Re: [Add] [EXTERNAL] Re: draft-grover-add-policy-detection-00

Rob Sayre <sayrer@gmail.com> Tue, 16 July 2019 19:19 UTC

Return-Path: <sayrer@gmail.com>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 123541200FD for <add@ietfa.amsl.com>; Tue, 16 Jul 2019 12:19:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.997
X-Spam-Level:
X-Spam-Status: No, score=-1.997 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 64KzbRNtZp2x for <add@ietfa.amsl.com>; Tue, 16 Jul 2019 12:19:53 -0700 (PDT)
Received: from mail-io1-xd43.google.com (mail-io1-xd43.google.com [IPv6:2607:f8b0:4864:20::d43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9771F120047 for <add@ietf.org>; Tue, 16 Jul 2019 12:19:53 -0700 (PDT)
Received: by mail-io1-xd43.google.com with SMTP id e20so11465597iob.9 for <add@ietf.org>; Tue, 16 Jul 2019 12:19:53 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=wlsLcm1A7n0BSPrNrxRlbPV4O0LpVS4JOWyF3FEnS1s=; b=sqR5QwRzbLarV9derngX1dYpbOvfXOg8Rm6I7S0FILSjGZdD1wI1Bm36C72p+rJfA6 RSJbBbI2sAXRyI9NLMsbHPgZu7H9YQSkIVldwnlIe6SEEtHeO7VNlE0hW3HQUpvyHSxF ahd9LBIG+FR50r2M/CdYGnv/W7WVpdZKmJoob8W7VI6GelZeNWhT6tL6JRY/Oz2szpHm 1XDdnte20AjvLZRd7YfFMcDMcMbGy6MqYPg0gI1YabbzZ17tEDYDeE+Z42SIEtjsFq8p 0nkrX43l7n34mu8hS45RhjYLQZEJPjJEhUI12hoN24J8ilh97BVn7ofVb5zOB85ao+rZ 0TgQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=wlsLcm1A7n0BSPrNrxRlbPV4O0LpVS4JOWyF3FEnS1s=; b=fXF+kyxCLWGDKaPOI//s2dT6aN5JsqIkqAhrQF/zLf3Pt36glx6Q/CsRw8+GXG+6cy fjidrrcBYf1cEKVg/K9ubsinahewE97/aA5e1EyOSs2Wkw9yHdmN301SCPap1m5X1vv2 1WS5DFvhWrRrbIbPrHc1gw26QaLxUXUFCBmnyLvo9LvB0kbq1JIbRbKnDK6cPe828Nu8 p18CDXrASDQtF/gjbENbxmrjq7xyOdCEmodzXJKEVuAQmSZye00J00VhYsJQiODY0Q/w dqPY09zK7qhcS9ijArQFW8PaNTP00uIqxltd2j/wJaaVTHp9Lc4ec7C0nnrTIDKeSPe2 89jw==
X-Gm-Message-State: APjAAAUlmp5HOhOKwHXUwPHOqTU27VBTB8cXI7D8xvicoAJzPvAusY7z n+ev2WErv1AdVxxw4XRg61VViMmkxg4fmYG/wKs=
X-Google-Smtp-Source: APXvYqwJgpYjnE2Qk790l6zzK0wL0ksJ7lZN90aMvAk+gnXSCEwPBoEXMT1kvmGW4UwPGek/TQXJviTP0CBA9SAJFWY=
X-Received: by 2002:a5e:d618:: with SMTP id w24mr32565955iom.73.1563304792880; Tue, 16 Jul 2019 12:19:52 -0700 (PDT)
MIME-Version: 1.0
References: <CAChr6SwEUz9MrdRA0bnv9f-oNi0oUHkfRKjd9-o6jwhuckLXdw@mail.gmail.com> <CAFWeb9LNdT=EYVKTsYDxcBCQKoQFNShKotYtWujt4U9GA-V1mg@mail.gmail.com> <CAFWeb9+eWKSKY9O2JLn9-0+Zq7hrD48F-y+Y4T-iRaaF0vtdOA@mail.gmail.com> <A45F4F74-D6C1-435A-A52F-C2DEA82E2999@sky.uk> <CAFWeb9JVBj+Yehup5q4v9X-7XDY+02frd-04AQGL2HoSLON2qA@mail.gmail.com> <CABcZeBMY9q9vKGse1svzbvXF_dSHA+9q06j4ugDVCZP9VT1koQ@mail.gmail.com> <CAChr6Sz5Rfz=UxOYuPguSvVK2HCX2ZoA1-FytW7+EOUxN8y46Q@mail.gmail.com> <CABcZeBNB7ASu2U3ZMBZ+OOxEhbSnhDXwFN3Lsex1uzVSDv3R=Q@mail.gmail.com> <CAChr6SwEwRRX7BA6ZCeBuC93hFxbfi3d7G_3G3VA7Lm09yuneg@mail.gmail.com> <CABcZeBNa97Vb6Fw-fMhoZnMezGtm3nJODENN4=XXsz7GWxf2Cg@mail.gmail.com> <CAChr6Sxm__NroZ92v4HL_6iCa62fwYgNw9r8ZDAxCdzVwNoDGw@mail.gmail.com> <20190716190219.5DEF4156CDF0@fafnir.remote.dragon.net> <CAChr6SzSkVU5xbh0sZCCEgd7BUdr-dMorNq=5iMkWp66k8PVow@mail.gmail.com>
In-Reply-To: <CAChr6SzSkVU5xbh0sZCCEgd7BUdr-dMorNq=5iMkWp66k8PVow@mail.gmail.com>
From: Rob Sayre <sayrer@gmail.com>
Date: Tue, 16 Jul 2019 12:19:41 -0700
Message-ID: <CAChr6SzW_Z25ikvQciFfES8883DmAAOkhsA=i-LgyMbgOodRNg@mail.gmail.com>
To: Paul Ebersman <list-add@dragon.net>
Cc: Eric Rescorla <ekr@rtfm.com>, add@ietf.org, "Dixon, Hugh" <Hugh.Dixon@sky.uk>, Alec Muffett <alec.muffett@gmail.com>
Content-Type: multipart/alternative; boundary="000000000000dafff7058dd142c4"
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/oGQZyY1jZz-B7prwIBAfh4syU7Y>
Subject: Re: [Add] [EXTERNAL] Re: draft-grover-add-policy-detection-00
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 16 Jul 2019 19:19:55 -0000

On Tue, Jul 16, 2019 at 12:10 PM Rob Sayre <sayrer@gmail.com> wrote:

> On Tue, Jul 16, 2019 at 12:02 PM Paul Ebersman <list-add@dragon.net>
> wrote:
>
>> Please stop saying this. Your own personal dissatisfaction is at odds
>> with literally millions of homes using these parental blocks via DNS and
>> most of the fortune 500 and many other SMBs using DNS RPZ/firewall. Both
>> parental and enterprise use are long standing, effective and popular.
>>
>
> I don't dispute that people sell them, but I do dispute that they work
> well.
>
> Whenever encryption is introduced to a protocol, there will be some
> middlebox vendors that get disintermediated.
>

So, to bring a little data to the table, two of the top 100 grossing US
iPhone apps are VPNs (Norton Secure VPN - WiFi Proxy, HotspotShield VPN &
Wifi Proxy).

I haven't used either one, but they are easily installed through the app
store and integrated into the iOS network settings app. These would bypass
any DNS-based filter policy.

You don't need to be hacker to install this stuff, and their position on
the grossing charts seems to indicated that they are effective (otherwise
people would not pay).

thanks,
Rob