Re: [dns-privacy] [internet-drafts@ietf.org: I-D Action: draft-bortzmeyer-dns-qname-minimisation-00.txt]

Phillip Hallam-Baker <hallam@gmail.com> Thu, 20 March 2014 14:31 UTC

Return-Path: <hallam@gmail.com>
X-Original-To: dns-privacy@ietfa.amsl.com
Delivered-To: dns-privacy@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 04E5A1A0750 for <dns-privacy@ietfa.amsl.com>; Thu, 20 Mar 2014 07:31:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5h49LMAphj4f for <dns-privacy@ietfa.amsl.com>; Thu, 20 Mar 2014 07:31:09 -0700 (PDT)
Received: from mail-la0-x22e.google.com (mail-la0-x22e.google.com [IPv6:2a00:1450:4010:c03::22e]) by ietfa.amsl.com (Postfix) with ESMTP id 087AC1A03CA for <dns-privacy@ietf.org>; Thu, 20 Mar 2014 07:31:08 -0700 (PDT)
Received: by mail-la0-f46.google.com with SMTP id hr17so659865lab.5 for <dns-privacy@ietf.org>; Thu, 20 Mar 2014 07:30:59 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=bd+ZnaZW/SBvnEJwYlouy07R95gHCrBfldqE9jWwwg0=; b=i9Smt9gOryzbct/mYLCSoUgviDV7ZtuY1VrwTN5DDhB5nvroEZslXkdvgL5wod08pe RwDLi+HxSiSXYpW0hR2BxPfcE9s+n1E1Jx7WX54thlJQJUQghzxaSvZlXJVKyO1YtkT9 /bogp9yI0YxNoq5pGy6yrQGyv1yH11sJ52eSiIExm9FLj3pGy6gNlZzl29TJhCV+eN9H BSIR3d0hwpp8HFVtiXIYvb6LJlyI/bjakVeq+/of++f2PDgdOrR1rHlarncmStVBfX9m qP1fOHr9QZvqOMcuHVRTusXI3VU/qQj+NitfG/lfznarmFOWeyEyg5UxrUP9YBYuJnD3 lRCA==
MIME-Version: 1.0
X-Received: by 10.112.133.136 with SMTP id pc8mr1197518lbb.56.1395325859377; Thu, 20 Mar 2014 07:30:59 -0700 (PDT)
Received: by 10.112.234.229 with HTTP; Thu, 20 Mar 2014 07:30:59 -0700 (PDT)
In-Reply-To: <20140320142020.GA12147@sources.org>
References: <20140320103354.GA14856@nic.fr> <alpine.LSU.2.00.1403201044100.31260@hermes-1.csi.cam.ac.uk> <20140320142020.GA12147@sources.org>
Date: Thu, 20 Mar 2014 10:30:59 -0400
Message-ID: <CAMm+Lwjc9BDdFLT+dDX9grpmtcX7N_jkAbMNvjUPrTdy0gh2iA@mail.gmail.com>
From: Phillip Hallam-Baker <hallam@gmail.com>
To: Stephane Bortzmeyer <bortzmeyer@nic.fr>
Content-Type: text/plain; charset="ISO-8859-1"
Archived-At: http://mailarchive.ietf.org/arch/msg/dns-privacy/CA-sq3FJu1gS5XVIsAedRzfI79g
Cc: Tony Finch <dot@dotat.at>, dns-privacy@ietf.org
Subject: Re: [dns-privacy] [internet-drafts@ietf.org: I-D Action: draft-bortzmeyer-dns-qname-minimisation-00.txt]
X-BeenThere: dns-privacy@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: <dns-privacy.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dns-privacy/>
List-Post: <mailto:dns-privacy@ietf.org>
List-Help: <mailto:dns-privacy-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 20 Mar 2014 14:31:11 -0000

On Thu, Mar 20, 2014 at 10:20 AM, Stephane Bortzmeyer <bortzmeyer@nic.fr> wrote:
> On Thu, Mar 20, 2014 at 11:04:13AM +0000,
>  Tony Finch <dot@dotat.at> wrote
>  a message of 65 lines which said:
>
>> You say "[RFC2181] suggests an algorithm to find the zone cut" but
>> although it describes what a zone cut looks like I can't see any
>> clear description of an algorithm for finding them.
>
> The wording in my draft is not perfect. Indeed, DNS RFCs rarely
> describe algorithms, probably to let some freedom to the
> implementations.


I think this is a very important effort. But we probably need to think
of it in terms of the proposed DBOUND work rather than tell people to
try to discover the zone cut through heuristics.

Heuristics are OK as a transition strategy but I don't like them as a
long term fixture.


The problem I have with the current DBOUND discussion is that it is
being driven by a use case I think is completely unhelpful. There are
no occasions where I think it is safe to share cookies across domains.
So trying to come up with rules for when it is safe is a losing
proposition and so is trying to develop a technology to meet that
goal.

DNS Privacy is a much better defined concern and one that we have a
good chance of addressing with something like DBOUND.


-- 
Website: http://hallambaker.com/