VeriSign is in many ways synonymous with managing the Web, thanks to its handling of key DNS root servers and of name resolution for .com, .net, and other domains. In recent years, it's had both strong ups and strong downs.
On the up side, VeriSign has aggressively pushed PKI, SSL/TLS, EV, and digital certificates, making these authenticated security approaches commonplace. And VeriSign has spent millions of dollars building out and protecting the Internet's massive DNS infrastructure, even though its contract with the DNS's governing body required that VeriSign spend just a fraction of that amount. Although VeriSign's extra investment was a business decision meant to keep its lead as DNS infrastructure manager, the result for Internet users is still a better DNS infrastructure than was required.
On the downside, in the 2005-2007 period, the company angered many users by adding new services to the Internet, such as domain waitlisting, and by raising registration fees. It garnered significant ill will when its Network Solutions domain registration unit (later sold) began redirecting misspelled URLs to ads, causing an uproar among users. When VeriSign met resistance over such actions from ICANN, the global steward of Web domains, it sued the organization. Although that suit was resolved after VeriSign agreed to new ICANN procedures, users and elected officials remained nervous about VeriSign's potential actions. In 2007, the company ran afoul of federal regulators, resulting in its CFO's resignation and a restatement of earnings.
During this same period of ups and downs, VeriSign entered several new lines of business, such as Wi-Fi roaming services, RFID contract resolution (to translate an RFID tag's electronic number to a product's common name), andone-time-use security credentials. More recently, VeriSign has been part of a consortium promoting the OpenID federated certificate standard.
Today, VeriSign is refocused on its Internet roots, after having dropped some of its new ventures, to focus on DNS management. The company processes about 48 billion name resolution requests per day across 60 different locations, peaking at 700,000 queries a second. It is a major provider of PKI technologies and services, including digital certificate products, managed security services, and IT consulting services.
InfoWorld interviewed CTO Ken Silva on the company's current and past challenges. Silva manages VeriSign's technical operations, which handle much of the world's DNS traffic and cryptographically protect millions of Web sites. Before joining VeriSign, Silva spent 10 years with the National Security Agency (NSA). Roger asked about VeriSign's current status and future plans. Here are some excerpts from that interview:
Read more about security central in InfoWorld's Security Central Channel.
Get the independent advice and expertise you need to support a virtual workforce.
The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Read this 2 page white paper now to learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.
Download now »Ensuring acceptable application delivery will become even more difficult over the next few years. As a result, IT organizations need to ensure that the approach that they take to resolving the current application delivery challenges can scale to support the emerging challenges. This handbook elaborates on the key tasks associated with planning, optimization, management and control and provides decision criteria to help IT organizations choose appropriate solutions.
Download now »A common misconception is that mid-range storage requirements are dramatically different than that of a larger enterprise. Mid-range storage users may require less capacity, but they have similar functionality and management requirements. This ESG paper examines mid-range storage needs and reviews a new solution that adjusts size while retaining value, performance and functionality.
Download now »
Sign up to receive Security Resource Alerts
This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.
Download now! »Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.
Download now! »Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.
Download now! »