<html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"></head><body dir="auto"><div dir="ltr"></div><div dir="ltr">I think the majority of solutions may lay elsewhere, but ICANN community forums are a good place to for a cross-section people to discuss issues, without leading to any direct ICANN policy or regulations.</div><div dir="ltr"><br></div><div dir="ltr">In my experience RIPE NCC meetings have been a bit more limited in extent and breadth of participation, which could maybe be widened.</div><div dir="ltr"><br></div><div dir="ltr">I also think these issues are well-placed for community discussion and best practice recommendations through the IGF, which will help strengthen the standing of this forum.</div><div dir="ltr"><br></div><div dir="ltr">Kind regards,</div><div dir="ltr"><br></div><div dir="ltr">Nick</div><div dir="ltr"><br>On 24 Jan 2019, at 09:24, Vladimer Svanadze <<a href="mailto:00000585df4969dc-dmarc-request@listserv.syr.edu">00000585df4969dc-dmarc-request@listserv.syr.edu</a>> wrote:<br><br></div><blockquote type="cite"><div dir="ltr"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><meta name="Generator" content="Microsoft Word 15 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Tahoma;
panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman",serif;}
h3
{mso-style-priority:9;
mso-style-link:"Heading 3 Char";
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:13.5pt;
font-family:"Times New Roman",serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
p.msonormal0, li.msonormal0, div.msonormal0
{mso-style-name:msonormal;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:12.0pt;
font-family:"Times New Roman",serif;}
span.apple-converted-space
{mso-style-name:apple-converted-space;}
span.Heading3Char
{mso-style-name:"Heading 3 Char";
mso-style-priority:9;
mso-style-link:"Heading 3";
font-family:"Calibri Light",sans-serif;
color:#1F4D78;}
span.EmailStyle21
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:#1F497D;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
/* List Definitions */
@list l0
{mso-list-id:1518886563;
mso-list-template-ids:-1482372418;}
ol
{margin-bottom:0in;}
ul
{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--><div class="WordSection1"><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Thanks James, <o:p></o:p></span></p><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">My opinion for this issue is other. ICANN will not return to back, and ICANN will not be "The administration of certain responsibilities associated with Internet DNS root zone management" (IANA). <o:p></o:p></span></p><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">I think that Security and Stability of DNS is a new challenge for us, for countries, for all community. DNS became a target for attacks, and this process will be grow, and grow, and this is threat not only for nations, also it is globally threat (<a href="https://www.zdnet.com/google-amp/article/iranian-hackers-suspected-in-worldwide-dns-hijacking-campaign/?fbclid=IwAR2uJ5pG_fcWKccaUz1te9oyUKKGppFjQ-sWhtgsduPdFQkMkH9129tkPdw">https://www.zdnet.com/google-amp/article/iranian-hackers-suspected-in-worldwide-dns-hijacking-campaign/?fbclid=IwAR2uJ5pG_fcWKccaUz1te9oyUKKGppFjQ-sWhtgsduPdFQkMkH9129tkPdw</a>). <o:p></o:p></span></p><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">ICANN may be to begin a discussion around this issue, and ICANN can be as an organization, which will give ONLY recommendation (and not administration) for register and providers. I think that this process will reduce threats at Cyber Space. Almost all experts are talking about this problem, and if ICANN do not do anything, I think will be not so good, when ICANN works directly with register and providers.<o:p></o:p></span></p><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Thank you, It is my opinion.<o:p></o:p></span></p><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Hope I could put</span> <span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">clearly my opinion with my poor English.<o:p></o:p></span></p><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Lado<o:p></o:p></span></p><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p><div><div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in"><p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> NCSG-Discuss [<a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU</a>] <b>On Behalf Of </b>James Gannon<br><b>Sent:</b> Thursday, January 24, 2019 12:52 PM<br><b>To:</b> <a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">NCSG-DISCUSS@LISTSERV.SYR.EDU</a><br><b>Subject:</b> Re: ICANN Remit: Security & Stability of the DNS System<o:p></o:p></span></p></div></div><p class="MsoNormal"><o:p> </o:p></p><p class="MsoNormal">My personal opinion is we spent a huge amount of political capital fighting for a limited mandate and for ICANN to stay out of areas not related to the root zone during the IANA transition, if we now turn around and say the opposite because its something we are interested in I think we burn a lot of creditability I think.