<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=utf-8"><meta name=Generator content="Microsoft Word 15 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Tahoma;
panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman",serif;}
h3
{mso-style-priority:9;
mso-style-link:"Heading 3 Char";
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:13.5pt;
font-family:"Times New Roman",serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
p.msonormal0, li.msonormal0, div.msonormal0
{mso-style-name:msonormal;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:12.0pt;
font-family:"Times New Roman",serif;}
span.apple-converted-space
{mso-style-name:apple-converted-space;}
span.Heading3Char
{mso-style-name:"Heading 3 Char";
mso-style-priority:9;
mso-style-link:"Heading 3";
font-family:"Calibri Light",sans-serif;
color:#1F4D78;}
span.EmailStyle21
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:#1F497D;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
/* List Definitions */
@list l0
{mso-list-id:120537911;
mso-list-template-ids:-1616586922;}
ol
{margin-bottom:0in;}
ul
{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-US link=blue vlink=purple><div class=WordSection1><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'>No, ICANN will not be as a controller for a registrar operates or mandates, ICANN will give only recommendation for them.<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'><o:p> </o:p></span></p><div><div style='border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in'><p class=MsoNormal><b><span style='font-size:11.0pt;font-family:"Calibri",sans-serif'>From:</span></b><span style='font-size:11.0pt;font-family:"Calibri",sans-serif'> NCSG-Discuss [mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU] <b>On Behalf Of </b>James Gannon<br><b>Sent:</b> Thursday, January 24, 2019 12:19 PM<br><b>To:</b> NCSG-DISCUSS@LISTSERV.SYR.EDU<br><b>Subject:</b> Re: ICANN Remit: Security & Stability of the DNS System<o:p></o:p></span></p></div></div><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>I think that if ICANN tried to define how a registarar operates or mandates 2FA for their clients we would see quite quickly that that is very much outside of the bylaws interpretation in my opinion =) <o:p></o:p></p><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>Not saying its not important, just out of scope for ICANN.<o:p></o:p></p><div><p class=MsoNormal><br><br><o:p></o:p></p><blockquote style='margin-top:5.0pt;margin-bottom:5.0pt'><div><p class=MsoNormal>On 24 Jan 2019, at 09:16, David Cake <<a href="mailto:dave@davecake.net">dave@davecake.net</a>> wrote:<o:p></o:p></p></div><p class=MsoNormal><o:p> </o:p></p><div><div><p class=MsoNormal>Registrar procedures are kind of within ICANN scope, or at least on the edges of it - but certainly procedures of groups that are definitely outside ICANNs remit have definitely been considered as part of ICANN policy processes. That is, ICANN may not in any way control processes like CAs, but it can (and does) consider the needs of such providers when looking at policy issues like RDS. <o:p></o:p></p><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>David<o:p></o:p></p><div><p class=MsoNormal><br><br><o:p></o:p></p><blockquote style='margin-top:5.0pt;margin-bottom:5.0pt'><div><p class=MsoNormal>On 24 Jan 2019, at 4:03 pm, James Gannon <<a href="mailto:james@CYBERINVASION.NET">james@CYBERINVASION.NET</a>> wrote:<o:p></o:p></p></div><p class=MsoNormal><o:p> </o:p></p><div><div><p class=MsoNormal>DNS below the root is out of scope for ICANN so I don’t agree that that is even a possibility.<o:p></o:p></p><div><p class=MsoNormal><br><br><o:p></o:p></p><blockquote style='margin-top:5.0pt;margin-bottom:5.0pt'><div><p class=MsoNormal>On 24 Jan 2019, at 08:59, Vladimer Svanadze <<a href="mailto:00000585df4969dc-dmarc-request@LISTSERV.SYR.EDU">00000585df4969dc-dmarc-request@LISTSERV.SYR.EDU</a>> wrote:<o:p></o:p></p></div><p class=MsoNormal><o:p> </o:p></p><div><div><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'>Hello,</span><o:p></o:p></p></div><div><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'> </span><o:p></o:p></p></div><div><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'>Thank you, Sam, for your email, and information provided us.