Re: [Add] fixing coffee shop brokenness with DoH

Andrew Campling <andrew.campling@419.consulting> Thu, 25 July 2019 15:39 UTC

Return-Path: <andrew.campling@419.consulting>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 85B4A120240 for <add@ietfa.amsl.com>; Thu, 25 Jul 2019 08:39:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=netorgft5189650.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id r53Hpji2ma1s for <add@ietfa.amsl.com>; Thu, 25 Jul 2019 08:39:33 -0700 (PDT)
Received: from GBR01-CWL-obe.outbound.protection.outlook.com (mail-eopbgr110079.outbound.protection.outlook.com [40.107.11.79]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 26906120235 for <add@ietf.org>; Thu, 25 Jul 2019 08:39:33 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=LkesVHOAmawMWWtnS5seD/cbjpxJ2ieGsJoEXhesthPQKPmLt0PVUHBjjcMbPdkX+X2lQ0FBdmKPTJkAft4k/g5Au2xzX51nIETnTpdGuIqo4M4VK/V4PbqVrJvmwGjGtNzTQU9gDbB0b5M9M3s02qauSDKu1YURgs0ztcdrY/UfjxAKu6UpApSt60H9R8KV6pM9KaeBTnWQtkBWaKuHUwT68jdRSNFPx75WKHE/Bx09k9YaBvDbuZGrjsUM0e3hPOzICiJJU1mM295nHd/dabqdoCtQDyJ+hVFhW8bi98H+PDx6sxpFL+t0Luz/dW/uzsAqkvSKDAOeHGqqrnW33Q==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=PUpP0gioJGI6TP5Vj+tYLS424GTcbHmPdO1suPQ64Qs=; b=GMJ76EE/peFUWIWTPbPlLXfzG0SWisivdw0cRRSvNHv1/l1FPgrGMjfc5skz0jZaPDFEsdR5htgiLdHIW3C4a8+NcuhbG0L+qMJ6pK+Zkgvu50gVvJNBGWq57fwsw96Sie0sNwT0UgdMwKNHt5n19dNoMBn0ua4Pswbqg23JWrraE1HbLMZm30X9JuiCjBrEo92Gwvp3aOwGXQed+5RQuJaNO01uxmEq8ZO96VOBBKFGwWMvQaJpcb3xX9548WeUgchX5JztjV1sIfknGkMw0axjmYBfJnp0g95HTCXOZNRHlzU13CRY4IhujncQiPHvxeCoROBgVkC6F5lRvIrL+g==
ARC-Authentication-Results: i=1; mx.microsoft.com 1;spf=pass smtp.mailfrom=419.consulting;dmarc=pass action=none header.from=419.consulting;dkim=pass header.d=419.consulting;arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=NETORGFT5189650.onmicrosoft.com; s=selector1-NETORGFT5189650-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=PUpP0gioJGI6TP5Vj+tYLS424GTcbHmPdO1suPQ64Qs=; b=pyYCBNBS5qyg1RbVQLkOCdbQCwCjB27W9aFjMfftVhgv0mCDqB2HCge3NRNSF78ejfquF2oq1D7FLKCtbCBbnOXylQL65N9ObnLDT/DstTV4eUXIy7VMRpmuNoGPdALazfDp1LKDkpBFf0eG3p4TCTxnSlytYDhXbpwtHKjimwM=
Received: from LO2P265MB1327.GBRP265.PROD.OUTLOOK.COM (20.176.138.146) by LO2P265MB1133.GBRP265.PROD.OUTLOOK.COM (20.176.141.139) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2115.10; Thu, 25 Jul 2019 15:39:30 +0000
Received: from LO2P265MB1327.GBRP265.PROD.OUTLOOK.COM ([fe80::387c:9c12:531b:b7bd]) by LO2P265MB1327.GBRP265.PROD.OUTLOOK.COM ([fe80::387c:9c12:531b:b7bd%3]) with mapi id 15.20.2094.013; Thu, 25 Jul 2019 15:39:30 +0000
From: Andrew Campling <andrew.campling@419.consulting>
To: Eric Rescorla <ekr@rtfm.com>
CC: "add@ietf.org" <add@ietf.org>
Thread-Topic: [Add] fixing coffee shop brokenness with DoH
Thread-Index: AQHVQv2xaDaTq1BGZ0eqO2wXmgt3vqbbdjTQ
Date: Thu, 25 Jul 2019 15:39:30 +0000
Message-ID: <LO2P265MB1327A47EE98888D755633C66C2C10@LO2P265MB1327.GBRP265.PROD.OUTLOOK.COM>
References: <CAChr6Sx9TEt6CMzRRrdb-HwT_k987oW=4yF1FCbDF17zkaE2Vg@mail.gmail.com> <2D09D61DDFA73D4C884805CC7865E6114E23910C@GAALPA1MSGUSRBF.ITServices.sbc.com> <14DF8769-A817-4C06-9140-80198518244F@akamai.com> <CAChr6SzH1EycAr5n+dK5BQcG=0Zsw66qE=8Rptvq7SEoEvQQ=Q@mail.gmail.com> <E5A0DAE2-A718-41EA-B490-58ABD0F31CF2@rfc1035.com> <CABcZeBMqvZivS_Hk_2mSOAOnM+mHy1mtcwnHVFc14v_jdkgU=Q@mail.gmail.com> <1EFB37A3-23C6-44FF-B001-8F04B381EC04@rfc1035.com> <CABcZeBPB2Bb8RCigDt+tJ5Lz3KQQnPAVVkrF+fDUiTFJcw=eVw@mail.gmail.com> <D3359CC8-80B4-4443-B3B1-F2AD80C94DA6@rfc1035.com> <CABcZeBOZiu_=VfWJDY_9V86TiGpsuZRKMCiersopxD+kTBBUtA@mail.gmail.com> <20190725142135.0FFA715BD17B@fafnir.remote.dragon.net> <CABcZeBPO-hi=z-fB1toOCBRTUF+krndCZqPHS=Jrev1tTtY6XQ@mail.gmail.com> <CAH1iCir9L+U7cUWJgOLdP-G1MtxWvPo5sUn4z9GRvym12buH2A@mail.gmail.com> <CABcZeBN1SrXFopZ4XVZjONQ=heqr7XE_s9XQWUv3ctYny3Xu1g@mail.gmail.com>
