Re: [Add] [EXTERNAL] Re: WG Adoption Call draft-schwartz-add-ddr-forwarders

Paul Wouters <paul@nohats.ca> Wed, 20 April 2022 14:45 UTC

Return-Path: <paul@nohats.ca>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8B3603A17AC for <add@ietfa.amsl.com>; Wed, 20 Apr 2022 07:45:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.103
X-Spam-Level:
X-Spam-Status: No, score=-2.103 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nohats.ca
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QSbF9joP2Bny for <add@ietfa.amsl.com>; Wed, 20 Apr 2022 07:45:55 -0700 (PDT)
Received: from mx.nohats.ca (mx.nohats.ca [IPv6:2a03:6000:1004:1::85]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 00B193A1798 for <add@ietf.org>; Wed, 20 Apr 2022 07:45:54 -0700 (PDT)
Received: from localhost (localhost [IPv6:::1]) by mx.nohats.ca (Postfix) with ESMTP id 4Kk3Pq3czlzF3k; Wed, 20 Apr 2022 16:45:51 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nohats.ca; s=default; t=1650465951; bh=jSPY5WOxooj2i9cwsWYudVTljC9SHwBIokFjTanYG4s=; h=Date:From:To:cc:Subject:In-Reply-To:References; b=EPZDK89WnY4gS9Ae1mi3svFYCvqr3XapRt2xo+nyYf9BAK2kQeOsdk+Mrc+q6/Pji +wMdecPAzMmfq2g8XSCjawShJl0ithk0dimjfweIEL2u1sMmLo5JENGH5xRULfXfFz ucudmepL0Z0c7vUT7ehLKX7wx1AnSSDg/zKRB4r4=
X-Virus-Scanned: amavisd-new at mx.nohats.ca
Received: from mx.nohats.ca ([IPv6:::1]) by localhost (mx.nohats.ca [IPv6:::1]) (amavisd-new, port 10024) with ESMTP id W3lQJkncg6pG; Wed, 20 Apr 2022 16:45:50 +0200 (CEST)
Received: from bofh.nohats.ca (bofh.nohats.ca [193.110.157.194]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx.nohats.ca (Postfix) with ESMTPS; Wed, 20 Apr 2022 16:45:50 +0200 (CEST)
Received: by bofh.nohats.ca (Postfix, from userid 1000) id 804F73296C8; Wed, 20 Apr 2022 10:45:49 -0400 (EDT)
Received: from localhost (localhost [127.0.0.1]) by bofh.nohats.ca (Postfix) with ESMTP id 7CF4E3296C7; Wed, 20 Apr 2022 10:45:49 -0400 (EDT)
Date: Wed, 20 Apr 2022 10:45:49 -0400
From: Paul Wouters <paul@nohats.ca>
To: Vittorio Bertola <vittorio.bertola=40open-xchange.com@dmarc.ietf.org>
cc: Tommy Jensen <Jensen.Thomas=40microsoft.com@dmarc.ietf.org>, Tommy Pauly <tpauly=40apple.com@dmarc.ietf.org>, "add@ietf.org" <add@ietf.org>, "Deen, Glenn" <Glenn_Deen=40comcast.com@dmarc.ietf.org>
In-Reply-To: <273738230.10947.1650445534230@appsuite-gw1.open-xchange.com>
Message-ID: <803648be-a12d-5ad0-25bc-19f75913b33@nohats.ca>
References: <9BE5F92B-4F58-46F7-9A55-A740E58DA2F8@comcast.com> <ABAB733A-743E-4E5C-9E71-104D9DF5E24F@apple.com> <SA1PR00MB13129F9723867B537828E79FFAEE9@SA1PR00MB1312.namprd00.prod.outlook.com> <273738230.10947.1650445534230@appsuite-gw1.open-xchange.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="US-ASCII"; format="flowed"
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/ZLHIm6S5RrTdryreQSHFRaTvDWM>
Subject: Re: [Add] [EXTERNAL] Re: WG Adoption Call draft-schwartz-add-ddr-forwarders
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Apr 2022 14:46:00 -0000

On Wed, 20 Apr 2022, Vittorio Bertola wrote:

> In other words, a commitment by browsers that they will still make use of unencrypted DNS in the long term in the "forwarding CPE with private IP" case,
> and that they will not try to push users to move to encrypted DNS servers run by other parties, could perhaps make the above draft redundant.

This does not seem in the interest of the enduser. Why would browser
vendors commit to this?

If a customer wants their ISP to intercept their DNS to protect them,
they can "subscribe" to such a feature using a TRR with DoH run by
the ISP.

Any kind of "prefer unencrypted DNS because" is going to be a very
weak proposal to customers and seem to mostly make life easier on
ISPs and their LI responsibilities.

Paul