</span><o:p></o:p></p></div><div><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'> </span><o:p></o:p></p></div><div><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'>I agree with David in sort of around the edges of ICANNs remit, but security of DNS is a very important process, and also it is a main target for criminals in the near future. This problem is not only National level, it is a globally problem, and challenge for all DNS Community.</span><o:p></o:p></p></div><div><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'> </span><o:p></o:p></p></div><div><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'>It is not a problem only for the US, it is problem for every infrastructure. I think that will be very important for a stability and security of infrastructure of all countries, if registrar use more technical tools with Unified International Standards of protection, and include secure authentication, multi-factor authentication, as David say.<span class=apple-converted-space> </span></span><o:p></o:p></p></div><div><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'> </span><o:p></o:p></p></div><div><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'>Also I would like to add that will be good if around of ICANN will be a discussion about Security and Stability of DNS, and ICANN will develop policy/strategy with recommendation for DNS SSR, as a National, also as a Global level.</span><o:p></o:p></p></div><div><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'> </span><o:p></o:p></p></div><div><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'>And once again I absolutely agree with David in issues of DNS SSR can be tackled solely at the ICANN level.</span><o:p></o:p></p></div><div><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'> </span><o:p></o:p></p></div><div><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'>Lado</span><o:p></o:p></p></div><div><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'> </span><o:p></o:p></p></div><div><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'> </span><o:p></o:p></p></div><div><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'> </span><o:p></o:p></p></div><div><div style='border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in'><div><p class=MsoNormal><b><span style='font-size:11.0pt;font-family:"Calibri",sans-serif'>From:</span></b><span class=apple-converted-space><span style='font-size:11.0pt;font-family:"Calibri",sans-serif'> </span></span><span style='font-size:11.0pt;font-family:"Calibri",sans-serif'>NCSG-Discuss [<a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU</a>]<span class=apple-converted-space> </span><b>On Behalf Of<span class=apple-converted-space> </span></b>David Cake<br><b>Sent:</b><span class=apple-converted-space> </span>Wednesday, January 23, 2019 10:47 AM<br><b>To:</b><span class=apple-converted-space> </span><a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">NCSG-DISCUSS@LISTSERV.SYR.EDU</a><br><b>Subject:</b><span class=apple-converted-space> </span>Re: ICANN Remit: Security & Stability of the DNS System</span><o:p></o:p></p></div></div></div><div><p class=MsoNormal> <o:p></o:p></p></div><div><p class=MsoNormal>Thanks for brining this up, Sam. Some of this is sort of around the edges of ICANNs remit, but I think very useful for the DNS community to discuss. <o:p></o:p></p></div><div><div><p class=MsoNormal> <o:p></o:p></p></div></div><div><div><p class=MsoNormal>These are issues for US infrastructure of course, but the same attacks, and the same mitigations, apply to all DNS use. It is important for all registrar services to include secure authentication, multi-factor authentication, etc. And supporting Certificate Transparency is definitely outside ICANNs direct remit, but a very interesting topic for discussion. <o:p></o:p></p></div></div><div><div><p class=MsoNormal> <o:p></o:p></p></div></div><div><div><p class=MsoNormal>A valuable reminder that DNS security is a real, and