
Photo: Natalia Chernohatova / Octagon.media / TASS
On January 30, from about 18.40 Moscow time, users of the Russian segment of the Internet began to face errors of DNS-reolning (transforming a request into an IP address that allows the browser to find a site requested by the user by name) of domains located in the .ru zone.
DNS is an “address book”, from where the browser receives IP data, to which you need to go to get to the site requested by the user.
The failure touched on the work of services, the sites and services of which use domains in the .ru zone, including almost all services of various Internet providers.
In the service “Monitoring of failures”, the number of complaints grew from the main radio frequency center.
Problems were observed in the work of the largest sites, including Yandex, Ozon, Avito and Sberbank. Many mobile applications did not work - for example, to call a taxi.
Rozetked carts notes that the subscribers of MegaFon, MTS and other operators have experienced difficulties. Most of the failures were recorded in Moscow, St. Petersburg, Krasnodar Territory, Bashkiria and the Kostroma region. But they did not affect all users even within the same region. Problems were also observed when trying to use Russian applications from abroad, as well as when going to sites using the services of bypassing locks.
The mincifers stated that the problem is related to DNSSEC, the department promised to restore access to sites in the near future. DNSSEC is a set of extensions of the DNS protocol, which allows you to check the integrity and reliability of the transmitted and received data. DNSSEC protocols check authenticity using digital signatures based on cryptography. If the authenticity of the signature is confirmed, then DNS data are considered real and returned to the user. If the signature does not undergo authenticity, then the recolver suggests that there was an attack, gets rid of the data and informs the user about the error.
The reason for the current failure was mass errors in determining the authenticity of digital signatures of domains located in the .ru zone.
At 20.35, the Coordination Center for Domains .ru/. RF published an official statement in which he also announced the “technical problem” related to Densec: “The Coordinating Center for Domains *.ru/.RF reports that there was a technical problem raising the *.ru zone related to the global DNSSEC infrastructure. Specialists of the Technical Center of the Internet and MSC-IX are working on its elimination. Currently, for NSDI subscribers, the problem has been solved. Recovery work is underway. We will keep you know the situation. ”
NSDI is a national domain name service. It is the experiments to create it, as the project “Network Freedom” suggests , that could lead to a large -scale malfunction. The authors of the project write that the Russian authorities planned to transfer all users of the country to the DNS national server; Perhaps this is happening now.
According to the telegram channel of the journalist Mikhail Klimarev* “Zelecom”, the Monitoring and Management Center for public communication network really directed the providers with a requirement of up to 23.00 “Follow the RKN requirement and connect to the NSDI servers (National Denssec Validation on DNS servers”, despite the shutdown Signs of digital signature can lead to an increase in the number of fraudulent operations.
The Russian authorities have long warned that they would try to transfer all users of the country to the DNS national server. Probably, this was exactly what happened on the night of January 31. A few hours later, Runet was “fixed”.
Elena Belyaeva