{"id":340,"date":"2019-02-22T00:05:58","date_gmt":"2019-02-21T17:05:58","guid":{"rendered":"http:\/\/www.seven-stones.biz\/blog\/?p=340"},"modified":"2019-02-22T06:03:07","modified_gmt":"2019-02-21T23:03:07","slug":"prevalent-dns-attacks-is-dnssec-the-answer","status":"publish","type":"post","link":"https:\/\/www.seven-stones.biz\/blog\/prevalent-dns-attacks-is-dnssec-the-answer\/","title":{"rendered":"Prevalent DNS Attacks &#8211; is DNSSEC The Answer?"},"content":{"rendered":"\n<p>Recently the venerable<a href=\"https:\/\/twitter.com\/briankrebs\"> Brian Krebs<\/a> covered a <a href=\"https:\/\/krebsonsecurity.com\/2019\/02\/a-deep-dive-on-the-recent-widespread-dns-hijacking-attacks\/\">mass-DNS hijacking attack<\/a> wherein suspected Iranian attackers intercepted highly sensitive traffic from public and private organisations. Over the course of the last decade, DNS issues such as cache poisoning and response\/request hijacking have caused financial headaches for many organisations.<\/p>\n\n\n\n<p>Wired does occasionally dip into the world of infosec when there&#8217;s something major to cover, as they did <a href=\"https:\/\/www.wired.com\/story\/what-is-dns-hijacking\/\">here<\/a>, and Arstechnica published an <a href=\"https:\/\/arstechnica.com\/information-technology\/2019\/01\/a-dns-hijacking-wave-is-targeting-companies-at-an-almost-unprecedented-scale\/\">article<\/a> in January this year that quotes warnings about DNS issues from Federal authorities and private researchers. Interestingly DNSSEC isn&#8217;t covered in either of these.<\/p>\n\n\n\n<p>The eggheads behind the Domain Name System Security Extensions (obvious really &#8211; you could have worked that out from the use of &#8216;DNSSEC&#8217;) are keeping out of the limelight, and its unknown as to exactly how DNSSEC was conceived, although if you like RFCs (and who doesn&#8217;t?) there is a strong clue from <a href=\"https:\/\/tools.ietf.org\/html\/rfc3833\">RFC 3833<\/a> &#8211; 2004 was a fine year for RFCs. <\/p>\n\n\n\n<p>The idea that responses from DNS servers may be untrustworthy goes way back, indeed the <a href=\"http:\/\/tolkiengateway.net\/wiki\/Council_of_Elrond\">Council of Elrond<\/a> behind RFC 3833 called out the year 1993 as being the one where the discussion on this matter was introduced, but the idea was quashed &#8211; the threats were not clearly seen in the early 90s. An even more exploitable issue was around lack of access control with networks, but the concept of private networks with firewalls at choke points was far from widespread.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">DNSSEC Summarised<\/h2>\n\n\n\n<p>For a <a href=\"https:\/\/www.cloudflare.com\/dns\/dnssec\/how-dnssec-works\/\">well-balanced look at DNSSEC, check Cloudfare&#8217;s version<\/a>. Here&#8217;s the headline paragraph which serves as a decent summary &#8220;DNSSEC creates a secure domain name system by adding cryptographic signatures to existing DNS records. These digital signatures are stored in DNS name servers alongside common record types like A, AAAA, MX, CNAME, etc. By checking its associated signature, you can verify that a requested DNS record comes from its authoritative name server and wasn\u2019t altered en-route, opposed to a fake record injected in a man-in-the-middle attack.&#8221;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">DNSSEC Gripes<\/h2>\n\n\n\n<p>There is no such thing as a &#8220;quick look&#8221; at a technical coverage of DNSSEC. There is no &#8220;birds eye view&#8221; aside from &#8220;it&#8217;s used for DNS authentication&#8221;. It is complex &#8211; so much so that&#8217;s it&#8217;s amazing that it even works at all. It is PKI-like in its complexity but PKIs do not generally live almost entirely on the Public Internet &#8211; the place where nothing bad ever happened and everything is always available.