[Add] Re: Hosting Encrypted Servers on CPEs / HTTPS for Local Domains

Michael Sweet <msweet@msweet.org> Tue, 10 September 2024 16:44 UTC

Return-Path: <msweet@msweet.org>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2477EC14F609; Tue, 10 Sep 2024 09:44:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.106
X-Spam-Level:
X-Spam-Status: No, score=-7.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=msweet.org
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dqLTtHmT6hfP; Tue, 10 Sep 2024 09:44:47 -0700 (PDT)
Received: from mail.msweet.org (mail.msweet.org [173.255.209.91]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 213CEC14F6FE; Tue, 10 Sep 2024 09:44:47 -0700 (PDT)
Received: from smtpclient.apple (cbl-66-186-76-47.vianet.ca [66.186.76.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.msweet.org (Postfix) with ESMTPSA id 401B480F0A; Tue, 10 Sep 2024 16:44:46 +0000 (UTC)
DKIM-Filter: OpenDKIM Filter v2.11.0 mail.msweet.org 401B480F0A
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=msweet.org; s=default; t=1725986686; bh=vDtKB8xIGwH/OwVykVA7G22jz8ecl3TdZNvB3KM4Xjc=; h=Subject:From:In-Reply-To:Date:Cc:References:To:From; b=hpNkZLybC7UWRBadHDwXWV1HHL3pPAwaDUQryZIK9CbhDFnqJly4zV4jK85gkcc6B 8MDz4XVusXqvXEWNOWFLOcxfm+GJ0iWv19ZZ1GZtX0tkjRnzGgWADUwpGepulBvfCS 9c3t6+T99r5fqs3wX4moqsJQVLcmByl42ezQ1buA=
Content-Type: multipart/signed; boundary="Apple-Mail=_EE320A71-B8AB-4257-BC0A-68ADE36BCA80"; protocol="application/pgp-signature"; micalg="pgp-sha256"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3776.700.51\))
From: Michael Sweet <msweet@msweet.org>
In-Reply-To: <ZuBviIVAlXUpgJNh@faui48e.informatik.uni-erlangen.de>
Date: Tue, 10 Sep 2024 12:44:36 -0400
Message-Id: <157E10CE-BA2C-4941-8D4D-D21CD95B5374@msweet.org>
References: <6FCA933A-F329-4B45-9C72-32FFCAD289BE@gmail.com> <CACJ6M16MgxzE+8Yiebd9hbYC_tY2tt0Sroc4_izOnP3kO3e5fQ@mail.gmail.com> <MW4PR15MB437956E8735320FFE83037C7B3952@MW4PR15MB4379.namprd15.prod.outlook.com> <ZtpGfh15m58gId0Z@faui48e.informatik.uni-erlangen.de> <21866.1725908702@obiwan.sandelman.ca> <3B84302E-11BC-4695-9C31-9179AD32FDB3@gmail.com> <ZuBviIVAlXUpgJNh@faui48e.informatik.uni-erlangen.de>
To: Toerless Eckert <tte@cs.fau.de>
X-Mailer: Apple Mail (2.3776.700.51)
Message-ID-Hash: C3VU2UEEPHCQKN7EVMZN23HIMH22VN7R
X-Message-ID-Hash: C3VU2UEEPHCQKN7EVMZN23HIMH22VN7R
X-MailFrom: msweet@msweet.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Dan Wing <danwing@gmail.com>, Michael Richardson <mcr+ietf@sandelman.ca>, "add@ietf.org" <add@ietf.org>, anima@ietf.org, iotops@ietf.org
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [Add] Re: Hosting Encrypted Servers on CPEs / HTTPS for Local Domains
List-Id: Applications Doing DNS <add.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/oUKwoDFyuIrdA8mNtP42RAa78F8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Owner: <mailto:add-owner@ietf.org>
List-Post: <mailto:add@ietf.org>
List-Subscribe: <mailto:add-join@ietf.org>
List-Unsubscribe: <mailto:add-leave@ietf.org>

Toerless,

> On Sep 10, 2024, at 12:10 PM, Toerless Eckert <tte@cs.fau.de> wrote:
> ...
> So, all-in-all i think i would try to stay away from QR codes whenever i can, home or 
> industrial - but to make that work, the whole network based solutions need a lot more detail
> improvement work.
> 
> Theoretically i think NFC would be a great option, but i have no actual experience. But the
> idea of having a box of 50 devices, and the reseller just has to type a button on the smartphone
> to register all 50 devices' NFC tags - that just sounds like an intriguing option. Would also
> have solved my QR code experiences. But not sure if it would be cheap enough for typical
> home automatin IOT devices. 

I agree that QR codes and NFC tags have their place and have potential for making onboarding easier.  But I also like how HomeKit/Matter also supports type-in codes if you can't easily scan the QR code.

FWIW, I have a bunch of "smart" plugs whose QR codes are on the bottom of the plug, making it impossible to scan while plugged in. But if you try scanning and then plugging in right after the onboarding app says it can't find the plug...  I also have some devices (routers and printers) that have an access password printed in an inaccessible place, for which I've taken pictures with my phone and stored them in a special "devices" folder for the odd times I need them... Sometimes you need to get the right people involved when they decide where to put these things, otherwise the user experience will suck.

________________________
Michael Sweet