The organization that keeps the internet running behind-the-scenes was forced to delay an important update to the global network because it was locked out of one of its own safes.
During routine administrative maintenance of our Key Management Facility on 11 February, we identified an equipment malfunction, explained Kim Davies, the head of the Internet Assigned Numbers Authority (IANA), in an email to the dozen or so people expected to attend a quarterly ceremony in southern California at lunchtime on Wednesday.
The malfunction will prevent us from successfully conducting the ceremony as originally scheduled" on February 12, Davis explained. The issue disables access to one of the secure safes that contains material for the ceremony. In other words, IANA locked itself out.
The ceremony sees several trusted internet engineers (a minimum of three and up to seven) from across the world descend on one of two secure locations one in El Segundo, California, just south of Los Angeles, and the other in Culpeper, Virginia both in America, every three months.
Once in place, they run through a lengthy series of steps and checks to cryptographically sign the digital key pairs used to secure the internets root zone. (Here's Cloudflare's in-depth explanation, and IANA's PDF step-by-step guide.)
At the heart of the matter, simply put, is the Key Signing Key (KSK): this is a public-private key pair, with the private portion kept locked away by IANA. This is because the KSK is used, every three months, to sign a set of Zone Signing Keys, which are used to secure official copies of the internet's root zone file. That file acts as a kind of directory for other parts of the internet, and these parts in turn, provide information on more of the internet. It is, in a way, the blueprint for how the internet as we know it is glued together: how domain names resolve to computers on the global network, so that when you visit, say, theregister.co.uk, you eventually reach one of our servers at network address 220.127.116.11.
Critical root DNS servers are spread out around the planet, each armed with a copy of the latest signed root zone file, and used, in a distributed, cascading manner, by other DNS servers to look up domain names for the internet's users. These servers can check the root zone file underpinning all of this is secured by a ZSK recently signed by the central IANA KSK, and thus can be treated and trusted as gospel. The KSK is thus the domain-name system's trust anchor. Everything relies on it to ensure the 'net's central directory is laid out the way it should be, according to IANA, anyway.
This is all necessary because it should be immediately obvious whether or not a root zone file is an unsigned forgery, or an authentic and clean copy secured by IANA's KSK. Otherwise, a well-resourced malicious organization could potentially fool networks into using a sabotaged root zone file that redirects vast quantities of traffic, i.e. billions of internet users, to different parts of the internet. Even worse, if someone were to get hold of the KSK, they could sign their own zone file and have the internet blindly trust it. The result would be a global loss of trust in the 'net's functioning.
For that reason, IANA takes its Root Key Signing Key Ceremony extremely seriously, and has a complex and somewhat convoluted DNSSEC-based process that briefly unlocks the private portion of the KSK to sign the ZSKs every three months. Only during this ceremony is the KSK used, and put away again when it is over, leaving IANA with a set of ZSKs to authoritatively secure its root zone.
Only specific named people are allowed to take part in the ceremony, and they have to pass through several layers of security including doors that can only be opened through fingerprint and retinal scans before getting in the room where the ceremony takes place.
Staff open up two safes, each roughly one-metre across. One contains a hardware security module that contains the private portion of the KSK. The module is activated, allowing the KSK private key to sign keys, using smart cards assigned to the ceremony participants. These credentials are stored in deposit boxes and tamper-proof bags in the second safe. Each step is checked by everyone else, and the event is livestreamed. Once the ceremony is complete which takes a few hours all the pieces are separated, sealed, and put back in the safes inside the secure facility, and everyone leaves.
But during what was apparently a check on the system on Tuesday night the day before the ceremony planned for 1300 PST (2100 UTC) Wednesday IANA staff discovered that they couldnt open one of the two safes. One of the locking mechanisms wouldnt retract and so the safe stayed stubbornly shut.
As soon as they discovered the problem, everyone involved, including those who had flown in for the occasion, were told that the ceremony was being postponed. Thanks to the complexity of the problem a jammed safe with critical and sensitive equipment inside they were told it wasnt going to be possible to hold the ceremony on the back-up date of Thursday, either.
We understand, however, that following an emergency meeting on Wednesday, the issue should be fixed by Friday, and the ceremony has now been moved to Saturday. In the meantime, some lucky locksmith in Los Angeles is going to have to drill out the safes locking mechanism and put in a new one.
Fortunately, apart from the inconvenience, there is no impact on the internet itself, particularly in this short term. The current arrangement will simply continue to do its job for three additional days. And IANA has been keen to point out that it has an identical set of equipment on the other coast of the US that can also be used if necessary.
