{"id":12286,"date":"2020-05-04T11:38:00","date_gmt":"2020-05-04T15:38:00","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=12286"},"modified":"2020-04-29T00:18:15","modified_gmt":"2020-04-29T04:18:15","slug":"eliminate-threats-to-your-domain-with-a-registry-lock","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/eliminate-threats-to-your-domain-with-a-registry-lock\/","title":{"rendered":"Eliminate Threats to Your Domain with a Registry Lock"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">DNS attacks are up 34%, according to IDC&#8217;s annual threat report. Here&#8217;s what to know about the growing need for domain safety.<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In 2019, several<a href=\"https:\/\/apnews.com\/9c71e3de89e54e52b0c13bf23f0f153c\" target=\"_blank\" rel=\"noreferrer noopener\"> leading security organizations<\/a>, including corporations like Akamai, Cisco, FireEye, and Talos, joined forces to inform the public and private organizations of the growing threat of domain name systems (DNS) or DNS hijacking. They were joined by international government agencies that included the U.S. Department of Homeland Security\u2019s Cybersecurity and Infrastructure Security Agency (CISA) and the UK National Cyber Security Centre.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The targets of the most recent attacks were corporate, telecommunication, government, and other infrastructure entities \u2014 the main aim seemed to be a direct effort to redirect emails and website traffic to collect sensitive information. <a href=\"https:\/\/www.csoonline.com\/article\/3402678\/dns-hijacking-grabs-headlines-but-its-just-the-tip-of-the-iceberg.html\" target=\"_blank\" rel=\"noreferrer noopener\">These attacks made headlines<\/a>, but experts believe we are only seeing the tip of the iceberg concerning the number and breadth of these attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But why are DNS hackings such an issue? And what can you do to protect your organization\u2019s domain registry?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why DNS Hijackings Are an Issue<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">DNS hijackings pose major threats to both government and private organizations for a couple of big reasons. Firstly, it can result in major data breaches, but more importantly, it can result in a privacy nightmare, especially when looking at the stringent government privacy policies that have been put in place like the<a href=\"https:\/\/gdpr-info.eu\/\" target=\"_blank\" rel=\"noreferrer noopener\"> European Union\u2019s (EU\u2019s) General Data Protection Regulation<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">DNS hijackings form an increasingly important \u2014 and increasingly dangerous \u2014 part of the threat landscape. According to <a rel=\"noreferrer noopener\" href=\"https:\/\/www.efficientip.com\/wp-content\/uploads\/2018-DNS-Threat-Report-Press-Release.pdf\" target=\"_blank\">recent research from IDC and efficient iP<\/a>:\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><em>\u201cTwo-in-five (40%) organizations suffered cloud outages and one-third (33%) of respondents were victims of data theft. One-in-five (22%) businesses had lost business due to DNS attacks.\u201d&nbsp;<\/em><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Even more worrying is the fact that the global average cost per DNS attack <a rel=\"noreferrer noopener\" href=\"https:\/\/www.efficientip.com\/news\/dns-threat-report-2018\/\" target=\"_blank\">has increased by 57%<\/a>, their data indicates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By using the collected information, hackers also have the opportunity to launch sophisticated phishing attacks on both employees and customers using a company\u2019s own domains to<a href=\"https:\/\/www.mailpoet.com\/blog\/how-spam-and-phishing-filters-work\/\" target=\"_blank\" rel=\"noreferrer noopener\"> make the phish appear authentic<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Is a Domain or Registry Lock?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Though some new and innovative communications-solutions,<a href=\"https:\/\/www.getweave.com\/business-texting\/\" target=\"_blank\" rel=\"noreferrer noopener\"> such as business texting<\/a>, have come to the foreground when it comes to an organization\u2019s online communication strategies, the domain name is still the essence of an organization or business\u2019s online operations. Usually linked to the business name or entity it represents, it would render any business or entity \u201cunfindable\u201d should it stop working, and all emails linked to the domain would cease to function.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In short, the <a href=\"https:\/\/www.digicert.com\/blog\/the-consquences-of-domain-hacking\/\" target=\"_blank\" rel=\"noreferrer noopener\">consequences of a domain hijacking<\/a> and the cost to the registered owner of a domain can be massive and far-reaching. And these <a rel=\"noreferrer noopener\" href=\"https:\/\/webprofessionals.org\/7-ways-hackers-avoid-detection\/\" target=\"_blank\">hijackers know how to avoid detection<\/a>. That is why domain security consists of \u201clocks,\u201d a variety of software rules that prevents changes to a domain\u2019s registration unless a set of predetermined criteria is met. The highest level of protection for a domain name is a registry lock \u2014 also called a domain lock, registrar lock, or domain transfer lock \u2014 where an area or zone operator (e.g. SIDN for .nl) secures a limitation on a domain name.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are <a href=\"https:\/\/www.cscdigitalbrand.services\/blog\/confused-about-domain-locks\/\" target=\"_blank\" rel=\"noreferrer noopener\">various types of domain locks<\/a>, and they can be implemented in different ways. The two main types are those that focus on the client, and those that focus on the server level. The fundamental idea, however, is the same in all types of domain lock: these will stop unauthorized deletion or manipulation of a domain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With a registry lock in place, nothing on a domain name\u2019s registration can be changed without registry approval by the registrant.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">When Is a Registry Lock Essential?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.symantec.com\/content\/dam\/symantec\/docs\/reports\/istr-22-2017-en.