Re: [Add] [Ext] Validity of network administrator role

Frode Kileng <frodek@tele.no> Fri, 16 August 2019 19:55 UTC

Return-Path: <frodek@tele.no>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7BC05120823 for <add@ietfa.amsl.com>; Fri, 16 Aug 2019 12:55:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, TO_MALFORMED=0.1, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=tele.no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jnTMggJ_Brhs for <add@ietfa.amsl.com>; Fri, 16 Aug 2019 12:55:45 -0700 (PDT)
Received: from gorgon.tele.no (gorgon.tele.no [IPv6:2001:700:800::70]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BFA4C120090 for <add@ietf.org>; Fri, 16 Aug 2019 12:55:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=tele.no; s=20180731; h=Content-Transfer-Encoding:Content-Type:In-Reply-To:MIME-Version :Date:Message-ID:From:References:Cc:To:Subject:Sender:Reply-To:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=6aoTOpya23CegzcuK3RxgvBTr98ZAf8KQORD/Nt9jMU=; b=QCFTZ0JRf6nyjS4tcjfIePSjxM CD2lOAlV33gypbq2+JcGxCuvHxU6qtm3+z9Dd6jz2BNokLENAEHo+Mf78EU0wCYb8cwJigBcAvori GJHNRq+yv/QoaOabR0QmdW4cBtvBo5UuwbZYSp3sPB7jg+qeX7cuyLWZOWbGBJw5+QQr8PR9BdN9J J46K6zPdJ2VSix/EgczNamLRE/4I58//GBLU92PHKKCWsVkyu61Q0jc9jABxDJlaEl0/A2R6tUEZk 0M4i813P5kFBvqgJeq1mpDdpKqn0z+o1zscNlpmBAnZy3C77kYwKOV71AhgNyQ+IuaR/d9V+sYZFY mfIeDD8A==;
Received: from pilt1.tele.no ([2001:700:800::20] helo=[IPv6:::1]) by gorgon.tele.no with esmtp (Exim 4.92) (envelope-from <frodek@tele.no>) id 1hyiK6-0004QA-Qa; Fri, 16 Aug 2019 21:55:42 +0200
To: Bret Jordan <jordan.ietf@gmai>
Cc: ADD Mailing list <add@ietf.org>
References: <2D09D61DDFA73D4C884805CC7865E6114E25D279@GAALPA1MSGUSRBF.ITServices.sbc.com> <7766e4b8-9284-6bfc-0e91-19992e95abc4@cs.tcd.ie> <9FF158A5-4D6E-4BBE-8FCF-D54016D09ADC@gmail.com> <26802715-e42d-d47a-d2ac-7f23766c542e@cs.tcd.ie> <F0018FFA-D647-4990-90B4-3042D3F9A370@gmail.com> <E0EF64CD-E9D4-402C-A160-4AA27C0FE5FB@icann.org> <CAH1iCioqUHiDZkR8uVjWBn1kyt0WsWGMyv8rPUTSVz+T19rdcQ@mail.gmail.com> <8e00891f-2aa2-ee11-559a-b5a8967b22d9@nostrum.com> <2C23D415-84F9-4B6C-B67B-0CC3EB600520@gmail.com> <CABcZeBNtgE_rACyMe2ZPo-9TiQoy64=TMKGWD8UU9mwaypQm7A@mail.gmail.com> <MWHPR21MB01929E3203DC2F0C21C49014FAAC0@MWHPR21MB0192.namprd21.prod.outlook.com> <E0AF667A-1782-4A6F-9FD5-740BF20B30DB@gmail.com> <2704899B-E43D-4978-A3C9-30E9E7CEBEBD@fugue.com> <alpine.DEB.2.20.1908152109020.21548@uplift.swm.pp.se> <4CC4C262-BEF4-4B39-ACB1-A595AB66D6CD@gmail.com> <ffea6533-95e8-ad67-3fae-6eb39783ad59@tele.no> <E9031B42-1120-4C28-9B5B-694F8258B3EC@gmail.com>
From: Frode Kileng <frodek@tele.no>
Message-ID: <f2cb3dee-768b-3161-358d-72b46917f99a@tele.no>
Date: Fri, 16 Aug 2019 21:55:42 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.8.0
MIME-Version: 1.0
In-Reply-To: <E9031B42-1120-4C28-9B5B-694F8258B3EC@gmail.com>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/EuFqU2k58kZh0NYRLd9hpU8A5Sw>
Subject: Re: [Add] [Ext] Validity of network administrator role
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Aug 2019 19:55:49 -0000

On 16/08/2019 18:30, Bret Jordan wrote:
> Not every devices supports this.  Please stop using the “endpoints can 
> do everything” argument that been fronted by the “there is nothing 
> wrong camp” for the last 5 years.

How can "your" ISP DNS-filtering solution protect my children when not 
connected that specific network? How can it protect if the end-point 
bypass the network specific DNS using DoT or some "hidden" mechanisms? 
How can a "FQDN matching rule" protect when the malware/"dangerous 
content" is distributed from a previously un-classified source or 
distributed from a source normally considered safe?

Wanting to add competitive advantages compared to other ISPs by offering 
a DNS-based filtering solution is a perfectly good business argument but 
I cannot understand the argument that this is the only or best solution 
for this specific use-case.

Frode


>
> Thanks,
> Bret
> PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050
> "Without cryptography vihv vivc ce xhrnrw, however, the only thing 
> that can not be unscrambled is an egg."
>
>> On Aug 16, 2019, at 12:56 AM, Frode Kileng <frodek@tele.no 
>> <mailto:frodek@tele.no>> wrote:
>>
>> On 15/08/2019 23:58, Bret Jordan wrote:
>> <snip>
>>> If you say that the parental controls you have signed up for and 
>>> paid money for are no longer going to work, you might get a 
>>> different answer.
>>
>> There are numerous other client-side child-safe products in the 
>> markets that will continue to work perfectly well. Please please stop 
>> using this "save the children" argument that has been fronted by the 
>> "anti-encryption camp" for the last 5 years.
>>
>> frodek
>>
>>
>>
>>
>> -- 
>> Add mailing list
>> Add@ietf.org <mailto:Add@ietf.org>
>> https://www.ietf.org/mailman/listinfo/add
>