<o:p></o:p></p><div><p class="MsoNormal"><br><br><o:p></o:p></p><blockquote style="margin-top:5.0pt;margin-bottom:5.0pt"><div><p class="MsoNormal">On 24 Jan 2019, at 09:25, David Cake <<a href="mailto:dave@davecake.net">dave@davecake.net</a>> wrote:<o:p></o:p></p></div><p class="MsoNormal"><o:p> </o:p></p><div><div><p class="MsoNormal">What ICANN can contractually mandate, and what it can discuss, or consider in policy creation, best practice docs, comments, etc are very different things. And also, ICANN communities overlap with over Internet communities of practice quite a bit - no reason discussions in ICANN can’t comment on what goes on elsewhere. <o:p></o:p></p><div><p class="MsoNormal">Also, how registrars operate with regards to RDAP totally is being considered within ICANN at this point, and is not a 100% disjoint discussion. <o:p></o:p></p><div><p class="MsoNormal"><o:p> </o:p></p></div><div><p class="MsoNormal">David<o:p></o:p></p><div><p class="MsoNormal"><br><br><o:p></o:p></p><blockquote style="margin-top:5.0pt;margin-bottom:5.0pt"><div><p class="MsoNormal">On 24 Jan 2019, at 4:19 pm, James Gannon <<a href="mailto:james@cyberinvasion.net">james@cyberinvasion.net</a>> wrote:<o:p></o:p></p></div><p class="MsoNormal"><o:p> </o:p></p><div><div><p class="MsoNormal">I think that if ICANN tried to define how a registarar operates or mandates 2FA for their clients we would see quite quickly that that is very much outside of the bylaws interpretation in my opinion =) <o:p></o:p></p><div><p class="MsoNormal"><o:p> </o:p></p></div><div><p class="MsoNormal">Not saying its not important, just out of scope for ICANN.<o:p></o:p></p><div><p class="MsoNormal"><br><br><o:p></o:p></p><blockquote style="margin-top:5.0pt;margin-bottom:5.0pt"><div><p class="MsoNormal">On 24 Jan 2019, at 09:16, David Cake <<a href="mailto:dave@davecake.net">dave@davecake.net</a>> wrote:<o:p></o:p></p></div><p class="MsoNormal"><o:p> </o:p></p><div><div><p class="MsoNormal">Registrar procedures are kind of within ICANN scope, or at least on the edges of it - but certainly procedures of groups that are definitely outside ICANNs remit have definitely been considered as part of ICANN policy processes. That is, ICANN may not in any way control processes like CAs, but it can (and does) consider the needs of such providers when looking at policy issues like RDS. <o:p></o:p></p><div><p class="MsoNormal"><o:p> </o:p></p></div><div><p class="MsoNormal">David<o:p></o:p></p><div><p class="MsoNormal"><br><br><o:p></o:p></p><blockquote style="margin-top:5.0pt;margin-bottom:5.0pt"><div><p class="MsoNormal">On 24 Jan 2019, at 4:03 pm, James Gannon <<a href="mailto:james@CYBERINVASION.NET">james@CYBERINVASION.NET</a>> wrote:<o:p></o:p></p></div><p class="MsoNormal"><o:p> </o:p></p><div><div><p class="MsoNormal">DNS below the root is out of scope for ICANN so I don’t agree that that is even a possibility.<o:p></o:p></p><div><p class="MsoNormal"><br><br><o:p></o:p></p><blockquote style="margin-top:5.0pt;margin-bottom:5.0pt"><div><p class="MsoNormal">On 24 Jan 2019, at 08:59, Vladimer Svanadze <<a href="mailto:00000585df4969dc-dmarc-request@LISTSERV.SYR.EDU">00000585df4969dc-dmarc-request@LISTSERV.SYR.EDU</a>> wrote:<o:p></o:p></p></div><p class="MsoNormal"><o:p> </o:p></p><div><div><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Hello,</span><o:p></o:p></p></div><div><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"> </span><o:p></o:p></p></div><div><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Thank you, Sam, for your email, and information provided us.</span><o:p></o:p></p></div><div><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"> </span><o:p></o:p></p></div><div><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">I agree with David in sort of around the edges of ICANNs remit, but security of DNS is a very important process, and also it is a main target for criminals in the near future. This problem is not only National level, it is a globally problem, and challenge for all DNS Community.</span><o:p></o:p></p></div><div><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"> </span><o:p></o:p></p></div><div><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">It is not a problem only for the US, it is problem for every infrastructure. I think that will be very important for a stability and security of infrastructure of all countries, if registrar use more technical tools with Unified International Standards of protection, and include secure authentication, multi-factor authentication, as David say.<span class="apple-converted-space"> </span></span><o:p></o:p></p></div><div><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"> </span><o:p></o:p></p></div><div><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Also I would like to add that will be good if around of ICANN will be a discussion about Security and Stability of DNS, and ICANN will develop policy/strategy with recommendation for DNS SSR, as a National, also as a Global level.</span><o:p></o:p></p></div><div><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"> </span><o:p></o:p></p></div><div><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">And once again I absolutely agree with David in issues of DNS SSR can be tackled solely at the ICANN level.