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">According to Symantec<\/a>, the economy has been losing over $400 billion annually as a result of domain hijacking and related crimes. When looking at the latest published reports highlighting the<a href=\"https:\/\/thetokenist.io\/financial-statistics\/\" target=\"_blank\" rel=\"noreferrer noopener\"> personal and nationwide financial statistics in America<\/a>, it means that there are literally millions of domain names in the U.S. alone that can\u2019t afford to be without a lock. Locks are also desirable when a domain name is very valuable, as these are often targeted by hijackers. As such, every website admin should know how to<a href=\"https:\/\/www.thesslstore.com\/blog\/dns-poisoning-attacks-a-guide-for-website-admins\/\"> guard against DNS hijacking attacks<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Lenovo and Google<a href=\"https:\/\/www.pcworld.com\/article\/2889392\/like-google-in-vietnam-lenovo-tripped-up-by-a-dns-attack.html\" target=\"_blank\" rel=\"noreferrer noopener\"> have been hijacked in the past<\/a>, and they are but two of some very high-profile domains that have been attacked. But a registry lock may not be an ideal solution for all domain names. In fact, in certain cases, using a registry lock would be downright inconvenient. The delay in updates and the additional administrative workload that comes with a registry lock might mean that the drawbacks outweigh the benefits for some businesses. However, some domain names are so crucial (e.g. a search engine, bank or government department) that even a brief hijack could cost the domain owner millions.<\/p>\n\n\n<span style=\"--tl-form-height-m:861.156px;--tl-form-height-t:899.625px;--tl-form-height-d:899.625px;\" class=\"tl-placeholder-f-type-shortcode_12653 tl-preload-form\"><span><\/span><\/span>\n\n\n\n<h2 class=\"wp-block-heading\">Why Registry Locks Are Controversial<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Despite being a much-needed part of any organization\u2019s online security measures, registry locks are not very popular within the domain name industry. In fact, it is much easier to find your perfect domain name through a<a href=\"https:\/\/bestwebhostingaustralia.org\/domain-name-generators\/\" target=\"_blank\" rel=\"noreferrer noopener\"> domain name generator<\/a>, than it is to secure a registrar that can cater to all your security needs.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">There\u2019s No Standardization Among Registry Locks<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The main reason being that a registry lock safeguards against all hacks, including the hacking of a registrar or hosting platform. By offering registry locks, a registrar effectively acknowledges that his platform is fallible and not 100% secure against hacking. And, as we all know, no one is going to want to admit to that.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Furthermore, there\u2019s also a major need for a good internationally accepted e-ID system. A lot of human effort is currently needed to verify a customer&#8217;s identity in order to set up a registry lock \u2014 a process that comes with higher cost-implications. This<a href=\"https:\/\/www.centr.org\/news\/news\/standardisation-in-domain-name-analysis.html\" target=\"_blank\" rel=\"noreferrer noopener\"> lack of standardization is an industry-wide issue<\/a> as a .com lock works differently from a .info or .org lock, leading to a lot of complexities for international companies hosting multiple domains.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"640\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/domain-name-lock-1024x640.jpg\" alt=\"Graphic: Keyboard illustration of domain name locks for TLDs\" class=\"wp-image-12129\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/domain-name-lock-1024x640.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/domain-name-lock-300x188.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/domain-name-lock-768x480.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/domain-name-lock-1536x960.jpg 1536w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/domain-name-lock.jpg 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">The Demand for Registry Locks Is Rising<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The demand for registry locks <a href=\"https:\/\/www.sidn.nl\/en\/news-and-blogs\/registry-locks-great-potential-but-little-current-demand\" target=\"_blank\" rel=\"noreferrer noopener\">is on the rise<\/a>, especially amongst larger corporations and businesses. This forms part of a broader move toward enhanced cybersecurity for businesses, which are implementing a range of tools to protect their online platforms. The last few years have seen the use of <a href=\"https:\/\/www.thesslstore.com\/blog\/digicert-leads-initiative-to-enhance-ev-ssl-certificates\/\">enhanced SSL certificates<\/a> and encryption become standard practice for helping to secure websites. Registry locks are likely to be the next key technology that helps to secure your website, but specifically on the domain front.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As cybersecurity awareness grows, the online community is increasingly becoming aware of the value a safe and secure domain name brings. As such, unprotected names are being recognized as vulnerabilities. Domain names are, quite interestingly, also being pledged as collateral for business loans \u2014 and in these instances, the domain owners are doing everything in their power to keep the domain names safe.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The rise of electronic ID is also significant as it leads to less administrative burdens, effectively lowering the threshold of getting a domain name locked. It is, therefore, no surprise that more and more international registries are indicating plans to introduce domain transfer locks or to expand on their current safety offerings.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Final Thoughts<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Given the global rise in domain name system hijacking attacks, it has become a fundamental necessity for business owners and those responsible for an organization\u2019s online operating structure to understand not only the scope and scale of the threats that exist but to also educate themselves on the availability and the intricacies of the solutions they have at their disposal to safeguard themselves.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Too many business or brand owners have a false sense of security when it comes to their domain safety when looking at their current safety offering as provided by their hosting company or registrar. More comprehensive solutions should be considered to ensure the adequate level of protection they require.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>DNS attacks are up 34%, according to IDC&#8217;s annual threat report. Here&#8217;s what to know about the growing need for domain safety. In 2019, several leading security organizations, including corporations&#8230;<\/p>\n","protected":false},"author":15,"featured_media":12287,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[16],"tags":[11927,11928],"class_list":["post-12286","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hashing-out-cyber-security","tag-domain-security","tag-registry-locks","post-with-tags"],"views":15780,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/04\/registry-lock-domain-lock.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/12286","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=12286"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/12286\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/12287"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=12286"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=12286"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=12286"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}