Re: [Add] What to do in this potential working group

Rob Sayre <sayrer@gmail.com> Thu, 22 August 2019 06:01 UTC

Return-Path: <sayrer@gmail.com>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 493AA12011A for <add@ietfa.amsl.com>; Wed, 21 Aug 2019 23:01:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.997
X-Spam-Level:
X-Spam-Status: No, score=-1.997 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HAF08ihgrEeh for <add@ietfa.amsl.com>; Wed, 21 Aug 2019 23:01:56 -0700 (PDT)
Received: from mail-io1-xd2b.google.com (mail-io1-xd2b.google.com [IPv6:2607:f8b0:4864:20::d2b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 88C5412006F for <add@ietf.org>; Wed, 21 Aug 2019 23:01:56 -0700 (PDT)
Received: by mail-io1-xd2b.google.com with SMTP id j5so9513050ioj.8 for <add@ietf.org>; Wed, 21 Aug 2019 23:01:56 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=afrPpsKthqQq9aHWZteNetEFw8UuGwnLlgMywLkJC3k=; b=VuOllUIdVtVn4eWLkxoN2HnEGTOiNwSD28W3mWM5cA2dzKPi+cEhLrkbNFsat346uJ 20OnMsoSO6iogkhaoZdfQcOLOwvqDaX7ERVcyYFCa6FT5s5b58CCuA+AqNSpMwiqGxmq zYw+VU22ieeOryI+BF4F8Nr7g8hApbq4guGKwHJtK4ZvSRUi+xAx2W+hV2VUE23saqaQ dFMQN3mIg5ljDvFC/T48LrcgjQO2jRS4orLhnDgt3LdGcPS4elGSSLtphvDQjiHwyxhG 7mhYanKzUn21W51tLryRJtNyo3uVk13OA7oYGjkVSZDOxYRE1jQmYeaWdVl7q+eZr1+K M2Qw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=afrPpsKthqQq9aHWZteNetEFw8UuGwnLlgMywLkJC3k=; b=OKWqX46M3r+KVqN7Wxy2QdmSUdk+wBo4j/SNE24BKTWJiD8+H4runZtpaJ+8i3bDt9 7uGSlqy3hzwg7c21EUci73QiNwuQOCufvaON/ZFunan2bYeLdmULleiBf/6o0L9whLEM G9sTX+d8JmuW1gbjR4BNsG7X7wSLdBqeO8i6sp6FXSWBc4n3PGZh6UFwQMquWBldd4Pl BqXiTqCt6Wv8X1464lQPhb2e+gwaDr5CIhPOJ3UQnKYZOJgZFSO4uDL/FAUsYbm6uZnM 0c/9bLocdo7I55TZexngr3ptwSqxRgmLLOBsZgQeI2a46Ewj9aMffPTO+gRkoy2z9Dao DPMg==
X-Gm-Message-State: APjAAAUXG41NFtHYsm031n6bG4mygc1tcFyz0lH1bH8ip7GeNQx05x8u tCfEQLHeJNtOwFpp6vg4gKrCK+6+nMqs74Wz34k=
X-Google-Smtp-Source: APXvYqz9v1uvBPc7ALkGurIwof9r4eA/pmjKuw5BvvhIPf09YyqZ9f7XdSxzSMob8DurbV6dnZsolSLDdqdijfAqWdI=
X-Received: by 2002:a5e:9515:: with SMTP id r21mr18085303ioj.257.1566453715644; Wed, 21 Aug 2019 23:01:55 -0700 (PDT)
MIME-Version: 1.0
References: <A1128702-1E19-4657-9740-E84AE09992F2@piuha.net> <CABcZeBMfOTjq-8hDDoKMtJvfHUA5nC8o60zuk-2Xe-ZhfwriJQ@mail.gmail.com> <766112E1-F532-4C6B-8CA8-A096671E02EE@piuha.net> <CA+9kkMAfuOwJu8_qJTuhAY4mUwR+tVUxr+k3QFHBk3byV672Ow@mail.gmail.com> <A7EA862E-8E80-40E3-834D-E628988C0A24@virtualized.org> <CAFWeb9KT=2JL0oHUgJ2WMcduR3na+hP2QncvRR4YurmqsAWxTA@mail.gmail.com> <B7B73927-662B-49DF-B176-81E0C985AC5D@frobbit.se>
In-Reply-To: <B7B73927-662B-49DF-B176-81E0C985AC5D@frobbit.se>
From: Rob Sayre <sayrer@gmail.com>
Date: Wed, 21 Aug 2019 23:01:40 -0700
Message-ID: <CAChr6SydOamN9wPooV2H0-vNt0KA+4paUk5VOYY9frF6vk11Pw@mail.gmail.com>
To: Patrik Fältström <paf=40frobbit.se@dmarc.ietf.org>
Cc: Alec Muffett <alec.muffett@gmail.com>, Ted Hardie <ted.ietf@gmail.com>, ADD Mailing list <add@ietf.org>, David Conrad <drc@virtualized.org>
Content-Type: multipart/alternative; boundary="0000000000004739960590ae6dc2"
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/ZQPWhm-pRepDZNBvHbXA2_BqtBQ>
Subject: Re: [Add] What to do in this potential working group
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 22 Aug 2019 06:01:58 -0000

On Wed, Aug 21, 2019 at 10:55 PM Patrik Fältström <paf=
40frobbit.se@dmarc.ietf.org> wrote:

> On 21 Aug 2019, at 20:06, Alec Muffett wrote:
>
> > Fortunately we do not have to wait for DNSSEC in order to get answers
> from the people from whom we wish them supplied, privately and
> untampered-with, which is the whole point of DNS over HTTPS.
>
> Only if you do DNS over HTTPS directly to an authoritative DNS server.
>

Won't the client use the DNS information to make a request over TLS?

If you doubt the security of that, you are questioning the entire global
PKI. I happen to think that infrastructure is a joke, but I do agree that
it foils common criminals and overzealous local administrators.

thanks,
Rob