Re: [Add] Followup from ADD session today

Patrick McManus <mcmanus@ducksong.com> Wed, 24 July 2019 20:53 UTC

Return-Path: <mcmanus@ducksong.com>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 829E112060C for <add@ietfa.amsl.com>; Wed, 24 Jul 2019 13:53:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level:
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ducksong.com header.b=YN0A+VVK; dkim=pass (2048-bit key) header.d=outbound.mailhop.org header.b=sGd6Yy0X
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SPx730uFi9A9 for <add@ietfa.amsl.com>; Wed, 24 Jul 2019 13:53:35 -0700 (PDT)
Received: from outbound1g.eu.mailhop.org (outbound1g.eu.mailhop.org [52.28.6.212]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C88B9120285 for <add@ietf.org>; Wed, 24 Jul 2019 13:53:34 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1564001613; cv=none; d=outbound.mailhop.org; s=arc-outbound20181012; b=Pa2KIONwpMDrkYx+KPj6magS8bE0lWXmOrSnWfSusSH01MqglboA8AYXOFObR8aksj1nqq7yMa0jX ZB1X7J/um6ckKKFhH7o9XWTgz31+1Gzw7USt5tABm0eKyNxYUWTTs1oYgAqzvRtPHlaQxPzxus8kOS BybCyBlh+uMLlQPESb/9/oSxl7NFK7wVyibsj36+KboTu4kWB1Do7L/o1sNl3VEjBoWMf3/u4126JG OYlawnUdIW9ikf6nMRuIMkBiVdTCh8R4lCGDzuAjnO6ffeKK0MJXK1FwhjH1f4DjnLFfOUVqPzWddH OjtMw+lvNEAbQ9oAO3YzG8cvlNuD9Ig==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=outbound.mailhop.org; s=arc-outbound20181012; h=content-type:cc:to:subject:message-id:date:from:in-reply-to:references: mime-version:dkim-signature:dkim-signature:from; bh=If/0zu3G+VAc3XWwnMtS+MnZonfy9MielZKdupS5KQQ=; b=PBscxgNKQ+OErwRQ83K9xzS+L+Zr+FxVLiG/zo0UatsYxNRcqS6dI5AS92s7u/ujGb1hmy8POptcd qu+KMludlh0eHH1MBU8qlZUt6W5RjnoYnltDbJEzrUWEklsXK6IuHkSQ7MCWKR0KoZM1qFYc+5M957 lClWLNb4j6Jn87TqSjzUcHUrHa6xaBmJfXebNUf2pRmZYode7+ByBcEvznaT42OvjVEB2xBbPjOypF DIgSy0bl2S/UXZ6+SzqXJFvUCNvPHYDhX729KNMrB1ga6aGKNNbk3WsCwy2Y7ZDliLRVXg0MhPTyai Rk1kPEuJa3aQ9nXNBLMniWqTC/yKcDw==
ARC-Authentication-Results: i=1; outbound3.eu.mailhop.org; spf=pass smtp.mailfrom=ducksong.com smtp.remote-ip=209.85.167.181; dmarc=none header.from=ducksong.com; arc=none header.oldest-pass=0;
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ducksong.com; s=duo-1537391512170-ea99bbb3; h=content-type:cc:to:subject:message-id:date:from:in-reply-to:references: mime-version:from; bh=If/0zu3G+VAc3XWwnMtS+MnZonfy9MielZKdupS5KQQ=; b=YN0A+VVKhU9cLBz76OYzvlJZEKWAYnbQ0n6XuFXegC1xwPs8M5hkaVY59rJ/cToYrYUJ5i/ocks0G 6tYB2Ay2HY3DUpKqs98AJUhnrjx2ZvyUJ3h5G4/OWMTUMfG61TeVxWwkyJlzvN+iJlACUY2uGTDUUq khmghkaMOp3xjxek=
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=outbound.mailhop.org; s=dkim-high; h=content-type:cc:to:subject:message-id:date:from:in-reply-to:references: mime-version:from; bh=If/0zu3G+VAc3XWwnMtS+MnZonfy9MielZKdupS5KQQ=; b=sGd6Yy0XbXvIo3bmqNcTa4T31oaflcqLBCVWdzOGkde3ouI4iBNqmCeMDK9XvGwqbssJytR7UXLgd FcohV8wlhVMK67zzeG0MoJMD3xZlEsJ/bQBQ2tVOrZAtgLaECNKeiEI51v7nKs276zRltKlB4hQX9i /omCa7x15myPm2Ehi1RdaniBXyeU7DHO5NS+nru6fSjRg1A0m1SqlxqnegW5iiCXmbh3cVTIW4kUMM ZHxrXIjJrirrbtRFo7W/IT9BCKz29BfEtT69g/IEcsEtFTz3pclRnwB3xYHPbgPcM1/rCKQf4lpw6X Q+21uh4oj6VSDvjgBU9diutkLDSGV6Q==