<\/p>\n\n\n\n<p><strong>The resources required to make DNSSEC work, with key rotation, are not negligible<\/strong>. A common scenario &#8211; architecture designs call out a requirement for authentication of DNS responses in the HLD, then the LLD speaks of DNSSEC. But you have to ask yourself &#8211; how do client-side resolvers know what good looks like? If you&#8217;re comparing digital signatures, doesn&#8217;t that mean that the client needs to know what a good signature is? There&#8217;s some considerable work needed to get, for example, a Windows 10\/Server 2k12 environment DNSSEC-ready: <a href=\"https:\/\/docs.microsoft.com\/en-us\/previous-versions\/windows\/it-pro\/windows-server-2012-R2-and-2012\/dn593685%28v%3dws.11%29\">client side configuration<\/a>.<\/p>\n\n\n\n<p><strong>DNSSEC is far from ubiquitous<\/strong>. Indeed &#8211; here&#8217;s a glaring example of that:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><br> iantibble$ dig update.microsoft.com dnskey <br><br><\/pre>\n\n\n\n<iframe loading=\"lazy\" src=\"https:\/\/giphy.com\/embed\/1Zbeweu52ZaQE\" width=\"480\" height=\"402\" frameBorder=\"0\" class=\"giphy-embed\" allowFullScreen><\/iframe><p><a href=\"https:\/\/giphy.com\/gifs\/tumbleweed-1Zbeweu52ZaQE\">via GIPHY<\/a><\/p>\n\n\n\n<p>So, maybe i&#8217;m missing something, but i&#8217;m not seeing any Resource Records for DNSSEC here. And that&#8217;s bad, especially when threat modelling tells us that in some architectures, controls can be used to mitigate risk with most attack vectors, but if WSUS isn&#8217;t able to make a call on whether or not its pulling patches from an authentic source, this opens the door for attackers to introduce bad stuff into the network. DNSSEC isn&#8217;t going to help in this case.<\/p>\n\n\n\n<p>Overall the <a href=\"https:\/\/www.statdns.com\/\">provision of DNSSEC RRs for .com domains is less than 10%<\/a>, and there are some interesting stats <a href=\"https:\/\/blog.apnic.net\/2017\/12\/06\/dnssec-deployment-remains-low\/\">here<\/a> that show that the most commonly used Domain Name registrars do not allow users to add DNSSEC records even if they wanted to.<\/p>\n\n\n\n<p><strong>Don&#8217;t forget key rotation &#8211; DNSSEC is subject to key management.<\/strong> The main problem with Cryptography in the business world has been less about brute-forcing keys and exploiting algorithm weaknesses than is has been about key management weaknesses &#8211; keys need to be stored, rotated, and transported securely. <a href=\"https:\/\/twitter.com\/srwoodrow\/status\/1087610707812601856\">Here&#8217;s an example of an epic fail in this area<\/a>, in this case with the NSA&#8217;s IAD site. The page linked to by that tweet has gone missing.<\/p>\n\n\n\n<p><strong>For an organisation wishing to authenticate DNS responses, DNSSEC really does have to be ubiquitous<\/strong> &#8211; and that can be a challenge with mobile\/remote workers. In the article linked above from Brian Krebs, the point was made that the two organisations involved are both vocal proponents and adopters of DNSSEC, but quoting from Brian&#8217;s article: &#8220;On Jan. 2, 2019 \u2014 the same day the DNSpionage hackers went after Netnod\u2019s internal email system \u2014 they also targeted PCH directly, obtaining&nbsp;SSL certificates from Comodo for two PCH domains that handle internal email for the company. Woodcock said PCH\u2019s reliance on DNSSEC almost completely blocked that attack, but that it managed to snare email credentials for two employees who were traveling at the time. Those employees\u2019 mobile devices were downloading company email via hotel wireless networks that \u2014 as a prerequisite for using the wireless service \u2014 forced their devices to use the hotel\u2019s DNS servers, not PCH\u2019s DNNSEC-enabled systems.&#8221;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Conclusion<\/strong><\/h2>\n\n\n\n<p>Organisations do need to take DNS security more seriously &#8211; based on what i&#8217;ve seen most are not even logging DNS queries and answers, occasionally even OS and app layer logs are AWOL on the servers that handle these requests (these are typically serving AD to the organisation in a MS Windows world!).