Re: [dns-privacy] Datatracker State Update Notice: <draft-ietf-dprive-rfc7626-bis-04.txt>

Andrew Campling <andrew.campling@419.consulting> Wed, 13 May 2020 21:46 UTC

Return-Path: <andrew.campling@419.consulting>
X-Original-To: dns-privacy@ietfa.amsl.com
Delivered-To: dns-privacy@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4705A3A0971 for <dns-privacy@ietfa.amsl.com>; Wed, 13 May 2020 14:46:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=netorgft5189650.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uEOAfjqPIlgw for <dns-privacy@ietfa.amsl.com>; Wed, 13 May 2020 14:46:56 -0700 (PDT)
Received: from GBR01-CWL-obe.outbound.protection.outlook.com (mail-eopbgr110083.outbound.protection.outlook.com [40.107.11.83]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 481FA3A096A for <dns-privacy@ietf.org>; Wed, 13 May 2020 14:46:56 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=LgPU9b8zBEsH632kCUPGpbOwUmpPVqvYeHvGdO0Vttyxwdb7IUVjxk5ek6BoJOq5pL/drvToirIikZS4/96CkFhi+oAAes7rYcypUj/CwwBKjQZvPBBkQ4tihr2eUl8gVHfMFgYxm/Z0MS4goDReYfGquEBd5N9y+ngvN7C7l4mz05I95S/21HQyV/YP6V9FUO2dH8TdZHajdkSN/BAoxK2yfEBayLpN+nT7fJ3WFmVH6G3i0uCivwWCABrx2+Z5Qx+Ex14HwAHj5onSQmYq4Ggk/yYfsN5/8dtKPvUIBzMQ1rJpnhjW0l748+hqbvkti03j7qga0757R5IvNpsSJQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=wHY1PPeaGQ577Iw4ymav1MhQA2JRWee+fHybZgz1bvQ=; b=MKOfVuuE6EexBf0JvNcqCXJcJ9Tbk6J0upyoKngsqToPlZmEQPkUho8nAVntPKZNcyoxx/7//8Ib6ubIx9IZ047nzM0vquy1W6OjseFzoaYjqZzpj1nmQDPRkkTr+AtNEN23SKKz1NPBC+oG/Gd0PPzRsBzY6QkA96V8stYH01QZKBFzUJ0KvmskwhKiBgqwlbefS2ZnX2wU8BHDWDhZGSk9bmV+omSjYZVRHTFCFnKUy2Z+lbVG9M/QNZ/jp3MFEGMDUmNeStCYb91F90lsea+ZoHOgfNlXFApSEXNcRFjw1PEtwvtj3SIXnzIXECGUEw/y3yyAjqWFKEalLL+wsg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=419.consulting; dmarc=pass action=none header.from=419.consulting; dkim=pass header.d=419.consulting; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=NETORGFT5189650.onmicrosoft.com; s=selector1-NETORGFT5189650-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=wHY1PPeaGQ577Iw4ymav1MhQA2JRWee+fHybZgz1bvQ=; b=k5MxhLN1bXetQRDnloYp+dBVc81Orw+u2g3VddpYCM7k72LI7g9HfZzjyqf4UESab0tvQTJIGd2o7/fch9o7sfJwFCzQlbwUFGZ9DB5uAJTmVa4lyl8wrHHXXJ9hFGNosJnEBDf3hjoACS27Mar32FIo0Ae9vDP2/wrKKLrkXbo=
Received: from LO2P265MB0573.GBRP265.PROD.OUTLOOK.COM (10.166.85.15) by LO2P265MB0767.GBRP265.PROD.OUTLOOK.COM (10.166.100.148) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2979.34; Wed, 13 May 2020 21:46:53 +0000
Received: from LO2P265MB0573.GBRP265.PROD.OUTLOOK.COM ([fe80::683d:f224:e857:746a]) by LO2P265MB0573.GBRP265.PROD.OUTLOOK.COM ([fe80::683d:f224:e857:746a%5]) with mapi id 15.20.2979.033; Wed, 13 May 2020 21:46:53 +0000
From: Andrew Campling <andrew.campling@419.consulting>
To: S Moonesamy <sm+ietf@elandsys.com>, Ben Schwartz <bemasc=40google.com@dmarc.ietf.org>, Vittorio Bertola <vittorio.bertola=40open-xchange.com@dmarc.ietf.org>, "dns-privacy@ietf.org" <dns-privacy@ietf.org>
Thread-Topic: [dns-privacy] Datatracker State Update Notice: <draft-ietf-dprive-rfc7626-bis-04.txt>
Thread-Index: AQHWKVkJH60xGhTtTUuRquL7l8Isy6imilXQ
Date: Wed, 13 May 2020 21:46:53 +0000
Message-ID: <LO2P265MB05735B9AC7B76A5E3A969623C2BF0@LO2P265MB0573.GBRP265.PROD.OUTLOOK.COM>
References: <157955609351.1744.15099511006231348523.idtracker@ietfa.amsl.com> <F6C06842-9D76-45DF-84A0-B0C4D724E66E@sinodun.com> <CABcZeBPVocy593=WJM2k3Ytrwg36qc_1d4VQH3otRM5qyvZwLA@mail.gmail.com> <1388052392.1781.1586274052101@appsuite-gw1.open-xchange.com> <CABcZeBNi2LKvGFcmTM0uC+rFEVm5tgw6Zo1LS_CoO5=Zo0zqSA@mail.gmail.com> <C03AC6C2-9DCB-448A-B906-3062BD616E31@sinodun.com> <CAMOjQcGrWXFpStp=iVbo1jVN3qnen8rC71SyXv6evY2-MgUdxg@mail.gmail.com> <3345FB83-A19A-4542-8A8E-C535884B157F@sinodun.com> <CABcZeBPP6J=a=hW6BLcMnKawupa3RjjpYAzgZ317=ryLy39n+A@mail.gmail.com> <8CEFE3CB-A88C-4BBC-95B8-9850142DB5EE@sinodun.com> <CABcZeBPF41eq-HYXdYScx7bqYyUO7-oH6zWKqj7Ka23u8x_E4A@mail.gmail.com> <ACA9854E-00B7-4776-A850-E5069C672121@cisco.com> <CABcZeBOxN7iNTLFUw7JDc4ZGH_u4awys3g52de29CuOyQv2JUQ@mail.gmail.com> <C8B168D0-F719-405F-892F-14573A7C568D@sinodun.com> <CABcZeBPGAgqSPKWXKaL6kK5CYzgK+RmwFrMwhc6ED7aGnV_ayA@mail.gmail.com> <8AB227E2-F968-47C4-9EB6-40A988263892@sinodun.com> <4fc44293-cdd9-24b7-cf26-1451a3652f73@huitema.net> <541315765.30668.1589285684382@appsuite-gw2.open-xchange.com> <CAHbrMsBrB-BGog8kjE0WRBpNVZ16z-nBSpKXXzUYrfwm1bY68A@mail.gmail.com> <6.2.5.6.2.20200513095536.0aca0bb8@elandnews.com>
