Re: [Add] fixing coffee shop brokenness with DoH

<chris.box@bt.com> Wed, 24 July 2019 11:53 UTC

Return-Path: <chris.box@bt.com>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0DA7B12002E for <add@ietfa.amsl.com>; Wed, 24 Jul 2019 04:53:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.699
X-Spam-Level:
X-Spam-Status: No, score=-2.699 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=bt.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DZDSd1Lrl2TS for <add@ietfa.amsl.com>; Wed, 24 Jul 2019 04:53:02 -0700 (PDT)
Received: from smtpe1.intersmtp.com (smtpe1.intersmtp.com [62.239.224.234]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 40E661200A4 for <add@ietf.org>; Wed, 24 Jul 2019 04:53:02 -0700 (PDT)
Received: from tpw09926dag17h.domain1.systemhost.net (10.9.212.41) by RDW083A012ED68.bt.com (10.187.98.38) with Microsoft SMTP Server (TLS) id 14.3.439.0; Wed, 24 Jul 2019 12:52:19 +0100
Received: from tpw09926dag12f.domain1.systemhost.net (10.9.212.20) by tpw09926dag17h.domain1.systemhost.net (10.9.212.41) with Microsoft SMTP Server (TLS) id 15.0.1395.4; Wed, 24 Jul 2019 12:52:58 +0100
Received: from bwp09926077.bt.com (10.36.82.108) by tpw09926dag12f.domain1.systemhost.net (10.9.212.20) with Microsoft SMTP Server (TLS) id 15.0.1395.4 via Frontend Transport; Wed, 24 Jul 2019 12:52:58 +0100
Received: from GBR01-LO2-obe.outbound.protection.outlook.com (104.47.21.58) by smtpe1.intersmtp.com (10.36.82.108) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.1.1713.5; Wed, 24 Jul 2019 12:52:51 +0100
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=i89mD2t9NWzUGGg5gG32kb6XYI/hzJEGB1DYNL/S6RSLUHU6GqqKqBbNBKpiOmKNbAJyZX/L/uYRfBbCjdQECv7svCd/sqWYD21kpCM1ngJXjUZW2DOD8dAgyJ67D6+QdlcyrJp0OYZWufhMtwV7r+5bpgE9wDkDmE/NASmjDUdbBHlFPS85vIkRfKH1q3lYWc18/uLLa1q3PxzaFSo0hSuVrAoOyUNBCg6/BKnlclBCZ/uxCPbStwBcXz2P88CSet86RF4Vus0utP1yEI2sLY2Tuowa9Twx8a4KgqNqoudAWJPiqIMkuKaxxzf4YHqPpzNJKI+JoZlY7oYVtWSXPw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=u3DKMlH8jtpLQSQ4M/wSrA2I9QZpkYD/q1MzmaEEfJg=; b=Hi+L2YBfSEl7LvjcWB0VRE/p4fnaLNBNjtDPKVoMLdNCR9yYjrbKFVmSmfvyJW9dveDpwHAvfwDLd8DOBlI1VDH8QQ/qSJRVKCtrTp2PFHQU+kd3CSu4mzsZ4M1mFE7LT6eDi43wFU8M/GCZx7ssXqRIUZk+842vwQ2prg/XdyoDAs4QoC+ipkx0MBWZwwd3F/jh29jzOKFd3Z/Ae+Z0WXLUiXXDP6c1HQSBKai6lAf9LVNI2fRi4afQmzehDEzhVMSjuIz/jj5e+N+EDNLQgHgbhRSHnvovtcwJNRzA0KlaV2KpqFujExT+kyD3Gk+Gl0f17BboDJzVPlDVFL/d2A==
ARC-Authentication-Results: i=1; mx.microsoft.com 1;spf=pass smtp.mailfrom=bt.com;dmarc=pass action=none header.from=bt.com;dkim=pass header.d=bt.com;arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bt.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=u3DKMlH8jtpLQSQ4M/wSrA2I9QZpkYD/q1MzmaEEfJg=; b=f/ZHPenXmzIUgF8Y6EL5+aGY64zrDWgzs0x67fKgBEioXGBP997UjeNMACPJXADOzopw4nmDvdPJhSvew14KMQ6EnXeufJZqf5335Z4S7CIxxxbiJkrYakilfo/zXzfs3mbb16lxVg8Ok3aUeL8v7cMJz+TJkFneYJqcXMsEnic=
Received: from LO2P123MB2256.GBRP123.PROD.OUTLOOK.COM (20.176.158.15) by LO2P123MB2144.GBRP123.PROD.OUTLOOK.COM (20.176.157.80) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2115.10; Wed, 24 Jul 2019 11:52:57 +0000
Received: from LO2P123MB2256.GBRP123.PROD.OUTLOOK.COM ([fe80::4061:47b7:52f1:6836]) by LO2P123MB2256.GBRP123.PROD.OUTLOOK.COM ([fe80::4061:47b7:52f1:6836%3]) with mapi id 15.20.2094.013; Wed, 24 Jul 2019 11:52:57 +0000
From: chris.box@bt.com
To: add@ietf.org
Thread-Topic: [Add] fixing coffee shop brokenness with DoH
Thread-Index: AQHVQcJI+jqXeCJLjU2M+OG81Si+56bZBa+AgAACZgCAAADiAIAAAcuAgACEL4CAABWygA==
Date: Wed, 24 Jul 2019 11:52:57 +0000
Message-ID: <LO2P123MB22569D3F3476B913EDC8F8D69BC60@LO2P123MB2256.GBRP123.PROD.OUTLOOK.COM>
