You Know It Is Time To Re-Think DNS Security When…

You Know It Is Time To Re-Think DNS Security When…

25 February 2008 · No Comments

Hmmm… I know this threat isn’t particularly new, but you would have thought that the internet cabal would have already taken steps to prevent something like this from happening. (Quoting Threat Level: )

The Pakistani government ordered ISPs to censor YouTube to prevent Pakistanis from seeing a trailer to an anti-Islamic film by Dutch politician Geert Wilders. YouTube has since removed the clip for violating its terms of service, but a screenshot of the film, available via Google, shows a crude drawing of a pig defecating with the word Allah underneath it.

Pakistan Telecom complied by changing the BGP entry for YouTube—essentially updating its local internet address book for where YouTube’s section of the internet is. The idea was to direct its internet users to a page that said YouTube was blocked.

Unfortunately, the ISP announced the new route to upstream providers. The upstream providers didn’t verify the new route but accepted it and then passed it along, cascading the bad address around the net, until most everyone using the net on Sunday would have been directed to the Pakistani’s network block. The blunder not only took down YouTube, but also choked the Pakistani ISP, which was quickly deluged with millions of requests for talking cat videos.

So, a repressive government doesn’t like what some European posts to YouTube, and has all of YouTube taken down for everybody.

The ways that such a feat could be replicated and abused are rather disturbing, wouldn’t you say?

Tags: Censorship · Technology · ·