In-Reply-To: <6.2.5.6.2.20200513095536.0aca0bb8@elandnews.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: elandsys.com; dkim=none (message not signed) header.d=none;elandsys.com; dmarc=none action=none header.from=419.consulting;
x-originating-ip: [86.133.67.158]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 660bd4a7-51aa-4f70-bdc1-08d7f78726b0
x-ms-traffictypediagnostic: LO2P265MB0767:
x-microsoft-antispam-prvs: <LO2P265MB076788AA96E11AA0D526D0C9C2BF0@LO2P265MB0767.GBRP265.PROD.OUTLOOK.COM>
x-ms-oob-tlc-oobclassifiers: OLM:8273;
x-forefront-prvs: 0402872DA1
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: Ia/7Lhqo8/BwPOsgas22wC/lhOrbpr75OrG5PfLUQc/+AbH8DcKr/54faeX/d+gzDEyBw5ScJb79CnjV2gnwD8c/c1IFxn6HmZ2CViMFhrhtG6bmt0FhROOUD+bwkx3X4Etk+2dtIOjM1NB6vx5QiHNSpRTu7KAWvuII721UOsDp2rDcSL4SyaAhjTbgk2uNSTp0mTeo1Sj9XNr1lXUjLMQpGiqe/G95p5jNaG5Wxr8v4YkDfGoNWw0IKb6wqXLuXEaXIs5m6k2x1ZbcYC5zkUHkDO7cMMP3b5268VjVJoPb6MqzQyrbV5evZt2AWNf1Dd7jlVU34s4mPlZSvTGy6m7iihtWIn8KXaClQcwx8OzqCWAPGqae1Fm7u0sD7nnCdpG9Cbn0/iK7ugNAnRvC7hLT6f0fNgYTg1MTGDfNgQGg0DINEsV+UuDHEto8OL0bmQLrMD29oidb6C3IKpD3BkBl6BtyGz4yyyQZ//JX0RBNU/8vLUO3dLCA9tNbySzrSCIsf8TdLV3BKo4XQ50FHfq8XFKI4+gYyopUNREqKu6MmPeCxItHRDXIpBED4xU7
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:LO2P265MB0573.GBRP265.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFTY:; SFS:(136003)(396003)(366004)(376002)(39830400003)(346002)(33430700001)(8676002)(66946007)(5660300002)(110136005)(66556008)(55016002)(66476007)(66446008)(76116006)(86362001)(33656002)(44832011)(7696005)(52536014)(26005)(316002)(508600001)(64756008)(2906002)(71200400001)(186003)(33440700001)(6506007)(9686003)(8936002)(66574014)(46492006); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: m8SAR0Irrj9okJrttU8wAZQJfEJD2fzJZEpdegOeG0X0NCfcHVbp97ne3AE8ppzqqbQBqROJJ350kcRrnI2nb1znClIKN65OkvjDRihIIsPb4y7A7GUHSbDmgiY6FdeSR5m4Cy/5YqH1DhtgyAjv6+5IBH3/vmnNvANhze7GlN/TXpjKBBfmwquqKYiu1OD4DVSCzGlptqMcObXRz1ddSdWgD3i43qZkyhx+h7JhNGEpevOLedZpGeetHGAmm0tWXrIlY8SsjShfYuuFgYFjRhKx/Cfee4VwAum17avhELiNKyDPF0xHRTLQTw/otoHkYOSAdKsuDW3nBq5u9IRLQn6KyP+yIlWunyt4ZNJSlFw/RTPD3kpkTWqLapg7UG/ob+ZA43jcl2zYlgGbvRZ4Xl6kFHKnCVNsmIp8ZkwaFivnu5I6TAnw2K8lpaj1a2p9A1IcJa/3/Cn8bpRaKISQD1QogEm/maRrCaRnnD4lics=
x-ms-exchange-transport-forked: True
Content-Type: multipart/alternative; boundary="_000_LO2P265MB05735B9AC7B76A5E3A969623C2BF0LO2P265MB0573GBRP_"
MIME-Version: 1.0
X-OriginatorOrg: 419.consulting
X-MS-Exchange-CrossTenant-Network-Message-Id: 660bd4a7-51aa-4f70-bdc1-08d7f78726b0
X-MS-Exchange-CrossTenant-originalarrivaltime: 13 May 2020 21:46:53.6827 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 9c2ced3e-7522-4755-87dc-f983abc66ec3
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 8qiapdzn4IzuxpD7w0ptVKNYsmhhZJYt1sf8KaSyRLaWBcOofMGPByNKRmaoE9mClDSTA1RKdm0hXHmkhIfNFPoZjFBLQnbYTIahiUyO+2k=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: LO2P265MB0767
Archived-At: <https://mailarchive.ietf.org/arch/msg/dns-privacy/Dsk5OLJ6YTyxvbx7ICR_jcvxCQ0>
Subject: Re: [dns-privacy] Datatracker State Update Notice: <draft-ietf-dprive-rfc7626-bis-04.txt>
X-BeenThere: dns-privacy@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <dns-privacy.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dns-privacy/>
List-Post: <mailto:dns-privacy@ietf.org>
List-Help: <mailto:dns-privacy-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 May 2020 21:46:58 -0000