In-Reply-To: <CABcZeBN1SrXFopZ4XVZjONQ=heqr7XE_s9XQWUv3ctYny3Xu1g@mail.gmail.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=andrew.campling@419.consulting;
x-originating-ip: [2a00:23c4:a499:2e00:4c4d:3a84:6d17:cecf]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 3ee10cca-c9dc-450c-080b-08d711164904
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(7021145)(8989299)(5600148)(711020)(4605104)(1401327)(4534185)(7022145)(4603075)(4627221)(201702281549075)(8990200)(7048125)(7024125)(7027125)(7023125)(2017052603328)(7193020); SRVR:LO2P265MB1133;
x-ms-traffictypediagnostic: LO2P265MB1133:
x-microsoft-antispam-prvs: <LO2P265MB1133AB3370AF12F694C29BF8C2C10@LO2P265MB1133.GBRP265.PROD.OUTLOOK.COM>
x-ms-oob-tlc-oobclassifiers: OLM:8273;
x-forefront-prvs: 0109D382B0
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(34096005)(346002)(376002)(366004)(39830400003)(136003)(396003)(199004)(189003)(6116002)(316002)(99286004)(446003)(4744005)(186003)(33656002)(76176011)(7696005)(14444005)(256004)(71190400001)(44832011)(46003)(74316002)(790700001)(476003)(8936002)(81166006)(6916009)(81156014)(68736007)(486006)(8676002)(7736002)(6436002)(53546011)(102836004)(25786009)(6506007)(54896002)(86362001)(11346002)(236005)(508600001)(52536014)(53936002)(76116006)(66946007)(66476007)(66556008)(229853002)(9686003)(5660300002)(64756008)(66446008)(6246003)(14454004)(6306002)(4326008)(55016002)(2906002)(71200400001)(46492003); DIR:OUT; SFP:1101; SCL:1; SRVR:LO2P265MB1133; H:LO2P265MB1327.GBRP265.PROD.OUTLOOK.COM; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: 419.consulting does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam-message-info: BVllMPjD+6KHdUUVbpVv+QoDnRcqyr+GZtOzqzX3KdKVESGp75lU/XrFesgVICjtWICP1ZCXfbbLoF8FkR4F1nXSJeRiSLrpU/dGHogA61XxTgkAG1TloipHsiHrJtRoEVjBU6cEuZvjfmznKDK65cUD34IRCVjI1TZMG2XJFf6ITqqXaihEQB4tLaGrdvCDsrIQaIqDPgBKz2ZMcz5iAh/oaN0g3NwTIFs2/G43l/2s48ubhVMACxHSpDfQ1gsyMDABg9Rbznr/0r8jS1UxVIrU4mVGnmOi3dmlp1eWlqY3jIAP3u2h0LmsZcsgRPPWSfF2EyFY4mSNNzKXB1JHSrI5p2cIBPUUnIwyj3/RhImxN3/awKV0PXtkAQun9QXs9SpBDtSPJfsTC4eYoMKULXTM9eom0c6jTpz/L4GvAlU=
Content-Type: multipart/alternative; boundary="_000_LO2P265MB1327A47EE98888D755633C66C2C10LO2P265MB1327GBRP_"
MIME-Version: 1.0
X-OriginatorOrg: 419.consulting
X-MS-Exchange-CrossTenant-Network-Message-Id: 3ee10cca-c9dc-450c-080b-08d711164904
X-MS-Exchange-CrossTenant-originalarrivaltime: 25 Jul 2019 15:39:30.6988 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 9c2ced3e-7522-4755-87dc-f983abc66ec3
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: andrew.campling@419.consulting
X-MS-Exchange-Transport-CrossTenantHeadersStamped: LO2P265MB1133
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/h0DRmCjLb6lf0WRfe3vooFNs-WY>
Subject: Re: [Add] fixing coffee shop brokenness with DoH
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 Jul 2019 15:39:36 -0000

On Thu, Jul 25, 2019 at 4:21 PM Eric Rescorla <ekr@rtfm..com<mailto:ekr@rtfm.com>> wrote:

> This thread has gotten quite long and hard to track. I was talking about the case where DoH was not present, and my point was that DNSSEC is not a replacement for DoH in the settings I am concerned with.

> I agree that DoH potentially makes end-user software DNSSEC validation viable, and that's something that at some point we might look at.


Presumably this applies do both DoT and DoH Eric?

As someone said during the DoH discussion at the ICANN conference in Marrakesh last month, “DoT and DoH give you a hardened pipe, don’t stop you drawing poisoned water from the lake; DNSSEC reassures you that the water is safe” (or something very close to that).  I thought that was a useful analogy to highlight why the combination of DoT/H and DNSSEC was beneficial.


Andrew