<\/p>\n\n\n\n<p>But we do need DNS. The alternative is manually configuring IP addresses in a load balanced and forward-proxied world where the Origin IP address of web services isn&#8217;t at all clear. We are really back in pen and paper territory if there&#8217;s no DNS. And there&#8217;s also no real, planet earth alternative to DNSSEC. <\/p>\n\n\n\n<p>DNSSEC does actually work as it was intended and its a technically sound concept, and as in <a href=\"https:\/\/krebsonsecurity.com\/2019\/02\/a-deep-dive-on-the-recent-widespread-dns-hijacking-attacks\/\">Brian&#8217;s article<\/a>, it has thwarted or delayed attacks. It comes with the management costs of any key management system, and relies on private and public organisations to DNSSEC-ize themselves (<a href=\"https:\/\/twitter.com\/srwoodrow\/status\/1087610707812601856\">as well as manage their keys<\/a>).<\/p>\n\n\n\n<p>While I regard myself an advocate of DNSSEC deployment, it&#8217;s clear there are legitimate criticisms of DNSSEC. But we need some way of authentication of answers we receive from public DNS servers. DNSSEC is a key management system that works in principle. <\/p>\n\n\n\n<p>If the private sector applies enough pressure, we won&#8217;t be seeing so many articles about either DNS attacks or DNSSEC, because it will be one of those aspects of engineering that has been addressed and seen as a mandatory aspect of security architecture.<\/p>\n\n\n\n<p> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recently the venerable Brian Krebs covered a mass-DNS hijacking attack wherein suspected Iranian attackers intercepted highly sensitive traffic from public and private organisations. Over the course of the last decade, DNS issues such as cache poisoning and response\/request hijacking have &hellip; <a href=\"https:\/\/www.seven-stones.biz\/blog\/prevalent-dns-attacks-is-dnssec-the-answer\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26,150,149,152,148,11,16,151],"tags":[153,154],"class_list":["post-340","post","type-post","status-publish","format-standard","hentry","category-blog","category-dns-attacks","category-dns-hijacking","category-dns-security","category-dnssec","category-information-risk-managment-strategy","category-infosec-strategy","category-security-architecture","tag-dns-security","tag-dnssec"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Prevalent DNS Attacks - is DNSSEC The Answer? - Security Macromorphosis<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.seven-stones.biz\/blog\/prevalent-dns-attacks-is-dnssec-the-answer\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Prevalent DNS Attacks - is DNSSEC The Answer? - Security Macromorphosis\" \/>\n<meta property=\"og:description\" content=\"Recently the venerable Brian Krebs covered a mass-DNS hijacking attack wherein suspected Iranian attackers intercepted highly sensitive traffic from public and private organisations. Over the course of the last decade, DNS issues such as cache poisoning and response\/request hijacking have &hellip; Continue reading &rarr;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.seven-stones.biz\/blog\/prevalent-dns-attacks-is-dnssec-the-answer\/\" \/>\n<meta property=\"og:site_name\" content=\"Security Macromorphosis\" \/>\n<meta property=\"article:published_time\" content=\"2019-02-21T17:05:58+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2019-02-21T23:03:07+00:00\" \/>\n<meta name=\"author\" content=\"itibble@gmail.com\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@seven_stones\" \/>\n<meta name=\"twitter:site\" content=\"@seven_stones\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"itibble@gmail.com\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.seven-stones.biz\\\/blog\\\/prevalent-dns-attacks-is-dnssec-the-answer\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.seven-stones.biz\\\/blog\\\/prevalent-dns-attacks-is-dnssec-the-answer\\\/\"},\"author\":{\"name\":\"itibble@gmail.com\",\"@id\":\"https:\\\/\\\/www.seven-stones.biz\\\/blog\\\/#\\\/schema\\\/person\\\/dd7adbe0152f2279b133661b823e0c28\"},\"headline\":\"Prevalent DNS Attacks &#8211; is DNSSEC The Answer?