The Internet Corporation for Assigned Names and Numbers (ICANN) recently published its highly anticipated updated list of generic top-level domain applications. Among the myriad submissions, one particular company sparked profound concern within the network industry by applying for the .lan domain. This specific extension currently enjoys widespread utilization by OpenWrt and within various other networking environments. Fundamentally, administrators rely upon it to elegantly allocate and identify devices residing within local area networks.
Potential Hazards: Traffic Hijacking and Network Chaos
In the intricate realm of networking, LAN and WAN stand as incredibly ubiquitous terms. Specifically, LAN designates a Local Area Network. In numerous operational scenarios, systems allocate the .lan suffix directly to local network devices. For instance, the renowned OpenWrt firmware explicitly employs the .lan suffix for exactly this purpose.
According to official OpenWrt documentation, the system elegantly establishes .lan as the default local domain name. Consequently, a device might effortlessly provide local resolution services utilizing a format such as router.lan. Furthermore, countless home routers, sophisticated software routers, and compact office networks universally adopt strikingly similar configurations.
The Danger of External Resolution
The fundamental problem lies in the fact that local network names should solely undergo resolution by local DNS servers. Should a local DNS service fail, a device transition to an alternate network, or a client inadvertently forward a query to a public resolver, these sensitive requests could tragically leak outward. Consequently, this vulnerability creates profound potential for malicious traffic hijacking and widespread systemic confusion.
OpenWrt has previously integrated vital fixes specifically addressing the upstream resolution behavior of dnsmasq. These essential modifications deliberately prevent the erroneous forwarding of certain local address configurations. Unfortunately, these localized patches cannot possibly encompass all disparate router firmwares, countless client devices, and diverse DNS services. Ultimately, the genuine impact remains entirely dependent upon the specific implementation details and the precise local network configuration.
The Awaiting ICANN Approval Process
Analyzing current internet standards reveals that the IANA special-purpose domain name registry already safeguards reserved names such as home.arpa and .local. Specifically, IETF RFC 8375 unequivocally designates home.arpa as the exclusive domain name for residential networks, explicitly demanding that related queries remain securely confined within the local network perimeter. Meanwhile, the .local domain serves primarily for Multicast DNS. Thus, it proves entirely unsuitable as a generic substitute for standard unicast DNS.
Furthermore, ICANN has already resolutely determined to preserve the .internal domain exclusively for private networks and essential internal applications. Currently, the controversial .lan domain languishes merely within the initial application phase. Subsequently, ICANN must conduct a rigorous approval process and navigate a comprehensive public comment period. Given the anticipated volume of fervent objections, whether ICANN will ultimately reject this audacious application remains a subject of intense speculation.
The Applicant Behind the Controversy
It is worth noting that the American company Identity Digital, also known as Coffee Danger, submitted the application for the .lan domain. This particular enterprise possesses a distinct predilection for acquiring an eclectic array of vibrant domain names. Their diverse portfolio famously includes unique extensions discussed in tech forums such as .show, .today, .fan, .fyi, and .events.
Support Our Threat Intelligence
Find our tech and OS security coverage helpful? Support our work today and unlock a 100% ad-free reading experience!