Did a single security engineer avert a DNS disaster?
By holding off on announcing the patch for the DNS vulnerability, Dan Kaminsky avoided allowing hackers to do something they love to do - wait until someone fixes a problem and then figure out what was done to fix the problem and use that knowledge to attack unprotected platforms. By keeping the fix a secret and coordinating the implementation of the patch, he may have helped divert a major internet disaster. As Kaminsky wrote on his Web site, "After an enormous and secret effort, we've got fixes for all major platforms, all out on the same day. This has not happened before. Everything is genuinely under control."
read more »
Bury