Re: [Add] draft-arkko-abcd-distributed-resolver-selection

Rob Sayre <sayrer@gmail.com> Mon, 23 March 2020 21:19 UTC

Return-Path: <sayrer@gmail.com>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DE1C23A0ECB for <add@ietfa.amsl.com>; Mon, 23 Mar 2020 14:19:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jZOumr2FZu5D for <add@ietfa.amsl.com>; Mon, 23 Mar 2020 14:19:52 -0700 (PDT)
Received: from mail-io1-xd33.google.com (mail-io1-xd33.google.com [IPv6:2607:f8b0:4864:20::d33]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8C6F03A0ED9 for <add@ietf.org>; Mon, 23 Mar 2020 14:19:52 -0700 (PDT)
Received: by mail-io1-xd33.google.com with SMTP id h8so15971027iob.2 for <add@ietf.org>; Mon, 23 Mar 2020 14:19:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=pLcx+wel07UrbLzJjswrfwQVLu8lVblKzD6cBL5BEcw=; b=C8em/fjZKvg335rNNRVGLhtC+cWMTwtWoADKIKyUAwSZrbc/rZhQdKm43A+z+1kNUd j0WrX+wcINlp+QEw3EBFdjZe5KRuU9dxn3FMOungWejwjvEyhRMeaOZfp4BGrL2dbjuz UUrz2vSLn0io9Hyvwq746oylv9N0w2Glk9zrK4bZceAa39m8QzvBGYRjJFcVEohW5n/P Ht2LrsAtVg5/HyMKy2mCEUZWU8ACsVnOoA5HANheBvGDpamriZ7M5WEman7Hh7uO62+g v+F5M9FfIo3hxaAeo3HRWbmEnoZnf/dzGq2DHp8RKecH0EFol/YfAEfy/zQcffJbNRMD n7rw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=pLcx+wel07UrbLzJjswrfwQVLu8lVblKzD6cBL5BEcw=; b=KW7mjRs7WxLo0La0gx2+Vqz/GxL11/GRi3RkyEtBydqj58EmpIZXihvO/Nfm5RzztN EY87biwwng2KbMu6po39SF/erOxBDvEr9XzGwVsQWWqX8+pHr2Ib2IFU8GgiLsk9Fj/+ +EvT5y+KjqNHWEdmsiF8e5WEzJnucnpoYMz+t3wpDNilUlV8EH1jzFhKegKoD45nhiJB 9dXbjpx2TThih7VwcTbgY8S82MbQ3fhDqG2rDhw9DJYsvSJq0RTtzKqTh1A95zbQ5Sv/ Sph9xcaYDF/RGKwbpI0EqxN2GnEpP/J0nuxwCSgGiTy+dfGOU+jEQk+HA6WfOrQpWvg8 HDHg==
X-Gm-Message-State: ANhLgQ1t07uYXX1yvG6SPvaN8Vwz/5xNYLURfcSmMdpzFrNAJ02J5gmH IRIoq6L43mF93NFPwTaGFNDfzjWb/+YvLZRGyUg=
X-Google-Smtp-Source: ADFU+vtpdlkEV9UxDh+azxKWJRUfecmESUslUI2f5EiPZU3gahHIADfrBdqYXjrkgtq9mA3ejgo9GP7yr3GJzJwm4iQ=
X-Received: by 2002:a6b:5406:: with SMTP id i6mr21213487iob.188.1584998391627; Mon, 23 Mar 2020 14:19:51 -0700 (PDT)
MIME-Version: 1.0
References: <CA+9kkMDvX7e0WkRMmJtf33GwMQQ1rAGny87UwneA6znCom_85Q@mail.gmail.com> <CACJ6M17rjhta9rqFHAJ_JaugRiCR7xvAChww0uO912-NayQwEQ@mail.gmail.com> <CAChr6SyQKAd0iGNO6K7O7agFW5=kLi0HHrTjpf7we-FHC82juA@mail.gmail.com> <LO2P265MB0573BD41D2D46F61ABE25675C2F00@LO2P265MB0573.GBRP265.PROD.OUTLOOK.COM>
In-Reply-To: <LO2P265MB0573BD41D2D46F61ABE25675C2F00@LO2P265MB0573.GBRP265.PROD.OUTLOOK.COM>
From: Rob Sayre <sayrer@gmail.com>
Date: Mon, 23 Mar 2020 14:19:40 -0700
Message-ID: <CAChr6SyVLpz86MVAKeFOcSgYaVx5w393C_jYDjpXT5WTEHknYQ@mail.gmail.com>
To: Andrew Campling <andrew.campling@419.consulting>
Cc: "Chris Box (BT)" <chris.box.ietf@gmail.com>, Ted Hardie <ted.ietf@gmail.com>, ADD Mailing list <add@ietf.org>, Jari Arkko <jari.arkko@piuha.net>, Martin Thomson <mt@lowentropy.net>
Content-Type: multipart/alternative; boundary="0000000000001a451605a18c32a1"
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/RoNsH8c6C3PW1DCKewk-ax71ORg>
Subject: Re: [Add] draft-arkko-abcd-distributed-resolver-selection
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Mar 2020 21:20:15 -0000

On Mon, Mar 23, 2020 at 2:09 PM Andrew Campling
<andrew.campling@419.consulting> wrote:

> On Fri, Sun 22, 2020 at 05:12 Rob Sayre <sayrer@gmail.com> wrote:
>
>
>
> > Items 4.1 and 4.2 are pretend security.  Just take a Google Pixel phone
> and turn on the built-in VPN.
>
>
>
> I’m curious why you believe parents and enterprise network managers are
> “pretend security”?  Are you, for example, suggesting that there is
> currently no security on home or enterprise networks, or did you mean
> something else?
>

They aren't, but DNS-based measures (without installed Parental Control
Software or Enterprise Admin access) are. Chris Box wrote:

"the issues are complex enough that they can’t be solved by requiring
administrative control of the client."

But I think that solutions that don't require administrative control are
ineffective. My example was a Google Pixel phone: mine ships with a VPN
on-by-default for open WiFi, and the option to turn it on for all
connections.

thanks,
Rob