
CyberWire Daily
It’s always DNS, but that may just be FUD.
Feb 14, 2024
Ann Johnson, Director for Cyber and Critical Infrastructure Security, talks with Frank Cilluffo about cyber threats to critical infrastructure. They discuss DNS attacks, FUD in cybersecurity marketing, a government email server breach, a class-action lawsuit by law enforcement, and burglaries using Wi-Fi jammers. Additionally, they touch on a copyright case against OpenAI and Microsoft's security patch update.
29:11
Episode guests
AI Summary
AI Chapters
Episode notes
Podcast summary created with Snipd AI
Quick takeaways
- A critical DNS sec flaw called key trap poses a serious threat to the availability of essential internet services, requiring a redesign of DNS sec core principles.
- A report on fear, uncertainty, and doubt (FUD) in cybersecurity highlights the need for a critical approach to understanding and addressing cybersecurity risks.
Deep dives
DNS sec flaw threatens internet infrastructure
Researchers have discovered a critical DNS sec flaw called key trap that poses a serious threat to the availability of essential internet services like web browsing and email. The flaw, present for over two decades, exploits a design vulnerability that can exhaust CPU resources, affecting over 31% of web clients. Though patches have been released, fully mitigating the threat requires a redesign of DNS sec core principles.
Remember Everything You Learn from Podcasts
Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.