<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Ainda DNSSec e Dominios b.br</title><link>http://blogs.technet.com/fcima/archive/2007/07/04/ainda-dnssec-e-dominios-b-br.aspx</link><description>Continuo na busca do motivo pelo qual os dominios b.br com DNSSEC garantiriam mais segurança para os usuários de Internet Banking . Um comentário anônimo no meu post anterior deu uma pista: o DNSSEC trabalha em uma camada mais baixa que as outras soluções</description><dc:language>pt-BR</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Ainda DNSSec e Dominios b.br</title><link>http://blogs.technet.com/fcima/archive/2007/07/04/ainda-dnssec-e-dominios-b-br.aspx#1441843</link><pubDate>Thu, 05 Jul 2007 03:32:12 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1441843</guid><dc:creator>fabraz</dc:creator><description>&lt;p&gt;Cima,&lt;/p&gt;
&lt;p&gt;O artigo &amp;quot;Security vulnerabilities in DNS and DNSSEC&amp;quot; pode incrementar ainda mais sua reflex&amp;#227;o. &lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://csdl2.computer.org/persagen/DLAbsToc.jsp?resourcePath=/dl/proceedings/ares/&amp;amp;toc=comp/proceedings/ares/2007/2775/00/2775toc.xml&amp;amp;DOI=10.1109/ARES.2007.139"&gt;http://csdl2.computer.org/persagen/DLAbsToc.jsp?resourcePath=/dl/proceedings/ares/&amp;amp;toc=comp/proceedings/ares/2007/2775/00/2775toc.xml&amp;amp;DOI=10.1109/ARES.2007.139&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Abstract:&lt;/p&gt;
&lt;p&gt;We present an analysis of security vulnerabilities in the Domain Name System (DNS) and the DNS Security Extensions (DNSSEC). DNS data that is provided by name servers lacks support for data origin authentication and data integrity. This makes DNS vulnerable to man in the middle (MITM) attacks, as well as a range of other attacks. To make DNS more robust, DNSSEC was proposed by the Internet Engineering Task Force (IETF). DNSSEC provides data origin authentication and integrity by using digital signatures. Although DNSSEC provides security for DNS data, it suffers from serious security and operational flaws. We discuss the DNS and DNSSEC architectures, and consider the associated security vulnerabilities. &lt;/p&gt;</description></item><item><title>re: Ainda DNSSec e Dominios b.br</title><link>http://blogs.technet.com/fcima/archive/2007/07/04/ainda-dnssec-e-dominios-b-br.aspx#1461386</link><pubDate>Sat, 07 Jul 2007 02:10:38 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1461386</guid><dc:creator>fcima</dc:creator><description>&lt;p&gt;Obrigado pela indica&amp;#231;&amp;#227;o do artigo. Acabei encontrando o artigo completo dispon&amp;#237;vel em &lt;a rel="nofollow" target="_new" href="http://www.isg.rhul.ac.uk/~cjm/svidad.pdf"&gt;http://www.isg.rhul.ac.uk/~cjm/svidad.pdf&lt;/a&gt;. Ele menciona algunsque eu tratei anteriormente, como a depend&amp;#234;ncia na seguran&amp;#231;a dos provedores, e outros problemas como a dificuldade na troca das chaves de criptografia nas zonas principais.&lt;/p&gt;
&lt;p&gt;De qualquer forma, meu objetivo n&amp;#227;o &amp;#233; tentar mostrar que o DNSSEC &amp;#233; inseguro. Isso &amp;#233; uma outra quest&amp;#227;o. O meu ponto &amp;#233; que o DNSSEC n&amp;#227;o traz nenhuma vantagem para o Internet Banking, porque tudo o que ele pode fazer o HTTP com SSL j&amp;#225; faz e muito melhor.&lt;/p&gt;
&lt;p&gt;Abracos e obrigado, - Fernando Cima&lt;/p&gt;
</description></item><item><title>Onde Estão os Domínios B.BR?</title><link>http://blogs.technet.com/fcima/archive/2007/07/04/ainda-dnssec-e-dominios-b-br.aspx#2750928</link><pubDate>Wed, 16 Jan 2008 15:46:05 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2750928</guid><dc:creator>Segurança na Microsoft</dc:creator><description>&lt;p&gt;Em junho do ano passado o Comit&amp;#234; Gestor da Internet anunciou com grande repercuss&amp;#227;o a cria&amp;#231;&amp;#227;o do dom&amp;#237;nio&lt;/p&gt;
</description></item></channel></rss>