\",\"datePublished\":\"2019-02-21T17:05:58+00:00\",\"dateModified\":\"2019-02-21T23:03:07+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.seven-stones.biz\\\/blog\\\/prevalent-dns-attacks-is-dnssec-the-answer\\\/\"},\"wordCount\":1144,\"commentCount\":0,\"keywords\":[\"DNS Security\",\"DNSSEC\"],\"articleSection\":[\"Blog\",\"DNS attacks\",\"DNS Hijacking\",\"DNS Security\",\"DNSSEC\",\"Information Risk Managment Strategy\",\"Infosec Strategy\",\"Security Architecture\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.seven-stones.biz\\\/blog\\\/prevalent-dns-attacks-is-dnssec-the-answer\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.seven-stones.biz\\\/blog\\\/prevalent-dns-attacks-is-dnssec-the-answer\\\/\",\"url\":\"https:\\\/\\\/www.seven-stones.biz\\\/blog\\\/prevalent-dns-attacks-is-dnssec-the-answer\\\/\",\"name\":\"Prevalent DNS Attacks - is DNSSEC The Answer? - Security Macromorphosis\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.seven-stones.biz\\\/blog\\\/#website\"},\"datePublished\":\"2019-02-21T17:05:58+00:00\",\"dateModified\":\"2019-02-21T23:03:07+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.seven-stones.biz\\\/blog\\\/#\\\/schema\\\/person\\\/dd7adbe0152f2279b133661b823e0c28\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.seven-stones.biz\\\/blog\\\/prevalent-dns-attacks-is-dnssec-the-answer\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.seven-stones.biz\\\/blog\\\/prevalent-dns-attacks-is-dnssec-the-answer\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.seven-stones.biz\\\/blog\\\/prevalent-dns-attacks-is-dnssec-the-answer\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.seven-stones.biz\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Prevalent DNS Attacks &#8211; is DNSSEC The Answer?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.seven-stones.biz\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.seven-stones.biz\\\/blog\\\/\",\"name\":\"Security Macromorphosis\",\"description\":\"Ian Tibble&#039;s Security Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.seven-stones.biz\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.seven-stones.biz\\\/blog\\\/#\\\/schema\\\/person\\\/dd7adbe0152f2279b133661b823e0c28\",\"name\":\"itibble@gmail.com\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4efc9caa4c914912bcf9dd199b33f34a0d42e56752f4f713cd8d0c5416733603?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4efc9caa4c914912bcf9dd199b33f34a0d42e56752f4f713cd8d0c5416733603?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4efc9caa4c914912bcf9dd199b33f34a0d42e56752f4f713cd8d0c5416733603?s=96&d=mm&r=g\",\"caption\":\"itibble@gmail.com\"},\"description\":\"Author of Security De-engineering, CTO at Seven Stones (Indonesia)\",\"sameAs\":[\"http:\\\/\\\/www.seven-stones.biz\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Prevalent DNS Attacks - is DNSSEC The Answer? - Security Macromorphosis","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.seven-stones.biz\/blog\/prevalent-dns-attacks-is-dnssec-the-answer\/","og_locale":"en_US","og_type":"article","og_title":"Prevalent DNS Attacks - is DNSSEC The Answer? - Security Macromorphosis","og_description":"Recently the venerable Brian Krebs covered a mass-DNS hijacking attack wherein suspected Iranian attackers intercepted highly sensitive traffic from public and private organisations. Over the course of the last decade, DNS issues such as cache poisoning and response\/request hijacking have &hellip; Continue reading &rarr;","og_url":"https:\/\/www.seven-stones.biz\/blog\/prevalent-dns-attacks-is-dnssec-the-answer\/","og_site_name":"Security Macromorphosis","article_published_time":"2019-02-21T17:05:58+00:00","article_modified_time":"2019-02-21T23:03:07+00:00","author":"itibble@gmail.com","twitter_card":"summary_large_image","twitter_creator":"@seven_stones","twitter_site":"@seven_stones","twitter_misc":{"Written