Re: [Add] On the topic of routers doing dns with DC

Michael Richardson <mcr+ietf@sandelman.ca> Fri, 22 March 2024 01:03 UTC

Return-Path: <mcr+ietf@sandelman.ca>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AE0A1C14F6B6 for <add@ietfa.amsl.com>; Thu, 21 Mar 2024 18:03:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.107
X-Spam-Level:
X-Spam-Status: No, score=-2.107 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=sandelman.ca
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 87qASMjV0hOg for <add@ietfa.amsl.com>; Thu, 21 Mar 2024 18:02:56 -0700 (PDT)
Received: from relay.sandelman.ca (relay.cooperix.net [176.58.120.209]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 72C3EC14F6B2 for <add@ietf.org>; Thu, 21 Mar 2024 18:02:55 -0700 (PDT)
Received: from dyas.sandelman.ca (unknown [IPv6:2001:67c:370:1998:198:77d:65ec:928b]) by relay.sandelman.ca (Postfix) with ESMTPS id D454E1F4A8 for <add@ietf.org>; Fri, 22 Mar 2024 01:02:53 +0000 (UTC)
Authentication-Results: relay.sandelman.ca; dkim=pass (2048-bit key; secure) header.d=sandelman.ca header.i=@sandelman.ca header.b="jCoJ3wzf"; dkim-atps=neutral
Received: by dyas.sandelman.ca (Postfix, from userid 1000) id 426D6A190E; Fri, 22 Mar 2024 11:02:51 +1000 (AEST)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=sandelman.ca; s=dyas; t=1711069371; bh=HuyrR21ebmX/HblwVTQjMmIRloC81C/m6JdenSyYlwk=; h=From:To:Subject:In-reply-to:References:Date:From; b=jCoJ3wzfjKWCrW+kHlCnfDGgk6cowgoyWFMEK0RAyWvW0O9eDjvoA6j5NplDx11e4 eqCh4/umyow1l0qzAuJ5X9euvjIO7OEzopCV3dmeVZYWdw3X4LNpi/Rj8U/7cdlGKD 3vCghqfcB4tnuQVDIZta/D2GGbnas8VSu7vPZbUNiSdX6yjOXXgjecA7vMSI5kLQjf c5c8coLpTfnzpj0Q3SO1PDahKg79yrt6ZSsRebO7fMaE9n8r1Ib3Tcb2MhjyyRtSaA DUEtk8XkweSm0obXKbhCXRoCD5eKporR00qyenIRzY5b4egGnRbYPsEn/JnlFlhnrh 27xJbNkN8HG/w==
Received: from dyas (localhost [127.0.0.1]) by dyas.sandelman.ca (Postfix) with ESMTP id 3F3B4A0C77 for <add@ietf.org>; Fri, 22 Mar 2024 11:02:51 +1000 (AEST)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: ADD Mailing list <add@ietf.org>
In-reply-to: <ADAF56A8-9C1C-4041-A78D-27E6ED15A17D@nohats.ca>
References: <ADAF56A8-9C1C-4041-A78D-27E6ED15A17D@nohats.ca>
Comments: In-reply-to Paul Wouters <paul@nohats.ca> message dated "Fri, 22 Mar 2024 07:02:49 +1000."
X-Mailer: MH-E 8.6+git; nmh 1.7+dev; GNU Emacs 26.3
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg="pgp-sha512"; protocol="application/pgp-signature"
Date: Fri, 22 Mar 2024 11:02:51 +1000
Message-ID: <230093.1711069371@dyas>
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/y_fu0-KIIdqatUWOcIssw56qXJM>
Subject: Re: [Add] On the topic of routers doing dns with DC
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 22 Mar 2024 01:03:00 -0000

Paul Wouters <paul@nohats.ca> wrote:
    > Previous discussion on this feature came with claims of CPEs being very
    > secure these days and it’s safe to do ADD with DC.

    > This just came in on the dns unbound list:

So, what?  Lots of ISPs and vendors run ancient code here.
This refrain from you is getting really really annoying and disruptive.
It completely lacks any technical content.

Those ZTE devices aren't about to be upgraded to add ADD, PERIOD.

Meanwhile, multiple jurisdictions have legislation/regulation that will make
these devices illegal to sell starting in April.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-                      *I*LIKE*TRAINS*