<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: recursive]]></title>
    <link>http://securityratty.com/tag/recursive</link>
    <description></description>
    <pubDate>Tue, 20 May 2008 06:35:23 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[ICANN/IANA Offer DNS Domain Test]]></title>
      <link>http://securityratty.com/article/855965d8dbc50ef9ec1057e2671aedde</link>
      <guid>http://securityratty.com/article/855965d8dbc50ef9ec1057e2671aedde</guid>
      <description><![CDATA[ICANN has announced a test page, on the IANA site, to test if a domain is vulnerable to the Kaminsky DNS source port vulnerability. Click here to go to the test page. IANA also is providing a FAQ on...]]></description>
      <content:encoded><![CDATA[<a href="http://www.icann.org/en/announcements/announcement-06aug08-en.htm">ICANN has announced</a> a test page, on the IANA site, to test if a domain is vulnerable to the Kaminsky DNS source port vulnerability. <a href="http://recursive.iana.org/">Click here to go to the test page.</a>

IANA also is providing <a href="http://www.iana.org/reports/2008/cross-pollination-faq.html">a FAQ on the bug</a> that has a lot of useful information without digressing into attack details, as so many other writeups do. This FAQ is focused on explanation and practical advice for IT. There is good advice in it, such as pointing out that authoritative name servers should never be configured also to provide recursive name service. This bug is a perfect example of why.<img src="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~4/358495190" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 07:21:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/test">test</category>
      <category domain="http://securityratty.com/tag/iana">iana</category>
      <category domain="http://securityratty.com/tag/test page">test page</category>
      <category domain="http://securityratty.com/tag/advice">advice</category>
      <category domain="http://securityratty.com/tag/iana site">iana site</category>
      <category domain="http://securityratty.com/tag/practical advice">practical advice</category>
      <category domain="http://securityratty.com/tag/provide recursive">provide recursive</category>
      <category domain="http://securityratty.com/tag/bug">bug</category>
      <category domain="http://securityratty.com/tag/domain">domain</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/358495190/icanniana_offer_dns_domain_test.html">ICANN/IANA Offer DNS Domain Test</source>
    </item>
    <item>
      <title><![CDATA[ICANN/IANA Offer DNS Domain Test]]></title>
      <link>http://securityratty.com/article/f01b5a1c23cb4bc0cf12a8e859e2a559</link>
      <guid>http://securityratty.com/article/f01b5a1c23cb4bc0cf12a8e859e2a559</guid>
      <description><![CDATA[ICANN has announced a test page, on the IANA site, to test if a domain is vulnerable to the Kaminsky DNS source port vulnerability. Click here to go to the test page. IANA also is providing a FAQ on...]]></description>
      <content:encoded><![CDATA[<a href="http://www.icann.org/en/announcements/announcement-06aug08-en.htm">ICANN has announced</a> a test page, on the IANA site, to test if a domain is vulnerable to the Kaminsky DNS source port vulnerability. <a href="http://recursive.iana.org/">Click here to go to the test page.</a>

