Dan Kaminsky
loresecuritynetworking
The researcher who found the 2008 DNS cache-poisoning flaw that affected every resolver at once, and then coordinated the simultaneous multi-vendor patch rather than publishing it.
The weakness was in the protocol, not in one product: DNS matched answers to questions using a 16-bit query identifier, and he showed how to win that race reliably. What makes the episode a landmark is the handling. He was 29, working as a penetration tester, and he took the finding to competing vendors, who shipped a coordinated patch on 8 July 2008 - a month before he presented the detail at Black Hat. Source-port randomisation was the mitigation; DNSSEC was always the real answer. The uncomfortable footnote is that the fix had been proposed years earlier and not adopted, and that patched resolvers were shown to be poisonable in hours. He died in 2021.
Also known as: kaminsky bug, cve-2008-1447