We apologize for the inconvenience for the attendees who had already traveled to participate in the ceremony. This is the first time a ceremony has needed to be rescheduled in the 10-year history of KSK management, the email announcing the delay noted.
There is a certain irony, of course, that the security of the virtual internet has been held hostage by an old-school physical safe.
Sponsored: Detecting cyber attacks as a small to medium business
- Cyber Security & Network Security Services - Internet ... - February 18th, 2020
- Google Announced US$1 Million for its Be Internet Awesome Initiative - CISO MAG - February 18th, 2020
- Internet security Market Analysis With Key Players, Applications, Trends and Forecast To 2026 - Instant Tech News - February 18th, 2020
- Cybersecurity Level in the Middle East: An Overview of the Cybersecurity Market State - SCOOP EMPIRE - February 18th, 2020
- Quantum internet: the next global network is already being laid - The Conversation UK - February 18th, 2020
- IC3.gov 2019 Internet Crime Report: Its All About that BEC - Security Boulevard - February 18th, 2020
- Sophos Cloud Optix breakthrough IAM visualization is here - Naked Security - February 18th, 2020
- Stay Safe, Secure And Anonymous Online with The Doe - London Post - February 18th, 2020
- Industry Insight: The CCPAs Elusive Reasonable Security Safe Harbor - JD Supra - February 18th, 2020
- WISeKey Drives Innovations in IoT Security with 23 Strategic Patents in the U.S. - GlobeNewswire - February 18th, 2020
- IT Security Consulting Services Market Size, Share, Types, Growth Strategies, Interactive Components, Key Companies Overview and Forecast Outlook by... - February 18th, 2020
- Market Size of Internet of Things (IoT) Security Product , Forecast Report 2019-2026 - Redhill Local Councillors - February 18th, 2020
- Internet of Things (IoT) Security Market Projected To Witness Vigorous Expansion By 2026 - Instant Tech News - February 18th, 2020
- 40% respondents ready to share personal details on dating apps without meeting person - The News Minute - February 18th, 2020
- How to protect your personal information online during tax season - CTV News - February 18th, 2020
- It is with a heavy heart we must inform you, once again, folks are accidentally spilling thousands of sensitive pics, records onto the internet - The... - February 18th, 2020
- Security of online voting questioned | News, Sports, Jobs - The Daily Times - February 16th, 2020
- This may be the last piece I write: prominent Xi critic has internet cut after house arrest - The Guardian - February 16th, 2020
- An Alternative to Windows 7 - Budapest Business Journal - February 16th, 2020
- North Koreas Internet Use Surges, Thwarting Sanctions and Fueling Theft - The Indian Express - February 16th, 2020
- Microsoft Patch Tuesday fixes IE zeroday and 98 other flaws - We Live Security - February 16th, 2020
- 'More guidance and regulation': Zuckerberg requests government rules on 'what discourse should be allowed' - Washington Examiner - February 16th, 2020
- Internet of Things (IoT) Security Product Market: Development Factors and Investment Analysis by Leading Manufacturers 2018 2026 - TechNews.mobi - February 16th, 2020
- Our personal health history is too valuable to be harvested by the tech giants - The Guardian - February 16th, 2020
- Cyber Security Today The latest FBI Internet crime report, adware on the rise, attacks on Wi-Fi and more - IT World Canada - February 15th, 2020
- Indias proposed internet regulations can threaten privacy everywhere - The News International - February 15th, 2020
- Antivirus Is Not Enough in 2020: Here is Why - laprogressive.com - February 15th, 2020
- FBI: Cybercrime losses tripled over the last 5 years - We Live Security - February 15th, 2020
- AIoT Convergence of Artificial Intelligence with the Internet of Things - EnterpriseTalk - February 15th, 2020
- Indias proposed internet regulations could threaten privacy everywhere - The Verge - February 15th, 2020
- Global Internet of Things (IoT) Security Market Key Players, Share, Trend, Segmentation and Forecast to 2026: Cisco Systems, Intel Corporation, IBM... - February 15th, 2020
- Romance scammers stole $475m last year. Here's how to spot them - Verdict - February 15th, 2020
- Safer Internet Day 2020 Together for a better internet - Security Boulevard - February 14th, 2020
- Here's how to avoid becoming a victim of a tax scam - AZ Big Media - February 14th, 2020
- Will Weak Passwords Doom the Internet of Things (IoT)? - Security Intelligence - February 14th, 2020
- Bithumb Employee Found Guilty of Security Failings that Led to Hack - Cryptonews - February 14th, 2020
- Will your vote count? Ohio working to increase election security - WHIO - February 14th, 2020
