Re: [dns-privacy] [Ext] Threat Model

Eric Rescorla <ekr@rtfm.com> Sat, 02 November 2019 18:35 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: dns-privacy@ietfa.amsl.com
Delivered-To: dns-privacy@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9A0641208CC for <dns-privacy@ietfa.amsl.com>; Sat, 2 Nov 2019 11:35:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.896
X-Spam-Level:
X-Spam-Status: No, score=-1.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=rtfm-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WqpqXDBSF784 for <dns-privacy@ietfa.amsl.com>; Sat, 2 Nov 2019 11:35:01 -0700 (PDT)
Received: from mail-lj1-x229.google.com (mail-lj1-x229.google.com [IPv6:2a00:1450:4864:20::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 84D1B12002E for <dns-privacy@ietf.org>; Sat, 2 Nov 2019 11:33:43 -0700 (PDT)
Received: by mail-lj1-x229.google.com with SMTP id q2so6883221ljg.7 for <dns-privacy@ietf.org>; Sat, 02 Nov 2019 11:33:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rtfm-com.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=hz64cjaF/Lnw0VpupusPqELB4SsZnNYkhjOiLMNrzeE=; b=yiFimdPk2zzrwuZYAzzBTIMbNUO/5Gm20HRSoQlGfa6CSQ0Y7yU3BUZHkf4+/H0zI+ gJC0oM8pGEyUfxiI/6bEWe+tmeck3repg09whvgCFj+C22G2hwutrLoRcN/5LkPtDdFL ZbzcIXDpSdbbwYfJzCXZuUC/fMmRJ/m7K0+/SFut5/4BfjLLSOvTGLuyd0WCWTj8ZejB 52LeiLNiIPIDR7E6OTHrHUqHDLkC3ZIVDZ7aYaRC6jsUdYQqvNE+CYmcjUwCp3nWciF+ LblODIbQKqvN6eM3P5iARRZX3zKPSrVo2Z06u2jSUBpggYwmh+j6lDJz8+mtCs98eoSI edJQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=hz64cjaF/Lnw0VpupusPqELB4SsZnNYkhjOiLMNrzeE=; b=Bp6Uyd5KyL/Ry3dM6DiwRuhJAeHfNzPqbuwCyhyOqGlMRx4d9rtqWPFsXXAbUTUra4 q82AEWW4sDJwy929UQvVsuV/bwOtAjHHKY8qcKliPI7IvqU7xBPUN8lss3Z3gXDZOHxS WfiXtwqU8FQcf1R3bQCzpiQBSxefNJIEqMf3W4zrNkkNouuLaRbzpY6ACl40ijpqLQkZ olyAAMpFTOw3I7bo+eKKHCHKGXfwtMo6W4qjKffiz9ReTllv/VmL7Z2Q2sODtA34CFI5 KD5MM1hjyCYYxCpXgRzsPXKnEj4GKNE3MLzVvRdecqX/YG20EqCk2q/sL5XF4Wdy33E/ RgBQ==
X-Gm-Message-State: APjAAAVMPgRbUatQ1MiMvNqApza6jh/2IpArWggRmlNi5mc9TRtmBzIX udt10RV34yThrh/83dEaAnpa8HkdrwYo55N0wk2cXqCQ
X-Google-Smtp-Source: APXvYqz++nHirLy4uKmgTx/p2HuNw9q37ryDp+hCGLrlMFlFLBhuhUaIKvv876uvIGq26NXb4zNh+pnOtcs/F/F7Nj0=
X-Received: by 2002:a05:651c:10c:: with SMTP id a12mr12844207ljb.93.1572719621506; Sat, 02 Nov 2019 11:33:41 -0700 (PDT)
MIME-Version: 1.0
References: <CABcZeBMQEJ=LE8ATQYnJj59srsK47hf4HT3BMMg3X2crVfSUXQ@mail.gmail.com> <1a70035e-edef-a3f4-ea91-52409ba37828@icann.org> <CABcZeBPAtvf3RU2gKWzyTaNwd6NBGsBuxq+n6r0W6-2RCnivSA@mail.gmail.com> <17189d1a-7689-f68d-6fe3-8d704af614a3@icann.org>
In-Reply-To: <17189d1a-7689-f68d-6fe3-8d704af614a3@icann.org>
From: Eric Rescorla <ekr@rtfm.com>
Date: Sat, 02 Nov 2019 11:33:04 -0700
Message-ID: <CABcZeBOhSYvqPyDcm9zbMYRc03DmPcCKYTYE-uC54=Mm9HMcnQ@mail.gmail.com>
To: Paul Hoffman <paul.hoffman@icann.org>
Cc: "dns-privacy@ietf.org" <dns-privacy@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000005f216405966152c1"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dns-privacy/b08ldaJx01S2r0Gi8Fngi7rZtj0>
Subject: Re: [dns-privacy] [Ext] Threat Model
X-BeenThere: dns-privacy@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <dns-privacy.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dns-privacy/>
List-Post: <mailto:dns-privacy@ietf.org>
List-Help: <mailto:dns-privacy-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 02 Nov 2019 18:35:04 -0000

On Sat, Nov 2, 2019 at 7:03 AM Paul Hoffman <paul.hoffman@icann.org> wrote:

> On 11/2/19 9:58 AM, Eric Rescorla wrote:
> > Generally, I would expect that a solution which addressed the active
> threat model would also address the passive one.
>
> Of course, but there are many threat models that have different solutions.
> The passive threat models might be addressable more quickly than the active
> threat model.
>

Yes, that's why I asked the question of whether we are trying to solve the
active attacker case.

-Ekr