</span><o:p></o:p></p></div><div><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"> </span><o:p></o:p></p></div><div><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Lado</span><o:p></o:p></p></div><div><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"> </span><o:p></o:p></p></div><div><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"> </span><o:p></o:p></p></div><div><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"> </span><o:p></o:p></p></div><div><div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in"><div><p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span class="apple-converted-space"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> </span></span><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">NCSG-Discuss [<a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU</a>]<span class="apple-converted-space"> </span><b>On Behalf Of<span class="apple-converted-space"> </span></b>David Cake<br><b>Sent:</b><span class="apple-converted-space"> </span>Wednesday, January 23, 2019 10:47 AM<br><b>To:</b><span class="apple-converted-space"> </span><a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">NCSG-DISCUSS@LISTSERV.SYR.EDU</a><br><b>Subject:</b><span class="apple-converted-space"> </span>Re: ICANN Remit: Security & Stability of the DNS System</span><o:p></o:p></p></div></div></div><div><p class="MsoNormal"> <o:p></o:p></p></div><div><p class="MsoNormal">Thanks for brining this up, Sam. Some of this is sort of around the edges of ICANNs remit, but I think very useful for the DNS community to discuss. <o:p></o:p></p></div><div><div><p class="MsoNormal"> <o:p></o:p></p></div></div><div><div><p class="MsoNormal">These are issues for US infrastructure of course, but the same attacks, and the same mitigations, apply to all DNS use. It is important for all registrar services to include secure authentication, multi-factor authentication, etc. And supporting Certificate Transparency is definitely outside ICANNs direct remit, but a very interesting topic for discussion. <o:p></o:p></p></div></div><div><div><p class="MsoNormal"> <o:p></o:p></p></div></div><div><div><p class="MsoNormal">A valuable reminder that DNS security is a real, and complex, issue even if many aspects of it are at the edges of ICANNs mission, and not all DNS SSR issues can be tackled solely at the ICANN level. <o:p></o:p></p></div></div><div><div><p class="MsoNormal"> <o:p></o:p></p></div></div><div><div><p class="MsoNormal">David<o:p></o:p></p></div><div><div><p class="MsoNormal"> <o:p></o:p></p></div><div><div><p class="MsoNormal"><br><br><br><o:p></o:p></p></div><blockquote style="margin-top:5.0pt;margin-bottom:5.0pt"><div><div><p class="MsoNormal">On 23 Jan 2019, at 9:44 am, Sam Lanfranco <<a href="mailto:lanfran@YORKU.CA"><span style="color:purple">lanfran@YORKU.CA</span></a>> wrote:<o:p></o:p></p></div></div><div><p class="MsoNormal"> <o:p></o:p></p></div><div><div><div><div><p class="MsoNormal"><span style="font-family:"Tahoma",sans-serif">Excuse me if this is too far off base. It does serve as a quick primer on the kinds of threats that the DNS system is up against on a daily basis.<span class="apple-converted-space"> </span></span><o:p></o:p></p></div></div><div><div><p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif"> </span><o:p></o:p></p></div></div><div><div><p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif">As we work within the ICANN remit it might be useful to on occasion look out there at the ongoing daily threats to the security and stability of the DNS system. We are keenly aware of when various actors "turn off" the Internet but most of us are less aware of the other forms of attack on DNS security and stability. Here is a link to, and a few words from, the U.S. Department of Homeland Security on recent attacks on the DNS system.<span class="apple-converted-space"> </span></span><o:p></o:p></p></div></div><div><div><p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif"> </span><o:p></o:p></p></div></div><div><div><p class="MsoNormal"><span style="font-family:"Tahoma",sans-serif"><a href="https://cyber.dhs.gov/ed/19-01/"><span style="color:purple">https://cyber.dhs.gov/ed/19-01/</span></a></span><o:p></o:p></p></div></div><div><div><p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif"> </span><o:p></o:p></p></div></div><div><div><p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif"><br></span><span style="font-family:"Tahoma",sans-serif">This page contains a web-friendly version of the Cybersecurity and Infrastructure Security Agency’s<span class="apple-converted-space"> </span><a href="https://cyber.dhs.gov/assets/report/ed-19-01.pdf"><span style="color:purple">Emergency Directive 19-01</span></a>, “<em><span style="font-family:"Tahoma",sans-serif">Mitigate DNS Infrastructure Tampering</span></em>”.