The Internet Was Patched in One Day. The Flaw Is Still There.
The 2008 patch that saved DNS never fixed it. Eighteen years on, the flaw sits in the protocol — and the real cure is still mostly unused.
July 8, 2008.
Microsoft, Cisco, Sun and the maker of BIND release patches for their nameservers on the same day. Same flaw, every product.
The advisory describes the fix in detail. The attack gets one sentence.
The man who found it asks for thirty days of silence before he explains.
His name was Dan Kaminsky. What he had found was not a bug in anyone’s product.
It was the protocol.
DNS matches every answer to its question with a 16-bit transaction ID. 65,536 possibilities. Dan Bernstein, the author of djbdns, had flagged the number as guessable back in 1999; mainstream implementations counted on the cache to hold an attacker to a few guesses a day.
Kaminsky’s finding: ask the resolver for names that do not exist. 1.example.com. 2.example.com. Each one is new to the cache, so each one opens a fresh race against the real answer — and a forged answer that wins a single race can inject new records for the entire domain.
Guess until you win, and the resolver is yours. Its users’ web traffic, their email, their password resets — all of it goes where you point it.
Kaminsky called Paul Vixie, the DNS veteran behind BIND. Vixie’s conclusion: “everything in the digital universe was going to have to get patched.”
That is what happened. Quietly, with the vendors — then all at once, on July 8. Kaminsky called it the first synchronized multi-vendor patch release the industry had ever carried out.
The patch did not fix the flaw.
It could not. The 16-bit field sits in the protocol itself; replacing it means replacing DNS. So the patch added a second number to guess — the source port of every query was randomized, roughly sixteen more bits in front of the same design. CERT’s advisory said it openly: without changes to the protocol, these mitigations cannot completely prevent cache poisoning.
An attack that once needed tens of thousands of packets now needs billions. The flaw remains. It just costs more to hit.
The patch was a price increase, not a fix.
The plan gave the world thirty days to patch before Kaminsky explained the technique at Black Hat. It got thirteen — on July 21, a security firm’s blog post spelled the attack out. The post came down quickly. The mirrors did not.
The protocol-level repair exists: DNSSEC. Sign the answers cryptographically, and a forged one fails no matter how many packets the attacker sends.
Geoff Huston, APNIC’s chief scientist, ran the adoption numbers in 2023. 4.3 percent of .com domains were signed. google.com, amazon.com and microsoft.com were not among them. When weighted by traffic, about one percent of the world’s DNS queries ended in a cryptographically validated answer.
Eighteen years after the one-day patch, the price increase is still doing most of the protecting.
If your company’s domain is unsigned — more than 95 percent of .com was at the 2023 count — the barrier between your customers and a forged answer is a guessing game whose odds were last raised in 2008. Signing is a checkbox at your DNS provider and one change-control ticket. In most organizations it is nobody’s job.
In 2010, ICANN selected seven people to hold recovery shares of the key that signs the root of the DNS. Kaminsky was one of the seven. He died in 2021.
The internet gave the man who proved its answers could lie a piece of the key that makes them provable — and kept running on the stopgap.
Magyar változat: [zona.hu/tizennyolc-eve-egy-ideiglenes-megoldas-vedi-az-internetet/]