References: <CAChr6Sx9TEt6CMzRRrdb-HwT_k987oW=4yF1FCbDF17zkaE2Vg@mail.gmail.com> <2D09D61DDFA73D4C884805CC7865E6114E23910C@GAALPA1MSGUSRBF.ITServices.sbc.com> <14DF8769-A817-4C06-9140-80198518244F@akamai.com> <CAChr6SzH1EycAr5n+dK5BQcG=0Zsw66qE=8Rptvq7SEoEvQQ=Q@mail.gmail.com> <E5A0DAE2-A718-41EA-B490-58ABD0F31CF2@rfc1035.com> <CAChr6SzvUZS4Ru_SttiZgWtjwBuLrzc_fdewq9w-Ts+Rq_oNHw@mail.gmail.com> <9E8BD2C4-D750-4B8C-BA34-AC4425F2951D@gmail.com> <CAChr6Szo+1x6BnU2XH2A0o7CTQrQhFVPYezR7KQVLw-nWToULg@mail.gmail.com> <MN2PR21MB12134C6B57220E1B8BF5C811FAC60@MN2PR21MB1213.namprd21.prod.outlook.com> <CABtrr-Ue6rAom3ubJc_tPbn37T8HPGPabzX=CxT9UmiicbUtXQ@mail.gmail.com>
In-Reply-To: <CABtrr-Ue6rAom3ubJc_tPbn37T8HPGPabzX=CxT9UmiicbUtXQ@mail.gmail.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=chris.box@bt.com;
x-originating-ip: [2001:67c:1232:144:98f1:6764:e181:fb3a]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: ee307c8a-78b4-4179-4b2c-08d7102d785c
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(8989299)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(5600148)(711020)(4605104)(1401327)(2017052603328)(7193020); SRVR:LO2P123MB2144;
x-ms-traffictypediagnostic: LO2P123MB2144:
x-ms-exchange-purlcount: 2
x-microsoft-antispam-prvs: <LO2P123MB214409233CD087EE92F1B2929BC60@LO2P123MB2144.GBRP123.PROD.OUTLOOK.COM>
x-antispam-2: 1
x-ms-oob-tlc-oobclassifiers: OLM:6108;
x-forefront-prvs: 0108A997B2
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(4636009)(376002)(366004)(136003)(346002)(396003)(39860400002)(189003)(199004)(1730700003)(2906002)(2351001)(71200400001)(71190400001)(8676002)(6116002)(790700001)(2501003)(64756008)(256004)(76176011)(14444005)(52536014)(14454004)(966005)(6916009)(478600001)(5660300002)(229853002)(6436002)(86362001)(7736002)(99286004)(74316002)(316002)(7696005)(25786009)(11346002)(102836004)(53936002)(186003)(53546011)(6506007)(476003)(76116006)(486006)(5640700003)(33656002)(81156014)(66446008)(66556008)(66476007)(81166006)(8936002)(55016002)(46003)(9686003)(54896002)(6306002)(6246003)(68736007)(606006)(66946007)(446003)(236005); DIR:OUT; SFP:1101; SCL:1; SRVR:LO2P123MB2144; H:LO2P123MB2256.GBRP123.PROD.OUTLOOK.COM; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
received-spf: None (protection.outlook.com: bt.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam-message-info: yvTSRIVswo8u3HJrxDvbm8JmDv5q1YCxze2dLf6FHtN6X6fBNLVm9SQueE+EdaJlRmJLxvgqU9pwQGslHEJn9S3JWw6xqxhRZa79z5r9LtfT3TSbji3Xqh/TBTqidWesiQ5fJQhNkGjRFn7BDiVXK25gufaK1XW594//YT/dUFKe8H9ZrfHAmeHQLqGV9h3nvfMWymKxpJXD2kG1ncFYxz7WCBx32IquupBzwy1Xog0XtnsfdsMQdHeXEM37WqDnNb+iiRxY9lzIfRVZeMhixQo42wkWMZjc6vpwl4X7KI4w8/LpG7OIBRL4QFdA2F0tOtRq52zUbzJGISRd6jKYJ+n5Zu8z34P9wlVuwXLB8/5fgZiTb5IDv+b87JDbZAMK7HLVSlH5Q6k+l8ktr1jie4TUPHQJxmO0xHC0ydSjWjs=
Content-Type: multipart/alternative; boundary="_000_LO2P123MB22569D3F3476B913EDC8F8D69BC60LO2P123MB2256GBRP_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: ee307c8a-78b4-4179-4b2c-08d7102d785c
X-MS-Exchange-CrossTenant-originalarrivaltime: 24 Jul 2019 11:52:57.3352 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: a7f35688-9c00-4d5e-ba41-29f146377ab0
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: chris.box@bt.com
X-MS-Exchange-Transport-CrossTenantHeadersStamped: LO2P123MB2144
X-NAI-Spam-Flag: NO
X-NAI-Spam-Level:
X-NAI-Spam-Threshold: 5
X-NAI-Spam-Score: 0.6
X-NAI-Spam-Report: 4 Rules triggered * 0.6 -- TS_MSG_REP_20 * 0 -- EDT_SDHA_ADR_FRG * 0 -- EDT_SDHA_DMN_FRG * 0 -- RV6597
X-NAI-Spam-Version: 2.2.0.9309 : core <6597> : inlines <7125> : streams <1828280> : uri <2871837>
X-OriginatorOrg: bt.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/bCZi1cTCcYkts2mc8HM2VYzN_d4>
Subject: Re: [Add] fixing coffee shop brokenness with DoH
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Jul 2019 11:53:05 -0000

