Re: [Add] Participation

Brian Dickson <brian.peter.dickson@gmail.com> Sat, 17 August 2019 22:50 UTC

Return-Path: <brian.peter.dickson@gmail.com>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C1B65120147 for <add@ietfa.amsl.com>; Sat, 17 Aug 2019 15:50:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level:
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cns5BQdVXSXP for <add@ietfa.amsl.com>; Sat, 17 Aug 2019 15:50:56 -0700 (PDT)
Received: from mail-vs1-xe29.google.com (mail-vs1-xe29.google.com [IPv6:2607:f8b0:4864:20::e29]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 852AA1200E5 for <add@ietf.org>; Sat, 17 Aug 2019 15:50:56 -0700 (PDT)
Received: by mail-vs1-xe29.google.com with SMTP id b187so786769vsc.9 for <add@ietf.org>; Sat, 17 Aug 2019 15:50:56 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=vvSKT2CYYSl2ZqqdvP4EBQ49Rc18eAeEYWzGdV0E9vI=; b=fSWh41bv+cu0bpg6S2RYwAwsMLW0SJKbOmRCB5mmnLr0s9WHcEr5yKfO0JJgrSlZKc P22SxKTrLEraTmgwlbgOFGX/h1VttJwHCZVi1vss23Qp5uQgRDm25EaFGIhG+kyMAu5s zXlKdh8XegonCxJkBICZ7LdbfvlCZA4nFBsfcDzD8dGP9jh7OsQCVJruVoX2XjifJTQM P6eV1ylArUCxjrSVYzogQ+rR4yNJra59T4/d6w2slndPyzHw8ht6HMMRoL7jhQqkhH03 hu7kSxTmAVfmUQqnkdAkSp46dCq0TxVB0S3ZyCt+xsXNfvut86HbqZPhZI+gFBP9EorI S5zA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=vvSKT2CYYSl2ZqqdvP4EBQ49Rc18eAeEYWzGdV0E9vI=; b=HUVhtnH0OGMKyWtdPi/f/0DAu42+S1LxE/1Yticbcutp+1kF6ySy5D+s3btwsblhBE JkJGh5DSHmg2m7XZgpV2iqSnDL1Z7MG3a91v3ddEXfsiYvnyUhxqwIsn3ktcA+wPSeZV VhqPPVfQkwN+CyOjO6vBL0cKgOZpn7fL2sFByQ0aJjD9q/0gRr6fQydQbp6dpnfsaMt/ wAl+OGteWzAP2FAVFxqN3QeJ/XjN2VsADw5xtGAsQxmOa5eSwTebbjhY1Ve++NxCzV4g 5H7IfCSzvJ2V791ER8ia+6xRitztQa+/I8vT39R8lw9g1xzoF0bm3DayaGtG/KsftjGg uLXw==
X-Gm-Message-State: APjAAAWiOjnyfCLaAuWQjRTLn7YpdEBTdaXUhsKhW92DXsLb3oCCo+/W HEWsOhanaLQDj5VJGWzQDsolQvWTudtob6ohK7s=
X-Google-Smtp-Source: APXvYqzsQ1sbYqcEXOGyeB+S+KXlzygXxo3uGFnXwKp3JcUJxUfpBmsvWHWANzFwW+AXb7baVFkwM8FnkESfwvopRWg=
X-Received: by 2002:a67:d812:: with SMTP id e18mr10723735vsj.199.1566082255710; Sat, 17 Aug 2019 15:50:55 -0700 (PDT)
MIME-Version: 1.0
References: <LO2P265MB1327CC055667B8F972AEDC04C2AC0@LO2P265MB1327.GBRP265.PROD.OUTLOOK.COM> <CAH1iCiqt0YODvxuQf-_Wm3zdC0HAcyRTJ-jMYLe-kMKeLEy9zQ@mail.gmail.com> <09178E42-08B2-4958-A1C8-AF507AEE8834@fugue.com> <LO2P265MB13270AAEC9901FB41632D2F0C2AF0@LO2P265MB1327.GBRP265.PROD.OUTLOOK.COM> <0BDD4F7F-7301-476A-80DA-0CC84EE4557D@fugue.com> <B0B173E7-DA2F-40B9-9DE5-412D4808E9A2@gmail.com> <6698db4f-89ff-e5be-09a5-eb544f76ebc9@nostrum.com> <CAChr6SzBsF8W4-CKqX=m07oZ6hSrkDz0jJxsvT2C1RXh2Vb+bA@mail.gmail.com> <c7696b3e-6f3e-e9b8-94fd-8c36b676a6e4@nomountain.net> <CAChr6SxHWxu=ESVq29dmKTkikGXS=sM_NM5ZTPh15XQNqpBQmQ@mail.gmail.com> <20190817170031.6F71C1691138@fafnir.remote.dragon.net> <CAChr6SxOMcsKQxrEkMOXFsNnYJG33X-JOM+tawKhYtF28JfL5g@mail.gmail.com> <CAJhMdTO6VFzTa_AMRQowrkr9hwgO7hAmHCLekeCXvWdgmmFqjg@mail.gmail.com> <CAChr6Sz4RyKhpKGzUAtUA9dxRNbXpCQ9Xccm8qEAW4aQBJ=FtQ@mail.gmail.com> <CDB00A70-094E-47DC-A440-E06253B56E7C@hopcount.ca> <CAChr6SwjA9EpTpWNNEVQdxGpeTbY61pCQd1eJUx26AvS7aYr7Q@mail.gmail.com> <20190817205517.1128E16936B5@fafnir.remote.dragon.net> <CAChr6SyfFxnfXQgP+jGV9EOWxbfvNR9hZSgQwM4h8cyTKj1ygg@mail.gmail.com> <9FB124AF-79CB-48B9-87BB-DC6F2D532F10@fl1ger.de> <CAChr6Sx=02orod1+8sAH=c8bXP4wT7GwDterqYuRjkLfNt5_JQ@mail.gmail.com>
In-Reply-To: <CAChr6Sx=02orod1+8sAH=c8bXP4wT7GwDterqYuRjkLfNt5_JQ@mail.gmail.com>
From: Brian Dickson <brian.peter.dickson@gmail.com>
Date: Sat, 17 Aug 2019 18:50:32 -0400
Message-ID: <CAH1iCipmha5fxBEMysyg_dbgGS=D72OUXS0-ssEV1GL+O-TQ3g@mail.gmail.com>
To: Rob Sayre <sayrer@gmail.com>
Cc: Ralf Weber <dns@fl1ger.de>, Melinda Shore <melinda.shore@nomountain.net>, Paul Ebersman <list-add@dragon.net>, ADD Mailing list <add@ietf.org>, Joe Abley <jabley@hopcount.ca>
Content-Type: multipart/alternative; boundary="0000000000008a6dc2059057f074"
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/_heywWikg0Z190SSzeseI8PQKJc>
Subject: Re: [Add] Participation
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 17 Aug 2019 22:50:59 -0000