by":"itibble@gmail.com","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.seven-stones.biz\/blog\/prevalent-dns-attacks-is-dnssec-the-answer\/#article","isPartOf":{"@id":"https:\/\/www.seven-stones.biz\/blog\/prevalent-dns-attacks-is-dnssec-the-answer\/"},"author":{"name":"itibble@gmail.com","@id":"https:\/\/www.seven-stones.biz\/blog\/#\/schema\/person\/dd7adbe0152f2279b133661b823e0c28"},"headline":"Prevalent DNS Attacks &#8211; is DNSSEC The Answer?","datePublished":"2019-02-21T17:05:58+00:00","dateModified":"2019-02-21T23:03:07+00:00","mainEntityOfPage":{"@id":"https:\/\/www.seven-stones.biz\/blog\/prevalent-dns-attacks-is-dnssec-the-answer\/"},"wordCount":1144,"commentCount":0,"keywords":["DNS Security","DNSSEC"],"articleSection":["Blog","DNS attacks","DNS Hijacking","DNS Security","DNSSEC","Information Risk Managment Strategy","Infosec Strategy","Security Architecture"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.seven-stones.biz\/blog\/prevalent-dns-attacks-is-dnssec-the-answer\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.seven-stones.biz\/blog\/prevalent-dns-attacks-is-dnssec-the-answer\/","url":"https:\/\/www.seven-stones.biz\/blog\/prevalent-dns-attacks-is-dnssec-the-answer\/","name":"Prevalent DNS Attacks - is DNSSEC The Answer? - Security Macromorphosis","isPartOf":{"@id":"https:\/\/www.seven-stones.biz\/blog\/#website"},"datePublished":"2019-02-21T17:05:58+00:00","dateModified":"2019-02-21T23:03:07+00:00","author":{"@id":"https:\/\/www.seven-stones.biz\/blog\/#\/schema\/person\/dd7adbe0152f2279b133661b823e0c28"},"breadcrumb":{"@id":"https:\/\/www.seven-stones.biz\/blog\/prevalent-dns-attacks-is-dnssec-the-answer\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.seven-stones.biz\/blog\/prevalent-dns-attacks-is-dnssec-the-answer\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.seven-stones.biz\/blog\/prevalent-dns-attacks-is-dnssec-the-answer\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.seven-stones.biz\/blog\/"},{"@type":"ListItem","position":2,"name":"Prevalent DNS Attacks &#8211; is DNSSEC The Answer?"}]},{"@type":"WebSite","@id":"https:\/\/www.seven-stones.biz\/blog\/#website","url":"https:\/\/www.seven-stones.biz\/blog\/","name":"Security Macromorphosis","description":"Ian Tibble&#039;s Security Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.seven-stones.biz\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.seven-stones.biz\/blog\/#\/schema\/person\/dd7adbe0152f2279b133661b823e0c28","name":"itibble@gmail.com","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/4efc9caa4c914912bcf9dd199b33f34a0d42e56752f4f713cd8d0c5416733603?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4efc9caa4c914912bcf9dd199b33f34a0d42e56752f4f713cd8d0c5416733603?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4efc9caa4c914912bcf9dd199b33f34a0d42e56752f4f713cd8d0c5416733603?s=96&d=mm&r=g","caption":"itibble@gmail.com"},"description":"Author of Security De-engineering, CTO at Seven Stones (Indonesia)","sameAs":["http:\/\/www.seven-stones.biz"]}]}},"_links":{"self":[{"href":"https:\/\/www.seven-stones.biz\/blog\/wp-json\/wp\/v2\/posts\/340","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.seven-stones.biz\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.seven-stones.biz\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.seven-stones.biz\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.seven-stones.biz\/blog\/wp-json\/wp\/v2\/comments?post=340"}],"version-history":[{"count":18,"href":"https:\/\/www.seven-stones.biz\/blog\/wp-json\/wp\/v2\/posts\/340\/revisions"}],"predecessor-version":[{"id":392,"href":"https:\/\/www.seven-stones.biz\/blog\/wp-json\/wp\/v2\/posts\/340\/revisions\/392"}],"wp:attachment":[{"href":"https:\/\/www.seven-stones.biz\/blog\/wp-json\/wp\/v2\/media?parent=340"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.seven-stones.biz\/blog\/wp-json\/wp\/v2\/categories?post=340"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.seven-stones.biz\/blog\/wp-json\/wp\/v2\/tags?post=340"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}