This is a good point; there are valid reasons why 1.1.1.1 can be the right provider for some users. Please allow me to clarify some possible misunderstandings.

I’m not against DoH.
I’m not against privacy and security.
I’m not against user choice.

These are all valuable things we should strive for. Let’s do it in a way that works for everyone, by identifying and documenting best practice.

Chris

From: Add <add-bounces@ietf.org> On Behalf Of Joseph Lorenzo Hall
Sent: 24 July 2019 06:19
To: Tommy Jensen <Jensen.Thomas=40microsoft.com@dmarc.ietf.org>
Cc: Jim Reid <jim@rfc1035.com>; add@ietf.org; Bret Jordan <jordan.ietf@gmail.com>; Rob Sayre <sayrer@gmail.com>
Subject: Re: [Add] fixing coffee shop brokenness with DoH

[snip]

Tone aside, to some users, centralization is a benefit in that they don't have a bunch of unknown privacy policies applying to the resolution of the names they need. For example, the privacy policy of 1.1.1.1 is pretty amazing from the perspective of data retention, secondary uses, etc. (e.g., I know my resolutions will be removed from their logs within 24 hours).

This may seem small but it seems to be lost in the centralization/choice discussion.
--
Joseph Lorenzo Hall
Chief Technologist, Center for Democracy & Technology [https://www.cdt.org]
1401 K ST NW STE 200, Washington DC 20005-3497
e: joe@cdt.org<mailto:joe@cdt.org>, p: 202.407.8825, pgp: https://josephhall.org/gpg-key
Fingerprint: 3CA2 8D7B 9F6D DBD3 4B10  1607 5F86 6987 40A9 A871