</span><o:p></o:p></p></div></div><div><div><p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif"> </span><o:p></o:p></p></div></div><div style="margin-bottom:.05in"><div><p class="MsoNormal"><b><i><span style="font-family:"Tahoma",sans-serif">Excerpts:<span class="apple-converted-space"> </span></span></i></b><b><span style="font-family:"Tahoma",sans-serif"><a href="https://www.us-cert.gov/ncas/current-activity/2019/01/22/CISA-Emergency-Directive-DNS-Infrastructure-Tampering"><span style="color:purple">CISA Emergency Directive on DNS Infrastructure Tampering</span></a></span></b><o:p></o:p></p></div></div><div><div style="margin-bottom:.05in"><div><p class="MsoNormal"><i><span style="font-size:9.0pt;font-family:"Tahoma",sans-serif;color:#666666">01/22/2019 06:48 PM EST</span></i><o:p></o:p></p></div></div><div><p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif"><br>Original release date: January 22, 2019</span><o:p></o:p></p></div><div><p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif">The U.S. Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive to address ongoing incidents associated with global Domain Name System (DNS) infrastructure tampering. CISA is aware of multiple executive branch agency domains that were impacted by the tampering campaign and has notified the agencies that maintain them. The directive requires Federal agencies to take specific steps and comply with reporting procedures to mitigate risks from undiscovered tampering, prevent illegitimate DNS activity, and detect unauthorized certificates.</span><o:p></o:p></p></div><div><p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif">Federal agencies should review<span class="apple-converted-space"> </span><a href="https://cyber.dhs.gov/ed/19-01/"><span style="color:purple">Emergency Directive 19-01</span></a><span class="apple-converted-space"> </span>for required actions and reporting procedures.<span class="apple-converted-space"> </span></span><o:p></o:p></p></div><h3 id="background"><span style="font-family:"Tahoma",sans-serif">Background</span><o:p></o:p></h3><div><p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif">In coordination with government and industry partners, the Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) is tracking a series of incidents<sup id="fnref:1"><a href="https://cyber.dhs.gov/ed/19-01/#fn:1"><span style="color:purple">1</span></a></sup><span class="apple-converted-space"> </span>involving Domain Name System (DNS) infrastructure tampering. CISA is aware of multiple executive branch agency domains that were impacted by the tampering campaign and has notified the agencies that maintain them.</span><o:p></o:p></p></div><div><p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif">Using the following techniques, attackers have redirected and intercepted web and mail traffic, and could do so for other networked services.</span><o:p></o:p></p></div><ol style="margin-top:0in" start="1" type="1"><li class="MsoNormal" style="mso-list:l0 level1 lfo1"><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif">The attacker begins by compromising user credentials, or obtaining them through alternate means, of an account that can make changes to DNS records.</span><o:p></o:p></li><li class="MsoNormal" style="mso-list:l0 level1 lfo1"><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif">Next, the attacker alters DNS records, like Address (A), Mail Exchanger (MX), or Name Server (NS) records, replacing the legitimate address of a service with an address the attacker controls. This enables them to direct user traffic to their own infrastructure for manipulation or inspection before passing it on to the legitimate service, should they choose. This creates a risk that persists beyond the period of traffic redirection.</span><o:p></o:p></li><li class="MsoNormal" style="mso-list:l0 level1 lfo1"><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif">Because the attacker can set DNS record values, they can also obtain valid encryption certificates for an organization’s domain names. This allows the redirected traffic to be decrypted, exposing any user-submitted data. Since the certificate is valid for the domain, end users receive no error warnings.</span><o:p></o:p></li></ol><div><p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif">To address the significant and imminent risks to agency information and information systems presented by this activity, this emergency directive requires the following near-term actions to mitigate risks from undiscovered tampering, enable agencies to prevent illegitimate DNS activity for their domains, and detect unauthorized certificates. <span class="apple-converted-space"> </span></span><o:p></o:p></p></div><div><p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif">See:<span class="apple-converted-space"> </span><a href="https://cyber.dhs.gov/ed/19-01/"><span style="color:purple">Emergency Directive 19-01</span></a></span><o:p></o:p></p></div><div><p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif">Posted by: Sam L. NPOC</span><o:p></o:p></p></div></div></div></div></blockquote></div></div></div></div></blockquote></div><p class="MsoNormal"><o:p> </o:p></p></div></div></blockquote></div><p class="MsoNormal"><o:p> </o:p></p></div></div></div></blockquote></div><p class="MsoNormal"><o:p> </o:p></p></div></div></div></blockquote></div><p class="MsoNormal"><o:p> </o:p></p></div></div></div></div></blockquote></div><p class="MsoNormal"><o:p> </o:p></p></div></div></blockquote></body></html>