IANA also is providing <a href="http://www.iana.org/reports/2008/cross-pollination-faq.html">a FAQ on the bug</a> that has a lot of useful information without digressing into attack details, as so many other writeups do. This FAQ is focused on explanation and practical advice for IT. There is good advice in it, such as pointing out that authoritative name servers should never be configured also to provide recursive name service. This bug is a perfect example of why.<img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/WF9dPDOkfS4" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 07:21:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/test">test</category>
      <category domain="http://securityratty.com/tag/iana">iana</category>
      <category domain="http://securityratty.com/tag/test page">test page</category>
      <category domain="http://securityratty.com/tag/advice">advice</category>
      <category domain="http://securityratty.com/tag/iana site">iana site</category>
      <category domain="http://securityratty.com/tag/practical advice">practical advice</category>
      <category domain="http://securityratty.com/tag/provide recursive">provide recursive</category>
      <category domain="http://securityratty.com/tag/bug">bug</category>
      <category domain="http://securityratty.com/tag/domain">domain</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/WF9dPDOkfS4/icanniana_offer_dns_domain_test.html">ICANN/IANA Offer DNS Domain Test</source>
    </item>
    <item>
      <title><![CDATA[FISMA Report Card News, Formulas, and 3 Myths]]></title>
      <link>http://securityratty.com/article/b5be8b7e91c58d0ef038594276f66108</link>
      <guid>http://securityratty.com/article/b5be8b7e91c58d0ef038594276f66108</guid>
      <description><![CDATA[Ever watch a marathon on TV? Theres the usual formula for how we lay out the day
History of the marathon and Pheidippides
Discussion of the race length and how it was changes so that the Queen could...]]></description>
      <content:encoded><![CDATA[<p>Ever watch a marathon on TV?  There&#8217;s the usual formula for how we lay out the day:</p>
<ul>
<li>History of the marathon and <a title="Pheidippides" href="http://en.wikipedia.org/wiki/Pheidippides" target="_blank">Pheidippides</a></li>
<li>Discussion of the race length and how it was changes so that the Queen could watch the finish</li>
<li>World records and what our chances are for making one today</li>
<li>Graphics of the race course showing the key hills and the &#8220;sprint to the finish&#8221;</li>
<li>Talk about the womens&#8217; marathon including Joan Benoit and Kathrine Switzer</li>
<li>Description of energy depletion and &#8220;The Wall&#8221;</li>
<li>Stats as the leaders hit the finsh line</li>
<li>Shots of &#8220;back-of-the-pack&#8221; runners and the race against yourself</li>
</ul>
<p>Well, I now present to you the formula for FISMA Report Cards:</p>
<ul>
<li>Paragraph about how agencies are failing to secure their data, the report card says so</li>
<li>History and trending of the report card</li>
<li>Discussion on changing FISMA</li>
<li>Quote from Karen Evans</li>
<li>Quote from Alan Paller about how FISMA is a failure and checklist-driven security</li>
<li>Wondering when the government will get their act together</li>
</ul>
<p>Have a read of <a href="http://blogs.zdnet.com/security/?p=1185" target="_blank">Dancho&#8217;s response </a>to the FISMA Report Card.  Pretty typical writing formula that you&#8217;ll see from journalists.  I won&#8217;t even comment on the &#8220;FISMA compliance&#8221; title.  Oh wait, I just did.  =)</p>
<p>Some myths about FISMA in particular that I need to dispell right now:</p>
<ol>
<li><strong>FISMA is a report card:</strong>  It&#8217;s a law, the grades are just an awareness campaign.  In fact, the whole series of NIST Special Publications are just implementation techniques&#8211;they are <em>guidance </em>after all.  Usually the media and bloggers talk about what FISMA measures and um, well, it doesn&#8217;t measure anything, it just requires that agencies have security programs based on a short list of criteria such as security planning, contingency planning, and security testing.  It just goes back to the adage that <a href="http://www.guerilla-ciso.com/archives/150" target="_blank">nobody really knows what FISMA is</a>.</li>
<li><strong>FISMA needs to be changed:</strong>  As a law, FISMA is <em>exactly</em> where it needs to be.  Yes, Congress does have talks about modifying FISMA, but not much has come of it because what they eventually discover after much debate and sword-waving is that FISMA is the way to write the law about security, the problem is with the execution at all levels&#8211;OMB, GAO, and the agencies&#8211;and typically across organizational boundaries and competing master agendas.</li>
<li><strong>There is a viable alternative framework:</strong>  Dancho points out <a href="http://www.ignet.gov/pande/audit/fismaframework0906.pdf" target="_blank">this framework</a> in his post which is really an auditors&#8217; plugin to the existing NIST Framework for FISMA.  Thing is, nobody has a viable alternative framework because it&#8217;s still going to be the same people with the same training executing in the same environment.</li>
</ol>
<p style="text-align: center;"><em><img src="http://farm1.static.flickr.com/47/181917366_70c6423250.jpg?v=0" alt="Urban Myth: Cellular Phones Cause Gas Fires" width="500" height="375" /></em></p>
<p style="text-align: center;"><em>Urban Cell-Phone Fire Myth photo by </em><a href="http://www.flickr.com/photos/bike/" target="_blank"><em>richardmasoner</em></a><em>.  This myth is <a href="http://www.snopes.com/autos/hazards/gasvapor.asp" target="_blank">dispelled at snopes.com</a>.</em></p>
<p>Way back last year I wrote a blog post about <a href="http://www.guerilla-ciso.com/archives/96" target="_blank">indicator species and how we&#8217;re expecting the metrics to go up based on our continual measuring of them</a>.  Every couple of months I go back and review it to see if it&#8217;s still relevant.  And the answer this week is &#8220;yes&#8221;.</p>
<p>Now I&#8217;ve been thinking and talking probably too much about FISMA and the grades over the past couple of years, so occassionally I come to conclusions .  According to Mr Vlad the Impaler, the report card is a bad idea, but I&#8217;m slowly beginning to see the wisdom of it:  it&#8217;s an opportunity to have a debate and to raise some awareness of Government security outside of those of us who do it.  The only other time that we have a public debate about security is after a serious data breach, and that&#8217;s not a happy time.</p>
<p>I just wish the media would stop with the story line that FISMA is failing because the grades provide recursive evidence of it.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/404&amp;title=FISMA+Report+Card+News%2C+Formulas%2C+and+3+Myths" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Del.icio.us" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/404&amp;title=FISMA+Report+Card+News%2C+Formulas%2C+and+3+Myths" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to digg" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/404&amp;title=FISMA+Report+Card+News%2C+Formulas%2C+and+3+Myths" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to reddit" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=FISMA+Report+Card+News%2C+Formulas%2C+and+3+Myths&amp;url=http://www.guerilla-ciso.com/archives/404&amp;version=0.7" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Feed Me Links" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/404" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Technorati" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/404&amp;t=FISMA+Report+Card+News%2C+Formulas%2C+and+3+Myths" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Yahoo My Web" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/404&amp;title=FISMA+Report+Card+News%2C+Formulas%2C+and+3+Myths" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Stumble Upon" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/404&amp;title=FISMA+Report+Card+News%2C+Formulas%2C+and+3+Myths" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Google Bookmarks" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/404" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Squidoo" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/404" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Bloglines" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=CeAzjI"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=CeAzjI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=ZGK9zi"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=ZGK9zi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/299192207" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 27 May 2008 12:36:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/report card">report card</category>
      <category domain="http://securityratty.com/tag/fisma report card">fisma report card</category>
      <category domain="http://securityratty.com/tag/fisma">fisma</category>
      <category domain="http://securityratty.com/tag/fisma measures">fisma measures</category>
      <category domain="http://securityratty.com/tag/fisma compliance title">fisma compliance title</category>
      <category domain="http://securityratty.com/tag/fisma report cards">fisma report cards</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security programs based">security programs based</category>
      <category domain="http://securityratty.com/tag/framework">framework</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/299192207/404">FISMA Report Card News, Formulas, and 3 Myths</source>
    </item>
    <item>
      <title><![CDATA[New Open-Source DNS Server Supports DNSSEC]]></title>
      <link>http://securityratty.com/article/d95e0f93b61e91777f544252b78581a8</link>
      <guid>http://securityratty.com/article/d95e0f93b61e91777f544252b78581a8</guid>
      <description><![CDATA[A group of companies today released a new open-source recursive DNS server. It's an important program. Unbound is so-named to contrast it to BIND (Berkeley Internet Name Domain) , the overwhelmingly...]]></description>
      <content:encoded><![CDATA[A group of companies today released a new open-source recursive DNS server. It's an important program.

