Knowledge Centre

Major net bug 'fixed'

Computer mouse
A serious security flaw that could have put customers of commercial websites at serious risk of fraud has been fixed, according to software engineers.

The weakness affects the Domain Name System (DNS), through which internet-connected computers convert web addresses written in words to a series of numbers. Left unchecked, it would have allowed criminals to 'spoof' almost any website and hijack its traffic – even when the visitor had typed in the correct address.

Security researcher Dan Kaminsky discovered the problem by accident six months ago, since when he has been working secretly to find a fix, alongside a team of experts and software firms such as Microsoft, Cisco and Yahoo.

The silence was broken today, with the simultaneous release of security updates across software providers.

"This hasn't been done before and it is a massive undertaking," Kaminsky said, quoted by BBC News.

Businesses have been advised to make sure that their IT systems are protected by the latest security updates from their software provider.

Most personal computer users should receive the necessary patches automatically as part of their regular updates. Windows users can check that their computers are patched by visiting Windows Update.
Tags: Online

Business insurance is issued by Royal & Sun Alliance Insurance plc, which is authorised and regulated by the Financial Services Authority (Reg No. 202323). All offers subject to availability. For your protection, telephone calls may be recorded or monitored. Discounts based on prices available for like-for-like RSA policies. Apart from Van where following our May 2008 rate review over 10% of customers could pay at least 25% less. Half price breakdown is available to customers buying a Van or Business Car policy starting on or before 31st December 2008. Standalone breakdown is not available.