At 13 May 2020 18:10, S Moonesamy <sm+ietf@elandsys.com> wrote:



>Hi Ben,

>At 08:12 PM 12-05-2020, Ben Schwartz wrote:

>>That seems quite contentious to me.  Decentralization of the DNS is

>>_also_ a privacy threat: running your own recursive leaks your IP to

>>every authoritative (far worse than ECS!), pinning yourself to a unique

>>recursive makes you uniquely identifiable as you move across the

>>network, and using a recursive whose identity is unknown is obviously a

>>privacy concern.

>

>I commented about "centralization" within the context of IETF work on

>several occasions.  My opinion is likely clouded by past experience.

>With respect to privacy, I spent around two years getting the IESG to

>take it seriously.

>

>From what I recall of what is written in RFCs, DNS is described as a

>distributed database.  There are some advantages of it being distributed,

>or if I may say so, decentralized.  For example, some countries might

>wish to have some degree of control over their ccTLD.  System failures

>do not generally affect a majority of users.

>

>There are obviously privacy implications.  Within an IETF context, it would

>make surveillance easier if everything is one provider.



I note that draft-arkko-arch-infrastructure-centralisation made some helpful observations regarding the dangers of centralisation, with specific points relating to DNS.  It included the following points in the recommendation section: "Where such centralised points are created, they will eventually fail, or they will be misused through surveillance or legal actions regardless of the best efforts of the Internet community.  The best defense to data leak is to avoid creating that data store to begin with".  This seems to be good advice to me.



Andrew