complex, issue even if many aspects of it are at the edges of ICANNs mission, and not all DNS SSR issues can be tackled solely at the ICANN level. <o:p></o:p></p></div></div><div><div><p class=MsoNormal> <o:p></o:p></p></div></div><div><div><p class=MsoNormal>David<o:p></o:p></p></div><div><div><p class=MsoNormal> <o:p></o:p></p></div><div><div><p class=MsoNormal><br><br><br><o:p></o:p></p></div><blockquote style='margin-top:5.0pt;margin-bottom:5.0pt'><div><div><p class=MsoNormal>On 23 Jan 2019, at 9:44 am, Sam Lanfranco <<a href="mailto:lanfran@YORKU.CA"><span style='color:purple'>lanfran@YORKU.CA</span></a>> wrote:<o:p></o:p></p></div></div><div><p class=MsoNormal> <o:p></o:p></p></div><div><div><div><div><p class=MsoNormal><span style='font-family:"Tahoma",sans-serif'>Excuse me if this is too far off base. It does serve as a quick primer on the kinds of threats that the DNS system is up against on a daily basis.<span class=apple-converted-space> </span></span><o:p></o:p></p></div></div><div><div><p class=MsoNormal><span style='font-size:10.0pt;font-family:"Tahoma",sans-serif'> </span><o:p></o:p></p></div></div><div><div><p class=MsoNormal><span style='font-size:10.0pt;font-family:"Tahoma",sans-serif'>As we work within the ICANN remit it might be useful to on occasion look out there at the ongoing daily threats to the security and stability of the DNS system. We are keenly aware of when various actors "turn off" the Internet but most of us are less aware of the other forms of attack on DNS security and stability. Here is a link to, and a few words from, the U.S. Department of Homeland Security on recent attacks on the DNS system.<span class=apple-converted-space> </span></span><o:p></o:p></p></div></div><div><div><p class=MsoNormal><span style='font-size:10.0pt;font-family:"Tahoma",sans-serif'> </span><o:p></o:p></p></div></div><div><div><p class=MsoNormal><span style='font-family:"Tahoma",sans-serif'><a href="https://cyber.dhs.gov/ed/19-01/"><span style='color:purple'>https://cyber.dhs.gov/ed/19-01/</span></a></span><o:p></o:p></p></div></div><div><div><p class=MsoNormal><span style='font-size:10.0pt;font-family:"Tahoma",sans-serif'> </span><o:p></o:p></p></div></div><div><div><p class=MsoNormal><span style='font-size:10.0pt;font-family:"Tahoma",sans-serif'><br></span><span style='font-family:"Tahoma",sans-serif'>This page contains a web-friendly version of the Cybersecurity and Infrastructure Security Agency’s<span class=apple-converted-space> </span><a href="https://cyber.dhs.gov/assets/report/ed-19-01.pdf"><span style='color:purple'>Emergency Directive 19-01</span></a>, “<em><span style='font-family:"Tahoma",sans-serif'>Mitigate DNS Infrastructure Tampering</span></em>”.</span><o:p></o:p></p></div></div><div><div><p class=MsoNormal><span style='font-size:10.0pt;font-family:"Tahoma",sans-serif'> </span><o:p></o:p></p></div></div><div style='margin-bottom:.05in'><div><p class=MsoNormal><b><i><span style='font-family:"Tahoma",sans-serif'>Excerpts:<span class=apple-converted-space> </span></span></i></b><b><span style='font-family:"Tahoma",sans-serif'><a href="https://www.us-cert.gov/ncas/current-activity/2019/01/22/CISA-Emergency-Directive-DNS-Infrastructure-Tampering"><span style='color:purple'>CISA Emergency Directive on DNS Infrastructure Tampering</span></a></span></b><o:p></o:p></p></div></div><div><div style='margin-bottom:.05in'><div><p class=MsoNormal><i><span style='font-size:9.0pt;font-family:"Tahoma",sans-serif;color:#666666'>01/22/2019 06:48 PM EST</span></i><o:p></o:p></p></div></div><div><p class=MsoNormal><span style='font-size:10.0pt;font-family:"Tahoma",sans-serif'><br>Original release date: January 22, 2019</span><o:p></o:p></p></div><div><p class=MsoNormal><span style='font-size:10.0pt;font-family:"Tahoma",sans-serif'>The U.S. Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive to address ongoing incidents associated with global Domain Name System (DNS) infrastructure tampering. CISA is aware of multiple executive branch agency domains that were impacted by the tampering campaign and has notified the agencies that maintain them. The directive requires Federal agencies to take specific steps and comply with reporting procedures to mitigate risks from undiscovered tampering, prevent illegitimate DNS activity, and detect unauthorized certificates.