Re: [Add] point of deploying DoH in access network (Re: meeting hum: should the IETF take up this work?)

"Robert Mortimer" <robm@scramworks.net> Fri, 02 August 2019 11:18 UTC

Return-Path: <robm@scramworks.net>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 92E59120096 for <add@ietfa.amsl.com>; Fri, 2 Aug 2019 04:18:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, HTML_NONELEMENT_30_40=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=scramworks.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qN1gHbu1KD50 for <add@ietfa.amsl.com>; Fri, 2 Aug 2019 04:18:46 -0700 (PDT)
Received: from knid.scramworks.net (knid.scramworks.net [IPv6:2a01:4f8:c17:50eb::2]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AAAE0120033 for <add@ietf.org>; Fri, 2 Aug 2019 04:18:46 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=scramworks.net; s=bofh; h=References:In-Reply-To:To:From:Subject:Message-ID :Date:MIME-Version:Content-Type; bh=g+jf7D2v6AydYbD9yYVV7/Phfx66YFyA6qxH0LssLWc=; b=Sb3WWp5pzFgZmbZ84BQrurGS4W AHID8z+7Nylqh0M99iq73I4ZXOSyJe7yHnGOmipUgb8ny9838zrygORBtxK/J3BGURIQezwC1hOaz 4jotnwMzXMWmwq1EwmInSx2ZyVrO+u1vmAAAMjPQW2K7cNpuHS7LDiW9dB3vBeOU/EbY=;
Received: from [90.240.166.166] (helo=[192.168.1.6]) by knid.scramworks.net with esmtpsa (TLS1.1:ECDHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.86_2) (envelope-from <robm@scramworks.net>) id 1htVa9-00052D-1f for add@ietf.org; Fri, 02 Aug 2019 12:18:45 +0100
Content-Type: multipart/alternative; boundary="----=_NextPart_27581608.602884925896"
MIME-Version: 1.0
Date: Fri, 02 Aug 2019 12:17:19 +0100
Message-ID: <26e4fa63-f50d-42d6-bcda-4d7e62b95704@getmailbird.com>
From: Robert Mortimer <robm@scramworks.net>
To: add@ietf.org
In-Reply-To: <alpine.DEB.2.20.1908021048100.11612@grey.csi.cam.ac.uk>
References: <CAChr6Sx9TEt6CMzRRrdb-HwT_k987oW=4yF1FCbDF17zkaE2Vg@mail.gmail.com> <2D09D61DDFA73D4C884805CC7865E6114E23910C@GAALPA1MSGUSRBF.ITServices.sbc.com> <20190724171549.GD29051@laperouse.bortzmeyer.org> <CAJE_bqf=9r5yvCMY+CGuXMQBCNY+a-RFQTzjJ83wOtawhUHR0g@mail.gmail.com> <alpine.DEB.2.20.1908021048100.11612@grey.csi.cam.ac.uk>
User-Agent: Mailbird/2.6.1.0
X-Mailbird-ID: 26e4fa63-f50d-42d6-bcda-4d7e62b95704@getmailbird.com
X-Spam-Score-SW: -1.0 (-)
X-SW-Scan: bdace1d3122527610c608ab96d92af77
X-Clacks-Overhead: GNU Terry Pratchett
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/wGE0ownSn0CSK1kXugVkUFKltC0>
Subject: Re: [Add] point of deploying DoH in access network (Re: meeting hum: should the IETF take up this work?)
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 02 Aug 2019 11:18:49 -0000

Tony,

 Just on the javascript in browser making DNS queries, already been done to control a spam campaign.
https://www.bleepingcomputer.com/news/security/new-spam-campaign-controlled-by-attackers-via-dns-txt-records/ [https://www.bleepingcomputer.com/news/security/new-spam-campaign-controlled-by-attackers-via-dns-txt-records/]

So the bad guys at least are already doing this. They could of course use other methods etc. etc.

-- 
Robm
873
  "Ask not what I can do for the stupid, 
         but what the stupid can do for me" - Graeme Garden
On 02/08/2019 10:53:31, Tony Finch <dot@dotat.at> wrote:
神明達哉 wrote:
> Stephane Bortzmeyer wrote:
> >
> > I'm tempted to say that I don't see the point for an access network to
> > deploy DoH.
>
> I've been wondering about this, too.

University not access network, but providing encrypted DNS to my users
means DoT for most cases and DoH for Firefox users. There's also the vague
notion from the early days of DoH that javascript in the browser might
make DNS queries but I haven't seen any evidence of that or even any
signs of interest in the idea.

Tony.
--
f.anthony.n.finch http://dotat.at/
West Viking: Northerly 3 to 5. Slight or moderate. Mainly fair. Good,
occasionally poor at first.--
Add mailing list
Add@ietf.org
https://www.ietf.org/mailman/listinfo/add