<a href="http://www.unbound.net/">Unbound</a> is so-named to contrast it to <a href="http://www.isc.org/index.pl?/sw/bind/index.php">BIND (Berkeley Internet Name Domain)</a>, the overwhelmingly most popular recursive DNS (Domain Name System) server on the Internet. But BIND, which is also open source, is not many people's favorite program. It has <a href="http://www.isc.org/index.pl?/sw/bind/bind-security.php#matrix">a long history of serious security problems</a> and is not considered high performance. 

Recursive, as opposed to authoritative DNS servers, are the bread-and-butter DNS servers used by enterprises and ISPs to connect users to the rest of the Internet's Domain Name System. They cache results locally and pass requests back up to authoritative servers, such as the ones that run big domains like .com. 

Unbound was written by <a href="http://www.nlnet.nl/project/nlnetlabs/">NLnet Labs</a>, <a href="http://www.verisign.com/">VeriSign</a>, <a href="http://www.nominet.org.uk/">Nominet</a> and <a href="http://www.kirei.se">Kirei</a>. Unbound will support DNSSEC, a version of DNS that uses public-key cryptography to protect DNS results, from begriming. Unbound and BIND are the only open-source recursive DNS servers that support DNSSEC.

BIND is bewilderingly popular considering its reputation and performance, and a great deal of this must be due to it being open source and free. After BIND, the next most popular recursive DNS server is probably Microsoft's DNS which, of course, is not open source or free. Perhaps Unbound can change things.


<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=8c07008b82566fafca152fa3b72b5f03" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=8c07008b82566fafca152fa3b72b5f03" style="display: none;" border="0" height="1" width="1" alt=""/><img src="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~4/294311523" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 20 May 2008 06:35:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dns">dns</category>
      <category domain="http://securityratty.com/tag/dns servers">dns servers</category>
      <category domain="http://securityratty.com/tag/authoritative dns servers">authoritative dns servers</category>
      <category domain="http://securityratty.com/tag/popular recursive dns">popular recursive dns</category>
      <category domain="http://securityratty.com/tag/recursive">recursive</category>
      <category domain="http://securityratty.com/tag/protect dns results">protect dns results</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/unbound">unbound</category>
      <category domain="http://securityratty.com/tag/bind">bind</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/294311523/new_open_source_dns_server_supports_dnssec.html">New Open-Source DNS Server Supports DNSSEC</source>
    </item>
  </channel>
</rss>
