Re: [Add] "primary control over DNS routing should lie with..."
Rob Sayre <sayrer@gmail.com> Tue, 28 July 2020 05:33 UTC
Return-Path: <sayrer@gmail.com>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7C8E43A0C87 for <add@ietfa.amsl.com>; Mon, 27 Jul 2020 22:33:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KVIm_eAz0d9x for <add@ietfa.amsl.com>; Mon, 27 Jul 2020 22:33:02 -0700 (PDT)
Received: from mail-il1-x12e.google.com (mail-il1-x12e.google.com [IPv6:2607:f8b0:4864:20::12e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7B2FE3A0C85 for <add@ietf.org>; Mon, 27 Jul 2020 22:33:02 -0700 (PDT)
Received: by mail-il1-x12e.google.com with SMTP id l17so4933052ilq.13 for <add@ietf.org>; Mon, 27 Jul 2020 22:33:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=kwkjznqDUbeovng32DDf/81/aAT1D4ImuqCcsnWxXfo=; b=lnRls4dLevVUuYpJZ3BYFfnYOTB7r4BosQuMfvqZ5h6K119MzVA73LwpoDtBIYIuq/ LiOwpL+oaYZPwH6QVGW4XVZeRCL//ofz4VgBM+lFzdkLk/c1TiSXZh56QUgInubr+3Uw PzR1Ouyb7gwuRAcfMpnXlqrwaY9A4n18tYZ8XDcvQFVzjpFI70cSvmTC49H0cdpk9FGz oESVfvcy9VqaPVj+YdLH2GZklbspLHH429Ox/+LAwbu9ShjGmWBwht0PQ9AOBH2G81yc 7LllFwS5D7c3NPBhmxhJtLtT8aao8rupsDa4M6R+aWfO9y//B22hQahHg6LwjXqz5WH6 AmQA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=kwkjznqDUbeovng32DDf/81/aAT1D4ImuqCcsnWxXfo=; b=tscGWP3TlIEADiEKIPANC/JvdB3Sjaoun/Hsu7cfCGNuHVfDJnI6ysrzVfhGFK0eA0 /SJysZ7sZ7mEA++DUh0CrWGWTT9cYNy4AD7DazP3Fo/V3REnr9uJ+PiH/BWhM30ZHmkP KsQMnktGxuKfNfv4QGytK2LcksAiiP0Ee9CuAtFH4K52Ja4cO+OvViB8UsjmsGOwvIfm /zgL7rL0cclOqOe6RsbFPTBBZ2GZoBkYmUn+WJumvNCjrmSVsqwJfT/MSVkiYPplhhSB 7yYW8lPOvH9Nz0sUFwfew1+dbe5jrQxqM02fdItkTnF8BKPeDQncHPgx1+XYfsAeyY4/ SJ6A==
X-Gm-Message-State: AOAM531o/2siAWe/Z4yXoi1gNewmJdoiCrd0K8zeof/IVfyYHfuOS52P Lh0FkbAWm8mbHwhJ5efwvUx9+kWkJrDWXu2oEfM=
X-Google-Smtp-Source: ABdhPJwTO24qvNA/wMTzxE1P0gibDOywEyVICnruBhd7RV3aMHRmqZpjeY2yECSB93RKjf5I2CTyEfGopUAgst+KQH4=
X-Received: by 2002:a92:858d:: with SMTP id f135mr11374163ilh.257.1595914381608; Mon, 27 Jul 2020 22:33:01 -0700 (PDT)
MIME-Version: 1.0
References: <2583C66A-29E9-43B1-8BF5-DDF3D976DC61@nbcuni.com>
In-Reply-To: <2583C66A-29E9-43B1-8BF5-DDF3D976DC61@nbcuni.com>
From: Rob Sayre <sayrer@gmail.com>
Date: Mon, 27 Jul 2020 22:32:50 -0700
Message-ID: <CAChr6SwP-jk4p_6cgXtFmPuJ+V=AfMKtg_881VJ8GHcB__QE-w@mail.gmail.com>
To: "Deen, Glenn (NBCUniversal)" <Glenn.Deen@nbcuni.com>
Cc: ADD Mailing list <add@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000cecf7e05ab79c5fb"
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/2d-bb2A8mkZj6QgcOk10QVknLmc>
Subject: Re: [Add] "primary control over DNS routing should lie with..."
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Jul 2020 05:33:05 -0000
On Mon, Jul 27, 2020 at 4:24 PM Deen, Glenn (NBCUniversal) <
Glenn.Deen@nbcuni.com> wrote:
> -Taking off my chair hat and posting as a contributor –
>
>
>
> Rob,
>
>
>
> The RFC’s you cite (RFC1958, RFC7624) here, and have cited before when the
> discussion of security models has popped up are seemingly being taking out
> of context and are being raised to a higher level of authority that I
> believe the IAB intended them to be.
>
>
If those documents aren't convincing, you could consult RFC 7258 -
Pervasive Monitoring Is an Attack (aka BCP 188).
>
> Paul makes a very valid point – there are very significant numbers of
> networks in Enterprises, governments, schools, universities, and even homes
> of some highly skilled engineers that will have DoH present on devices,
> operating systems, and applications and will be attempting to do discovery,
> and these networks do have security practices and security systems which
> may interfere with certain discovery approaches – and ADD should be taking
> those things into account the best we can.
>
It is not a valid point. If one owns the devices, then configure them. As
another participant wrote: "From an endpoint's perspective, there is no
authoritative way to distinguish between network administration ('good')
and network attacks ('bad') without some prior knowledge and trust of the
network, such as preinstalled certificate".
thanks,
Rob
>
- [Add] Fwd: New Version Notification for draft-sch… Nick Sullivan
- Re: [Add] New Version Notification for draft-schi… Tommy Pauly
- Re: [Add] New Version Notification for draft-schi… David Schinazi
- [Add] "primary control over DNS routing should li… Paul Vixie
- Re: [Add] "primary control over DNS routing shoul… Rob Sayre
- Re: [Add] "primary control over DNS routing shoul… Adam Roach
- Re: [Add] "primary control over DNS routing shoul… Ted Lemon
- Re: [Add] "primary control over DNS routing shoul… Rob Sayre
- Re: [Add] New Version Notification for draft-schi… Tommy Pauly
- Re: [Add] "primary control over DNS routing shoul… Paul Vixie
- Re: [Add] "primary control over DNS routing shoul… Rob Sayre
- Re: [Add] New Version Notification for draft-schi… Andrew Campling
- Re: [Add] New Version Notification for draft-schi… David Schinazi
- Re: [Add] "primary control over DNS routing shoul… Paul Vixie
- Re: [Add] "primary control over DNS routing shoul… Rob Sayre
- Re: [Add] "primary control over DNS routing shoul… Paul Vixie
- Re: [Add] "primary control over DNS routing shoul… Rob Sayre
- Re: [Add] "primary control over DNS routing shoul… Tony Rutkowski
- Re: [Add] "primary control over DNS routing shoul… Rob Sayre
- Re: [Add] "primary control over DNS routing shoul… Deen, Glenn (NBCUniversal)
- Re: [Add] "primary control over DNS routing shoul… Rob Sayre
- Re: [Add] "primary control over DNS routing shoul… Steffen Nurpmeso