Re: [Add] data integrity and DNSSEC or DoH/DoT

Rob Sayre <sayrer@gmail.com> Fri, 23 August 2019 04:54 UTC

Return-Path: <sayrer@gmail.com>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9C84912080B for <add@ietfa.amsl.com>; Thu, 22 Aug 2019 21:54:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.997
X-Spam-Level:
X-Spam-Status: No, score=-1.997 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nFsk1yIEDOM6 for <add@ietfa.amsl.com>; Thu, 22 Aug 2019 21:54:03 -0700 (PDT)
Received: from mail-io1-xd35.google.com (mail-io1-xd35.google.com [IPv6:2607:f8b0:4864:20::d35]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DE9FD120C27 for <add@ietf.org>; Thu, 22 Aug 2019 21:54:02 -0700 (PDT)
Received: by mail-io1-xd35.google.com with SMTP id j4so8850431iog.11 for <add@ietf.org>; Thu, 22 Aug 2019 21:54:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=DsIZJEQZYyotwkqC5QG/LN2Hd1nbSDe408CO+KqwyiU=; b=q1+Z1sVY5tSQiY1kP6hwGfMM5x9HP3FUJI/ub+U3k/8OqJf6rE3QQAmCHhH/1Rl6zw G3ep4l+7dITXQzA0hgEqwA2ds8Dx+sYqKQdWBgL3rz6wXUa0++kkGZNLyzqt6WIju0NJ HwmNVamIELUTVB67E+2n0HSJ4wCUCoO0B9MhqwQPaa38aCU+jLiBJPPRNW05llw0MGTb ol6PRK67LAN+1wOtbtprscM0utwJnP+ovtr/fe09Mb5lx9zV9MhvJBrIrCy2rxjCLad6 uBuf35Iodbm+yFh/EUVAWnzPSy2+Oal7/pzrwkO+eVbkb6Ln82c8RKrAGeT5j+doZswA YF1Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=DsIZJEQZYyotwkqC5QG/LN2Hd1nbSDe408CO+KqwyiU=; b=HRQFBd5vJbk+HQ+RkghOxhg16EmIRCUlX+HyC+CizMEkRiBt2RZBN9Scpas3lMtyGT PgVfSwuiI3A0/3liS2WS8SUMu89s9fssqkc1Iwa/dXs8Cnm0XlJ2XWBTBmmDLI+L54yK lVXBXJon2MunO8z5QRqPssin7AWmBR8qbiqBeeU90opJcCGXAaY/SbKcedm5ifhIxyxb BwgdnnYZMHxXpwFacl5T1noCIrYIMnc8XyuTx35JWQG2cjtCH0FvhTKc7VXixIJuGY1K sbkxBcJXkSHOKwK0yG6k9d/p6nAcIaf6n453VSyixHyzOrw9DpIrBsgd6RCuKjK+svES gzNw==
X-Gm-Message-State: APjAAAW1quE+nEDwm1cUlspdr/8EiCIAANofVW9DnkxyKM651s4vQvmf txCN+KSKlHiPydK4lDG9kJ6dhG0MNCzsmiIIFks=
X-Google-Smtp-Source: APXvYqy5AEEJbFXxovTND8WEEGnXYzbuxzmrbIi6UiEtO3S+Urz6L/kbNTbzt+DhD6BWPCaNyGiOZW0GVXq9REEB8+E=
X-Received: by 2002:a05:6638:a09:: with SMTP id 9mr3134190jan.95.1566536042008; Thu, 22 Aug 2019 21:54:02 -0700 (PDT)
MIME-Version: 1.0
References: <A1128702-1E19-4657-9740-E84AE09992F2@piuha.net> <CABcZeBMfOTjq-8hDDoKMtJvfHUA5nC8o60zuk-2Xe-ZhfwriJQ@mail.gmail.com> <766112E1-F532-4C6B-8CA8-A096671E02EE@piuha.net> <CA+9kkMAfuOwJu8_qJTuhAY4mUwR+tVUxr+k3QFHBk3byV672Ow@mail.gmail.com> <A7EA862E-8E80-40E3-834D-E628988C0A24@virtualized.org> <CAFWeb9KT=2JL0oHUgJ2WMcduR3na+hP2QncvRR4YurmqsAWxTA@mail.gmail.com> <59E0EC53-0E30-431C-8376-52C7BFC121A8@virtualized.org> <CAFWeb9+Z7RmXEr46qx5PaUcxh2R3+HXhrZeW-8QEMX4HLt7a-w@mail.gmail.com> <589DAFCB-1BDC-4156-A2CA-179C4559A6B2@virtualized.org> <cf2152d7-8618-7ad2-b8f9-7a259ab5df19@cs.tcd.ie> <683A176C-3CE6-4866-A736-F2A7465FA5B5@rfc1035.com> <CABcZeBPmWYBKcKhjTUBLw62xJT=OXbp3v6MZ+8Gtr=gFmQ-g6A@mail.gmail.com> <E40CC478-BBA1-4DA9-8F6A-FE1782E0F27E@rfc1035.com> <CABcZeBMnG_HJHYrGpQD1LWWNi8zuhAm=0Uy2HNRRmhYS9PsCtg@mail.gmail.com>
In-Reply-To: <CABcZeBMnG_HJHYrGpQD1LWWNi8zuhAm=0Uy2HNRRmhYS9PsCtg@mail.gmail.com>
From: Rob Sayre <sayrer@gmail.com>
Date: Thu, 22 Aug 2019 21:53:49 -0700
Message-ID: <CAChr6Sx9a7mZmjd0dAA-7bmBJh3E14RvQ8msdy0O6WyaFdqNPw@mail.gmail.com>
To: Eric Rescorla <ekr@rtfm.com>
Cc: Jim Reid <jim@rfc1035.com>, ADD Mailing list <add@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000004fdb4b0590c198ae"
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/OH5--b5g593N9Hu31OnSAsrQbgQ>
Subject: Re: [Add] data integrity and DNSSEC or DoH/DoT
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 Aug 2019 04:54:07 -0000

On Thu, Aug 22, 2019 at 9:50 PM Eric Rescorla <ekr@rtfm.com> wrote:

> On Thu, Aug 22, 2019 at 1:41 PM Jim Reid <jim@rfc1035.com> wrote:
>
>> I'm surprised that distinction matters to you. I thought any form of DNS
>> blocking or filtering was malicious from your PoV. :-)
>>
>
> Smiley or no, this really doesn't seem like it advances the conversation.
>

I agree with Ekr.

thanks,
Rob