The Monday morning of July 1st was interesting for many reasons. More than a handful major websites were affected, or at least word around the Web is, DNS poisoned, by an exotically named Tiger Mate from Bangladesh.
So, why is this spate of website downtimes interesting?
For one, the ‘DNS poisoning’ seems limited to Malaysian domain websites. Second, the website defacement on these websites include a saucy little message about Malaysians and how we treat our foreign workers. “Respect our workers, we will respect you!” it said.
Duly noted, m@te.
Third and maybe most important of all, the organisations whose websites have been affected (not defaced) include really big brand names in the technology and yes, even security field. These include Google, Dell, Skype, Microsoft and a few of Microsoft’s online properties like Bing and MSN.
Mind you, these are not NGOs, or retail or clothing or health, beauty and fashion websites, but big technology MNCs, many who themselves offer security solutions as well.
Businesses rely on these IT vendors’s systems and solutions to secure their business and IT assets. It does not bode well if vendors purporting security, get hacked themselves!
If a hacker with the will to teach humility, is all it takes to bring down websites for the good part of a business work day, does Malaysia’s critical nationalinformation infrastructures, stand a chance against a team of very focused and very motivated hackers?
History tell us, “Hell, no.”
Even security vendor Kaspersky was not spared during this round of cyber mischief. This brings me back to about five years ago, when I had the honour of meeting founder Eugene Kaspersky in Munich.
The main learning I got from the ruddy-faced Russian, was that every founder of every online security company out there have very good reason to be very paranoid when traversing the WWW.
There’s a saying that goes ‘It takes a thief to catch a thief’, and security experts like Eugene Kaspersky likely knows every trick in the hacker handbook.
If Eugene Kaspersky himself practices austere Web usage, shouldn’t we be following his footsteps? That might damage a lot of businesses however, most especially his own Web security business.
IT BYTES BACK! says: When even tech and security vendors have websites with compromised security, what hope for the rest of us?
UPDATE:
*A nice young man well-versed in the mysterious ways of threats on the WWW has written in to clarify that the vendors are not at fault.
“Saying the vendors are responsible, is akin to saying house owners are responsible for Poslaju losing parcels addressed to them (house owners). IT was MYNIC that got compromised. Nothing the tech vendors could have done, short of not using a .my domain.”
He also shared that Google was able to restore their website ahead of the others, probably because, “Google noticed it faster and could also push out DNS faster, because they run their own.“



