Google strives to make Public DNS secure
- 05 December, 2009 04:00
- Comments
In an effort to enhance the Web experience and speed things up for users, Google is getting into the DNS business. DNS has privacy and security implications, though, that Google has to take into consideration in providing this service.
I will let my PC World peer David Coursey explain DNS: " DNS is an Internet protocol that acts as both telephone directory and switchboard. It provides for the translation of a URL, such as http://www.pcworld.com/, into the IP address of the server that hosts the site."
Privacy is a concern with virtually everything Google touches. The very nature of many of Google's core offerings is based on cataloging and indexing every possible detail about everything. To provide the best search results, it has to create the most comprehensive site index. To provide the most detailed maps, it has to painstakingly catalog every street in the world. Sometimes the goal of providing information oversteps the privacy boundary.
The privacy concern with Google Public DNS though is more about the Big Brother status that Google achieves by acting as the DNS resolver to the world. With recent purchases like AdMob and Teracent, Google is aggressively expanding its advertising footprint. The ability to monitor and capture detailed Web data from the DNS traffic could be a goldmine for Google.
David Ulevitch, founder of OpenDNS, challenges Google's altruism in his blog post: "Google claims that this service is better because it has no ads or redirection. But you have to remember they are also the largest advertising and redirection company on the Internet. To think that Google's DNS service is for the benefit of the Internet would be naive."
Privacy issues aside, DNS also comes with some inherent security concerns. The Google Code Blog acknowledged the security implications of DNS in the post announcing Google Public DNS. "DNS is vulnerable to spoofing attacks that can poison the cache of a nameserver and can route all its users to a malicious website."
There have been a number of issues discovered with DNS and attacks that exploit weaknesses in DNS in recent years. It was designed in a Utopian era before Internet or Web security were issues. DNSSEC has been developed as a next-generation, more secure implementation of DNS, but it is not yet part of the mainstream.
Google is aware of the security flaws with DNS though and has taken steps to protect against them. "Until new protocols like DNSSEC get widely adopted, resolvers need to take additional measures to keep their caches secure. Google Public DNS makes it more difficult for attackers to spoof valid responses by randomizing the case of query names and including additional data in its DNS messages."
DNS cache poisoning can be a very effective exploit if successful, and Google Public DNS will provide a very tempting target. The steps Google has taken are a good interim action while we wait for the widespread adoption of DNSSEC.
These measures don't address the Big Brother privacy concerns, but that is a whole different battle that Google will have to fight probably as long as it is in the business of indexing the world and providing targeted advertising.
Tony Bradley tweets as @PCSecurityNews, and can be contacted at his Facebook page .
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- Google Public DNS and Your Privacy - PC World
- Stories About Google Inc. - PC World
- Google Public DNS: Wonderful Freebie or Big New Menace? - PC World Business Center
- Domain Name System - Wikipedia, the free encyclopedia
- Uniform Resource Locator - Wikipedia, the free encyclopedia
- Reviews and News on Tech Products, Software and Downloads - PC World
- IP address - Wikipedia, the free encyclopedia
- Google's Swiss Street View Battle Highlights Privacy Challenge - PC World Business Center
- Stories About Big Brother (TV Show) - PC World
- Google Bets on Mobile Advertising with AdMob Purchase - PC World Business Center
- Google's Ad Empire is Good for Small Business - PC World Business Center
- OpenDNS : Internet Navigation And Security
- OpenDNS Blog » Some thoughts on Google DNS
- Google Code Blog: Introducing Google Public DNS: A new DNS resolver from Google
- How DNS Cache Poisoning Works - PC World Business Center
- DNS Hole Prompts Patching Effort by IT Vendors - PC World Business Center
- DNSSEC - The DNS Security Extensions - Protocol Home Page
- @PCSecurityNews
- Incompatible Browser : Facebook
- CommVault Extends its Data Protection and Information Management Strategy with Simpana 9
- Protecting Against the Leading Causes of Data Breach
- 10 Essential Steps to Web Security
- Virtual Certainty - Best Practices for Gaining Monitoring Clarity in VMware Environments
- Blurring boundaries: The disappearing gap between work and home life
-
Drupal gains ground down under
-
NBN build gaining momentum daily: Quigley
-
Chambers: Networking's changing competitive landscape
-
The NBN, service providers and you... what could go wrong?
-
NBN build gaining momentum daily: Quigley
-
Office 2007 All-In-One Desk Reference for Dummies
-
Excel 2007 All-In-One Desk Reference for Dummies
-
MYOB Software for Dummies 6E Australian Edition
-
Windows 7 for Seniors for Dummies®
-
Office 2007 for Dummies
-
Computers for Seniors for Dummies, 2nd Edition
-
Teach Yourself Visually Windows 7
-
Windows 7 for Dummies® Dvd+book Bundle
-
Windows 7 for Dummies®









Comments
Post new comment