Thursday, January 24, 2019

U.S. Government Emergency Directive 19-01 DNS tampering

 On January 22, 2019 the U.S. Department of Homeland Security issued a rare emergency directive to any and all U.S. government agencies to use defined steps to better secure Domain Name Service (DNS) infrastructure.

 With the U.S. government shutdown it is unclear if the directive will be acted upon in a timely manner. Many security certificates have expired thus far due to the shutdown.

 Both tampering with DNS records and security certificates can be used to intercept user traffic to and from government Internet infrastructure. Worse yet, inter-agency traffic can be intercepted and/or altered.

 This can be bad, and almost impossible to detect. Be aware.