- 12-02-19Meerderheid banken heeft online gegevenstransport niet of onvoldoende beveiligd
- 23-01-19Medische wereld heeft onvoldoende aandacht voor privacy
- 29-12-18Hostingsector publiceert gedragscode abusebestrijding
- 28-12-18Update RFO netwerkstoring
- 24-12-18RFO netwerkstoring
- 13-12-18Reactie op aankondigingen Minister Grapperhaus over kinderporno
- 06-12-18BIT roept IT-professionals op tot actie met Internet Schoon Manifest
- 15-11-18Techsessie: Nieuw access netwerk van BIT
- 14-11-18BIT Nieuwjaarsborrel - THE MATRIX
- 23-08-18BIT-Portal vernieuwd en uitgebreid met two-factor-authenticatie
BIT now has reverse DNS zones signed with DNSSEC
Internet operates with domain names and IP addresses. An IP address is connected to a domain name and that connection has been protected at BIT for the last few years by the implementation of DNSSEC signatures on the DNS traffic.
Clients who wish to do so can enable DNSSEC for their domain names in the BIT-Portal. Simply put, this means that answer of the DNS cannot be altered ‘on route’, which creates more security that when you access httsp://example.nl, you are truly accessing the servers of example.nl.
Since the start of august, BIT also has all its ‘reverse DSN zones’ signed with DNSSEC. Both for IPv4 as for IPv6 addresses! Because domain names come with IP addresses, but you could (roughly) say that IP addresses are always connected to a name. This is called the ‘reverse’ of an IP address and is also in the DNS, like domain names. Since august, BIT has also secured this ‘reverse DNS’ with DNSSEC!
Why now? While we have been implementing ‘forward’ DNSSEC for years? The step from IP to domain name is much less important for the safe operation of the internet than the step from domain name to IP. The chance of someone causing problems by ‘changing’ the name connected to an IP address into something that is not correct, is very small. The biggest risk is in ‘changing’ the IP address connected to a domain name to redirect internet traffic to an incorrect site. We have mostly activated this DNSSEC protection ‘because we can’ and we like to do things thoroughly.
Did you, in consultation with BIT, get the reverses for IP addresses delegated to you and did you arrange their signing yourself? Give us a call, so we can ensure that the delegation to you is also secure!
By: Sander Smeenk