Skip to main content

Attackers Target Internet Root Servers

Although the motivation for the attack remains unknown, early Tuesday attackers launched a distributed denial-of-service attack against the Internet’s core DNS servers, which are ultimately responsible for converting human-friendly site names (like www.digitaltrends.com) to IP numbers (like 209.85.60.103) which computers, routers, and software uses behind the scenes. Think of DNS as the ever-updating address book for the millions of machines on the Internet.

Three of the thirteen top-level root servers—one operated by ICANN, one by the U.S. Department of Defense, and one by UltraDNS—were briefly overwhelmed with the flood of bogus traffic pointed at them from hordes of so-called “zombie” computers around the world, although none of the three ever stopped working entirely. The remaining root servers were unaffected, and, for the most part, Internet users never noticed a major attack was underway. The incident serves as an illustration of the age-old tenet of the Internet’s design to route around damage: the DNS system is decentralized, such that if one host goes offline or becomes unavailable, remaining hosts take over the load.

Recommended Videos

“These zombie computers could have brought the web to its knees, and while the resilience of the root servers should be commended, more needs to be done to tackle the root of the problem—the lax attitude of some users towards IT security,” said Graham Cluley, senior technology consultant at Sophos, in a statement. “Society is almost totally reliant on the Internet for day-to-day communication—it’s ironic that the people who depend on the web may have been the ones whose computers were secretly trying to bring it down.”

Reports indicate that the attack’s origin and coordination of zombie computers may have taken place in South Korea; however, the nature and motivation of the attackers remains unclear. Denial-of-service attacks are typically used by cyber-criminals as an extortion mechanism: they take control of a zombie network and use it to flood a key router, server, or single point of failure for a network provider or business such that the organization’s Internet connectivity grinds to a halt or the server’s crash under the load. Once the attack is underway and proven effective, they blackmail the organization, offering to call off the attack in exchange for cash or other demands. Many organizations targeted by such attacks never go public for fear of damaging their reputation.

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Microsoft calls Recall one of ‘the most secure experiences’ it’s ever built
Recall promotional image.

As part of its Ignite 2024 announcements, Microsoft has provided an update on how its AI-powered Recall feature will work in the context of an IT department. Noting that the company has "heard your feedback," specifically in terms of it needing it to be more "secure and controllable," Microsoft claims to have gotten its ducks in a row for the launch of its controversial new Windows 11 feature.

Microsoft says that Recall "will ship with meaningful security enhancements, including additional layers of data encryption and Windows Hello protection, making it one of the most secure experiences we have ever built." Whether or not this will be enough to satisfy the security community, however, is still to be determined.

Read more
Windows 11 is finally coming to the Quest 3 and Quest 3S
A visualization of Windows being used on a headset.

Microsoft has announced that Windows 11 support is officially coming to the Quest 3 and Quest 3S headsets. The announcement comes as part of Microsoft Ignite 2024, which was otherwise focused on updates to its Copilot AI systems. And though not many details were shared on the mixed reality front, it's nice to see the support finally arrive.

According to the announcement, the update will bring "the full capabilities of Windows 11 to mixed reality headsets" through either a local Windows PC or a Windows 365 Cloud PC. The point, of course, is not to bring PC games into VR, but rather to do to work in mixed reality. You'll be able to have multiple virtual monitors all at your disposal to use however you want, regardless of the physical space you're working in.

Read more
With Copilot Actions, Microsoft brings AI agents to Outlook, Teams, and more
microsoft expanding ai agents 365 copilot early 2025 actions2

Microsoft plans to roll out a slew of new features for its business-facing 365 Copilot products starting early next year, the company announced during its Microsoft Ignite 2024 event on Tuesday.

365 Copilot, which was rebranded from just Copilot in September, enables businesses to incorporate Microsoft Copilot generative AI into its Microsoft 365 family of apps (as well as in Teams) for a $30/employee/month subscription.

Read more