</span><o:p></o:p></p></div><div><p class=MsoNormal><span style='font-size:10.0pt;font-family:"Tahoma",sans-serif'>Federal agencies should review<span class=apple-converted-space> </span><a href="https://cyber.dhs.gov/ed/19-01/"><span style='color:purple'>Emergency Directive 19-01</span></a><span class=apple-converted-space> </span>for required actions and reporting procedures.<span class=apple-converted-space> </span></span><o:p></o:p></p></div><h3 id=background><span style='font-family:"Tahoma",sans-serif'>Background</span><o:p></o:p></h3><div><p class=MsoNormal><span style='font-size:10.0pt;font-family:"Tahoma",sans-serif'>In coordination with government and industry partners, the Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) is tracking a series of incidents<sup id="fnref:1"><a href="https://cyber.dhs.gov/ed/19-01/#fn:1"><span style='color:purple'>1</span></a></sup><span class=apple-converted-space> </span>involving Domain Name System (DNS) infrastructure tampering. CISA is aware of multiple executive branch agency domains that were impacted by the tampering campaign and has notified the agencies that maintain them.</span><o:p></o:p></p></div><div><p class=MsoNormal><span style='font-size:10.0pt;font-family:"Tahoma",sans-serif'>Using the following techniques, attackers have redirected and intercepted web and mail traffic, and could do so for other networked services.</span><o:p></o:p></p></div><ol style='margin-top:0in' start=1 type=1><li class=MsoNormal style='mso-list:l0 level1 lfo1'><span style='font-size:10.0pt;font-family:"Tahoma",sans-serif'>The attacker begins by compromising user credentials, or obtaining them through alternate means, of an account that can make changes to DNS records.</span><o:p></o:p></li><li class=MsoNormal style='mso-list:l0 level1 lfo1'><span style='font-size:10.0pt;font-family:"Tahoma",sans-serif'>Next, the attacker alters DNS records, like Address (A), Mail Exchanger (MX), or Name Server (NS) records, replacing the legitimate address of a service with an address the attacker controls. This enables them to direct user traffic to their own infrastructure for manipulation or inspection before passing it on to the legitimate service, should they choose. This creates a risk that persists beyond the period of traffic redirection.</span><o:p></o:p></li><li class=MsoNormal style='mso-list:l0 level1 lfo1'><span style='font-size:10.0pt;font-family:"Tahoma",sans-serif'>Because the attacker can set DNS record values, they can also obtain valid encryption certificates for an organization’s domain names. This allows the redirected traffic to be decrypted, exposing any user-submitted data. Since the certificate is valid for the domain, end users receive no error warnings.</span><o:p></o:p></li></ol><div><p class=MsoNormal><span style='font-size:10.0pt;font-family:"Tahoma",sans-serif'>To address the significant and imminent risks to agency information and information systems presented by this activity, this emergency directive requires the following near-term actions to mitigate risks from undiscovered tampering, enable agencies to prevent illegitimate DNS activity for their domains, and detect unauthorized certificates. <span class=apple-converted-space> </span></span><o:p></o:p></p></div><div><p class=MsoNormal><span style='font-size:10.0pt;font-family:"Tahoma",sans-serif'>See:<span class=apple-converted-space> </span><a href="https://cyber.dhs.gov/ed/19-01/"><span style='color:purple'>Emergency Directive 19-01</span></a></span><o:p></o:p></p></div><div><p class=MsoNormal><span style='font-size:10.0pt;font-family:"Tahoma",sans-serif'>Posted by: Sam L. NPOC</span><o:p></o:p></p></div></div></div></div></blockquote></div></div></div></div></blockquote></div><p class=MsoNormal><o:p> </o:p></p></div></div></blockquote></div><p class=MsoNormal><o:p> </o:p></p></div></div></div></blockquote></div><p class=MsoNormal><o:p> </o:p></p></div></div></body></html>