- Perimeter 81 Introduces SASE Platform This latest offer is based on a partnership with investor and - Channel Futures - February 14th, 2020
- NHS Secure Boundary the next layer of cyber protection for the NHS - Digital Health - February 14th, 2020
- Global Internet of Things (IoT) Security Market Segmentation along with Regional Outlook, Competitive Strategies, Factors Contributing to Growth and... - February 14th, 2020
- North Koreas Internet Use Surges, Thwarting Sanctions and Fueling Theft - The New York Times - February 14th, 2020
- TechForce Aberdeen event to kick off Cyber Scotland Week - The Scotsman - February 14th, 2020
- Security Strategy: Moving Away From Tried and True - Security Boulevard - February 5th, 2020
- Internet Security Software Market investigated in the latest research - WhaTech Technology and Markets News - February 5th, 2020
- What Is Log Management, and Why Is It Important? - Security Boulevard - February 5th, 2020
- Latest Released 2020 Version Of Internet Security Market With Market Data Tables, Graphs, Figures and Pie Chat - TheLoop21 - February 5th, 2020
- Booter Boss Busted By Bacon Pizza Buy - Krebs on Security - February 5th, 2020
- Yet another Windows 10 fail as new update breaks the internet - heres how to fix it - TechRadar India - February 5th, 2020
- 'Formjacking' Is the New Internet Scam We Need to Watch Out For - q985online.com - February 5th, 2020
- Kiwis think benefits of the internet outweigh the negatives - SecurityBrief New Zealand - February 5th, 2020
- GAO: DHS and Agencies Must Work to Improve Cybersecurity - HSToday - February 5th, 2020
- Government to strengthen security of internet-connected products - GOV.UK - January 31st, 2020
- DigiCert Leads Initiative to Enhance EV SSL Certificates - Security Boulevard - January 31st, 2020
- eScan Internet Security Suite - Download - January 30th, 2020
- Internet Security - January 30th, 2020
- Best malware removal software of 2020: free and paid anti-malware tools and services - TechRadar - January 30th, 2020
- Government to strengthen security of internet-connected products - SecurityNewsDesk - January 30th, 2020
- IoT security: Your smart devices must have these three features to be secure - ZDNet - January 30th, 2020
- Millions of Wawa customers data breached selling on dark web - wobm.com - January 30th, 2020
- DigiCert CEO: Focus Security and Privacy on the Person - Infosecurity Magazine - January 30th, 2020
- CounterAct Cybersecurity Group Launches End-to-End Approach to Help MSPs Protect Their Businesses and Customers from Information Security Threats -... - January 30th, 2020
- The US Space Force Has a Rough Launch on the Internet - WIRED - January 30th, 2020
- Startup MGZN The only Arab company on eSecurity Planet's Top 18 Cybersecurity Startups 2020 is this one! - Startup MGZN - January 30th, 2020
- Bitdefender wants to protect your device for just over 7 dollars, but there's a catch - TechRadar - January 26th, 2020
- How scammers take advantage of stressed-out taxpayers - The Guardian - January 26th, 2020
- Here's the Top Cyber-Security Software You Need To Consider Downloading For 2020 - Grit Daily - January 26th, 2020
- Limited internet to be restored in Kashmir, no access to social media - Reuters - January 26th, 2020
- Analyzing AppFolio (NASDAQ:APPF) and Cyren (NASDAQ:CYRN) - Riverton Roll - January 26th, 2020
- The Rise of the Internet of Things | 2020-01-20 - Security Magazine - January 25th, 2020
- Protecting Websites from Magecart and Other In-Browser Threats - Security Boulevard - January 25th, 2020
- Off-campus wireless internet security on par with University - Kent Wired - January 25th, 2020
- Jeff Bezos Phone Hack Should Terrify Everyone - The New York Times - January 25th, 2020
- Limited internet to be restored in Kashmir, no access to social media - WSAU News - January 25th, 2020
- Cyber Security Today Kids clothes site hacked, a new phony email extortion scam and be careful with Internet Explorer - IT World Canada - January 25th, 2020
- Experts write to government on cyber fixes - Economic Times - January 25th, 2020
- Internet Security Software Market by Types, Applications, Countries and Forecasts to 2026 - Vital News 24 - January 24th, 2020
- An Open Source Effort to Encrypt the Internet of Things - WIRED - January 24th, 2020
- Local News Role of the internet in human trafficking to be highlighted at summit in SLO - KSBY San Luis Obispo News - January 24th, 2020
- Global Internet of Things (IoT) Security Market | By Component,By Type,By Application Area Dagoretti News - Dagoretti News - January 24th, 2020
- Internet Security Market to Reap Excessive Revenues by 2026 Dagoretti News - Dagoretti News - January 19th, 2020