DNS Problem Linked to DDoS Attacks Gets Worse
Internet security experts say that misconfigured DSL and cable modems are worsening a well-known problem with the Internet's DNS (domain name system), making it easier for hackers to launch distributed denial-of-service (DDoS) attacks against their victims.
Context & Ripple Effects
Internet security experts are flagging an old weakness in the domain name system that is getting worse rather than better: misconfigured DSL and cable modems on consumer broadband lines now compound the DNS problem, lowering the bar for hackers who want to knock sites offline. With no fix coming from the device side, the burden shifts to network operators and DNS administrators.
First-order effects
- Victims of distributed denial-of-service attacks face heavier traffic floods, because misconfigured consumer modems give attackers an easier path to overwhelm the domain name system.
Second-order effects
- Broadband providers and modem makers come under pressure to correct default configurations on deployed hardware, since their subscribers' devices are the ones doing the damage.
Third-order effects
- If consumer edge devices keep serving as unwitting attack infrastructure, responsibility for securing the Internet's core name-resolution layer will keep migrating away from end users toward ISPs and infrastructure operators.
The trend: Consumer broadband equipment is drifting into the role of attack infrastructure, pushing the cost of defending core services like DNS onto network operators.