Re: [dns-privacy] Adam Roach's No Objection on draft-ietf-dprive-bcp-op-08: (with COMMENT)

Rob Sayre <sayrer@gmail.com> Thu, 06 February 2020 05:36 UTC

Return-Path: <sayrer@gmail.com>
X-Original-To: dns-privacy@ietfa.amsl.com
Delivered-To: dns-privacy@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 66EE012001A; Wed, 5 Feb 2020 21:36:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.997
X-Spam-Level:
X-Spam-Status: No, score=-1.997 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id H2ilw9feYCGS; Wed, 5 Feb 2020 21:36:01 -0800 (PST)
Received: from mail-io1-xd42.google.com (mail-io1-xd42.google.com [IPv6:2607:f8b0:4864:20::d42]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 71A13120120; Wed, 5 Feb 2020 21:36:01 -0800 (PST)
Received: by mail-io1-xd42.google.com with SMTP id d15so4973608iog.3; Wed, 05 Feb 2020 21:36:01 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=BH8BWxwATFtX4LtQzKJdiZnNvU9NSy9QuUiNa8MNseM=; b=f9W4EQ9JYCBv2lB42wxzQz+TeuxDG9xcj7IDac5Hoec7O49AWzsiIDwVdepw35ez4X C5n1CUCqBSdaHHjhGqkyxWRtvbJzjDA2v1krmtwL5lfgByAqsmfUBKbt39F+PFAPh5jH 5VYVpYFxav6tE0CxehbAMIbMzkCenI/OHUSH+BLx79Ig8efI0SJeUSPM857NC2BhgHBk N48b3WPd5wrbydQ2ckIie+rhyrKr9QO5smvBODxfJG+/xwiBlqzIl2DB826C6dCXsifY A/OKoOJbsw50qR2zSB3S1AigC8PAdoWWpeOvH7pkkW8U1wvuWx2OWKos3dTwAzwNfU6J QsTA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=BH8BWxwATFtX4LtQzKJdiZnNvU9NSy9QuUiNa8MNseM=; b=pmAogBrxYArlixCAJmF0cuotgwDL2NvRKlZusaFojQ8F+LQNveaHDsWbyy9prWEYC6 aC/Qj/D7Nff/LN6FzxFK3GJhwRQheUo3rBFM4JbWJ00ynv8MRn+xKk5dzeP2nDlkx1sW NmhW/ie5/0VksFLs7dfyNAmmG59eSMynajNFE13upCgdJnfgmNJmKLqSjX69zI1zmXtt LFCfeLN5YeyDcEg2y2SQqKJX6e0rZLPNX84OnZs+e3wRwsSH/QIzRqg2pPMYuiRD8QsJ SD4WQQFVysOD3Koj7qKEe0HZndRj4MhfZzOQiOFmzNuJ5u/B5jPj8XhMQeslUcil7oh+ gohw==
X-Gm-Message-State: APjAAAVdEokBHjAbISLZLt5bSdTOXPFIyT7rhXferoJC46FYvzZ4Yf4H Uk4vnnq9ya8Y7c/Eg0GEXkeWyzr9AxgnoboCOpE=
X-Google-Smtp-Source: APXvYqx1MaOPlShn1n84WUziXaox6jK8gY2/t3JWzdVjvOGcS3FgPPl66CVR6wjPexK+K78ML4l7QKnOUKV63M2GcME=
X-Received: by 2002:a6b:6103:: with SMTP id v3mr32318552iob.49.1580967360724; Wed, 05 Feb 2020 21:36:00 -0800 (PST)
MIME-Version: 1.0
References: <158096547226.30514.2103023305468871108.idtracker@ietfa.amsl.com>
In-Reply-To: <158096547226.30514.2103023305468871108.idtracker@ietfa.amsl.com>
From: Rob Sayre <sayrer@gmail.com>
Date: Wed, 05 Feb 2020 21:35:46 -0800
Message-ID: <CAChr6SzPwqezNjLBdAhJb=N6hLxjwJ8j2tnugrEUaqR8JhCKjA@mail.gmail.com>
To: Adam Roach <adam@nostrum.com>
Cc: The IESG <iesg@ietf.org>, Tim Wicinski <tjw.ietf@gmail.com>, draft-ietf-dprive-bcp-op@ietf.org, DNS Privacy Working Group <dns-privacy@ietf.org>, dprive-chairs@ietf.org
Content-Type: multipart/alternative; boundary="000000000000f00473059de1a5e6"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dns-privacy/SWbOoKXSEUUk-FrfZecojLxWT-E>
Subject: Re: [dns-privacy] Adam Roach's No Objection on draft-ietf-dprive-bcp-op-08: (with COMMENT)
X-BeenThere: dns-privacy@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <dns-privacy.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dns-privacy/>
List-Post: <mailto:dns-privacy@ietf.org>
List-Help: <mailto:dns-privacy-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 06 Feb 2020 05:36:04 -0000

On Wed, Feb 5, 2020 at 9:04 PM Adam Roach via Datatracker <noreply@ietf.org>
wrote:

> §5.1.4:
>
> >  DNS Privacy Threats:
> >
> >  o  Users may be directed to bogus IP addresses for e.g. websites
> >     where they might reveal personal information to attackers.
>
> You might want to consider a different example than websites here. 80% of
> worldwide website traffic is secured by HTTPS, which means than any such
> attempts will be prevented by WebPKI certificate mismatches.
>

While I agree that this example could use a caveat, I do not believe WebPKI
certificate mismatches will always prevent these attempts.

thanks,
Rob