X-MHO-RoutePath: bWNtYW51cw==
X-MHO-User: 1793c7ef-ae55-11e9-af75-8714a675f328
X-Report-Abuse-To: https://support.duocircle.com/support/solutions/articles/5000540958-duocircle-standard-smtp-abuse-information
X-Originating-IP: 209.85.167.181
X-Mail-Handler: DuoCircle Outbound SMTP
Received: from mail-oi1-f181.google.com (unknown [209.85.167.181]) by outbound3.eu.mailhop.org (Halon) with ESMTPSA id 1793c7ef-ae55-11e9-af75-8714a675f328; Wed, 24 Jul 2019 20:53:31 +0000 (UTC)
Received: by mail-oi1-f181.google.com with SMTP id m206so36043501oib.12 for <add@ietf.org>; Wed, 24 Jul 2019 13:53:30 -0700 (PDT)
X-Gm-Message-State: APjAAAWmguTCda9T1t7cX9fGmnddg9JoaOjAWbAfjfjmODUfiyE9aWgP ykma6fQdXCmq905mtWZGcyGA084TEWPCeOT/fW0=
X-Google-Smtp-Source: APXvYqyVPrgLxhiAL0vMniE8/VQrzHc6A6S8wY/uvzJKhZT7DZcRXFnr2VIFBqTIGizkcMGSN+Sgz7RZNAp2qmGjpvk=
X-Received: by 2002:aca:ad0f:: with SMTP id w15mr8108295oie.58.1564001610000; Wed, 24 Jul 2019 13:53:30 -0700 (PDT)
MIME-Version: 1.0
References: <WWG1Fgpd10sfGeSNhDiKMUmG4HAaAQVIVcAKP8tgh3SSVpqoZ0OUeW6ItVKBS68AgMAZ_YgwPKaaiJ0GIxyylNJBjPE1A95SP_YpCkJUJ8s=@protonmail.com> <20190724203554.GA5078@laperouse.bortzmeyer.org>
In-Reply-To: <20190724203554.GA5078@laperouse.bortzmeyer.org>
From: Patrick McManus <mcmanus@ducksong.com>
Date: Wed, 24 Jul 2019 16:53:18 -0400
X-Gmail-Original-Message-ID: <CAOdDvNq4sDEEc-fm=LxTZaoDhj3AEkr3uD7Q+YK_VfFU-0jz5w@mail.gmail.com>
Message-ID: <CAOdDvNq4sDEEc-fm=LxTZaoDhj3AEkr3uD7Q+YK_VfFU-0jz5w@mail.gmail.com>
To: Stephane Bortzmeyer <bortzmeyer@nic.fr>
Cc: "Arnaud.Taddei.IETF" <Arnaud.Taddei.IETF@protonmail.com>, "add@ietf.org" <add@ietf.org>, Barry Leiba <barryleiba.mailing.lists@gmail.com>
Content-Type: multipart/alternative; boundary="000000000000646f57058e7380b4"
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/6FakgvJ_FqrKP600ZtSnNcoN1UE>
Subject: Re: [Add] Followup from ADD session today
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Jul 2019 20:53:38 -0000

On Wed, Jul 24, 2019 at 4:37 PM Stephane Bortzmeyer <bortzmeyer@nic.fr>
wrote:

>
> It seems to me a bad idea. If you use DoH, it's because you don't
> completely trust the infrastructure. IMHO, the choice of a DoH server
> should not depend on the local access network.
>
>
I mostly agree with this - trust is not a feature of the network, and you
can't generally can't even be certain what network you are using.

OTOH the locality of a resource is an interesting optimization. So if you
can discover something locally and then find an out of band way to ratchet
up your trust (e.g. a PVD based discovery shows you a resolver that turns
out to have a certificate signed by a trust anchor you trust to vet
resolvers separate from the web PKI) then maybe you've done something
useful.