footnote">1</a></sup>
  involving Domain Name System (DNS) infrastructure tampering. CISA is
aware of multiple executive branch agency domains that were impacted by 
the tampering campaign and has notified the agencies that maintain them.</p><p class="">Using the following techniques, attackers have redirected and
intercepted web and mail traffic, and could do so for other networked
services.</p>

<ol class=""><li class="">The attacker begins by compromising user credentials, or obtaining
 them through alternate means, of an account that can make changes to
DNS records.</li><li class="">Next, the attacker alters DNS records, like Address (A), Mail
Exchanger (MX), or Name Server (NS) records, replacing the legitimate
address of a service with an address the attacker controls. This enables
 them to direct user traffic to their own infrastructure for
manipulation or inspection before passing it on to the legitimate
service, should they choose. This creates a risk that persists beyond
the period of traffic redirection.</li><li class="">Because the attacker can set DNS record values, they can also
obtain valid encryption certificates for an organization’s domain names.
 This allows the redirected traffic to be decrypted, exposing any
user-submitted data. Since the certificate is valid for the domain, end 
users receive no error warnings.</li></ol><p class="">To address the significant and imminent risks to agency information
and information systems presented by this activity, this emergency
directive requires the following near-term actions to mitigate risks
from undiscovered tampering, enable agencies to prevent illegitimate DNS
 activity for their domains, and detect unauthorized certificates.  <br class=""></p><p class="">See:  <a href="https://cyber.dhs.gov/ed/19-01/" class="">Emergency Directive 19-01</a></p><p class="">Posted by: Sam L. NPOC<br class=""></p><p class=""><br class=""></p></div></font></div>
</div></blockquote></div><br class=""></div></div></body></html>