Re: [Add] data integrity and DNSSEC or DoH/DoT

Alec Muffett <alec.muffett@gmail.com> Fri, 06 September 2019 15:57 UTC

Return-Path: <alec.muffett@gmail.com>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DC1A71200DB for <add@ietfa.amsl.com>; Fri, 6 Sep 2019 08:57:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level:
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FgzxSsm_YzTo for <add@ietfa.amsl.com>; Fri, 6 Sep 2019 08:57:17 -0700 (PDT)
Received: from mail-yw1-xc29.google.com (mail-yw1-xc29.google.com [IPv6:2607:f8b0:4864:20::c29]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E6B97120026 for <add@ietf.org>; Fri, 6 Sep 2019 08:57:16 -0700 (PDT)
Received: by mail-yw1-xc29.google.com with SMTP id f187so2358371ywa.5 for <add@ietf.org>; Fri, 06 Sep 2019 08:57:16 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=d1J+4c2z5wN9JnxyIh8xfIs4caZYVWFCdTXQRmWsCBo=; b=gxMabUTQ0PukJqkaoDHJvZYZIFGCqb9tmjmk6HduKuAq/cNCnwU8PPlpiTQvperB8Y SsNBrxrYkCgaCiiUtmIh23jTUTn9jJZjWAAKNkcDM3PHDtGgyhYLNCchMSOfImfx5R36 u3sRvfNqKn9YXWDHOyJAXLWjlqtNshBfDbP3GY2td66x6YGHRux7XAgYFpibnZm3fGkS l0yfWyUJ7IzC+1JOnDkWEXAqUB0aTjfNROnTDsjv9SEwuByo9uoQVXYrYxS+IRAgaUCh w9HMsHyykNmip+KV8ZReiYwsM8Dv4RJiINOqbi6dGgqVZ+oq4zC190Q7BYbjgOCLbOJw KpCg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=d1J+4c2z5wN9JnxyIh8xfIs4caZYVWFCdTXQRmWsCBo=; b=D2UAcCr2oa9qOedKUbzXlzR0a39xIX3i6SretYXT/qntVgVvKYgyUr1i4KBebSsKkq yrm2rf8F4YctO2L/9v8dZ07qsF+/gXe2W7rFSoKxFR3D2zQnsK6klrNR+y+lGnmiwZ1M 3+iFDRyWFtuDaYH5/wI47Nn9AgohumRtJIkm/Kd1zWEkWm+n+Z0nu6y+tKPNQWOfspqU 2rM8+Ad4Sq0Ykxf8o8tJIBOlEq5XZ4+IZ4NM32hwdVt0TctH/GLYFKVZcnNQ5+/dc723 fVbgWE0c710uI+G+/pXsbh00O4uxNC6VKDgxuVrYt2ntPBcaIJXCzHgzcdo9D+NS0zYb OirQ==
X-Gm-Message-State: APjAAAU686yiS3q43g9zzZOLYpj79m6jVvoXOnEK4T2Zuvak2qsfWYJd nHeMPX3zCB/IkPu8uZO0jBUL4v7DRrGsAVFUFbY=
X-Google-Smtp-Source: APXvYqzwn1svMTub16p3KOTN8r9/qoiwUH2NdrlM3LebVZM1Tx6cU65DZzfe+36AhrIqfM8jnlSYQdYibB4YfdvKmRM=
X-Received: by 2002:a0d:f6c7:: with SMTP id g190mr6699162ywf.13.1567785435974; Fri, 06 Sep 2019 08:57:15 -0700 (PDT)
MIME-Version: 1.0
References: <A1128702-1E19-4657-9740-E84AE09992F2@piuha.net> <CA+9kkMAfuOwJu8_qJTuhAY4mUwR+tVUxr+k3QFHBk3byV672Ow@mail.gmail.com> <A7EA862E-8E80-40E3-834D-E628988C0A24@virtualized.org> <CAFWeb9KT=2JL0oHUgJ2WMcduR3na+hP2QncvRR4YurmqsAWxTA@mail.gmail.com> <59E0EC53-0E30-431C-8376-52C7BFC121A8@virtualized.org> <CAFWeb9+Z7RmXEr46qx5PaUcxh2R3+HXhrZeW-8QEMX4HLt7a-w@mail.gmail.com> <589DAFCB-1BDC-4156-A2CA-179C4559A6B2@virtualized.org> <cf2152d7-8618-7ad2-b8f9-7a259ab5df19@cs.tcd.ie> <683A176C-3CE6-4866-A736-F2A7465FA5B5@rfc1035.com> <CABcZeBPmWYBKcKhjTUBLw62xJT=OXbp3v6MZ+8Gtr=gFmQ-g6A@mail.gmail.com> <E40CC478-BBA1-4DA9-8F6A-FE1782E0F27E@rfc1035.com> <CABcZeBMnG_HJHYrGpQD1LWWNi8zuhAm=0Uy2HNRRmhYS9PsCtg@mail.gmail.com> <06613304-C325-4BA4-AB6F-32D79DFCECA0@open-xchange.com> <CABcZeBMr6WtzbyPPA6W1Da0A9bUoowMVucbBf5K0BQgqZrNdwg@mail.gmail.com> <CAH1iCioWFzHN_hTW4G=0kNHX+2onC64xTSEG-U4miQ1YUH8bSQ@mail.gmail.com> <125944910.3423.1567677431631@appsuite-gw1.open-xchange.com> <alpine.LRH.2.21.1909052317500.4174@bofh.nohats.ca> <795043082.753.1567780338538@appsuite-gw2.open-xchange.com> <CAFWeb9+7qqL7JgR_h3pH=jRKhyKdOyBjt0-5fsqtQ3i7FyBrpg@mail.gmail.com>
In-Reply-To: <CAFWeb9+7qqL7JgR_h3pH=jRKhyKdOyBjt0-5fsqtQ3i7FyBrpg@mail.gmail.com>
From: Alec Muffett <alec.muffett@gmail.com>
Date: Fri, 06 Sep 2019 16:57:07 +0100
Message-ID: <CAFWeb9KsCN9npR-4wba7ygZb8Lk1xTHGNWdSXZLoD_0egbPZbA@mail.gmail.com>
To: Vittorio Bertola <vittorio.bertola@open-xchange.com>
Cc: Paul Wouters <paul@nohats.ca>, ADD Mailing list <add@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000fed3520591e47d45"
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/7zyD9K7g3AV1D3K0aCA2ZM4574c>
X-Mailman-Approved-At: Sat, 07 Sep 2019 09:34:49 -0700
Subject: Re: [Add] data integrity and DNSSEC or DoH/DoT
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 06 Sep 2019 15:57:19 -0000

>
> So why should it be different when the content (via DoH) is a DNS
>> response?
>
>
> Because HTTPS has a security-model of "the URL is the Key, and a chain of
> trust should permit an authoritative response of the content - which need
> not be fixed! - whereas DNS is essentially a search query amongst untrusted
> search engines, some of which are lying for their own reasons/benefit.
>
> That's why.
>



ps: in case I did not make my point obvious enough: the whole point of DoH
is literally to remedy *some* of the risks inherent in the latter, by
layering requests on top of the former.

- a