On Sat, Aug 17, 2019 at 5:39 PM Rob Sayre <sayrer@gmail.com> wrote:

> On Sat, Aug 17, 2019 at 2:33 PM Ralf Weber <dns@fl1ger.de> wrote:
>
>> As said before DNSSEC and DoH/DoT are complementary and solve different
>> problems.
>>
> [...]

>
>
But I think people are looking for a way to break DoH/DoT, in a
> well-meaning way.
>

I'm not sure if you are counting me in the population of "people", but if
so, you are WAY wrong, or at least mistaken on intent.

I'm looking for ways of breaking involuntary change of DNS resolver choice.
This applies to both managed and unmanaged devices, hosts, virtual hosts,
infrastructure, and those of any partner companies, sister companies,
subsidiaries, outsource companies, or customers.

That the target (ie new choice of) DNS resolver might happen to be doing
DoH is completely irrelevant. What matters is that the resolver is changed,
not the protocol being used.

Incidentally, I am strongly in favor of upgrading all DNS client
connections-to-resolvers in our larger ecosystem, to be DoT.

If it is not possible to convince browsers to do DoT, the alternative may
be in-host proxy services that do DoH to DoT conversion. Those are nearly
trivial to implement.

Mostly choosing DoT over DoH is about not adding any HTTP junk to DNS
resolution on the server side. Our DNS servers do not do HTTP anything. We
want the greatest amount of flexibility in choice of servers, and the
smallest available attack surface.

Adding TLS to a regular DNS server (which is what DoT amounts to) is the
simplest option.

This is the exact opposite of wanting to break DoH/DoT.

Wanting to continue to operate infrastructure for DNS resolution, and
maintain (or add) existing DNS-based toolsets, is a significant driver in
this philosophy.

When you operate DNS infrastructure at scale, and offer DNS services at
scale as well, any attempt by any software vendor to interfere with that,
regardless of motivation or intention, is going to provoke a strong
negative response, and justifiably so.

So, in short, please stop what folks like I am doing, as being
anti-encryption or anti-DoH/DoT, because it isn't.

Brian