Re: [dns-privacy] Datatracker State Update Notice: <draft-ietf-dprive-rfc7626-bis-04.txt>

Eric Orth <ericorth@google.com> Tue, 07 April 2020 16:11 UTC

Return-Path: <ericorth@google.com>
X-Original-To: dns-privacy@ietfa.amsl.com
Delivered-To: dns-privacy@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EDC283A0DE6 for <dns-privacy@ietfa.amsl.com>; Tue, 7 Apr 2020 09:11:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -17.6
X-Spam-Level:
X-Spam-Status: No, score=-17.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rUJFj9oDgEN2 for <dns-privacy@ietfa.amsl.com>; Tue, 7 Apr 2020 09:11:21 -0700 (PDT)
Received: from mail-wm1-x334.google.com (mail-wm1-x334.google.com [IPv6:2a00:1450:4864:20::334]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 945CA3A0DDC for <dns-privacy@ietf.org>; Tue, 7 Apr 2020 09:11:19 -0700 (PDT)
Received: by mail-wm1-x334.google.com with SMTP id h2so2302554wmb.4 for <dns-privacy@ietf.org>; Tue, 07 Apr 2020 09:11:19 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=6mlf1r7dGOLiCOQegQELdvjFxn0OFwTf9k0PD9edoN0=; b=pF2PNaB6Af/ZpI4JMwxdkwBUP3EXu/sQR9uqTCJoYcwfHW4xDQ2tLlnOQ5w2Sc3Ff+ bSXPqkiAm7x1J4Ao5cnTfYYYhi/elKY1i9vOZ3AhEPWQiLx9u2xPGGYfKXxs7m6ArGeY SD2lJJeVf8Mofi0FxnamQIbqDFkH+JXBd7qxwbnO6jEnLiFp0FIAezJOv7wvTtdHWsJE UVfVyDaq+/jEwPjcJNwVOPUDPCtCEU2iqgtHfi+Sb8GpqCe+t0fpo2REZkMM+s8HHsx/ RPhj/m24UvcvbxLv/tFogXYNUCSYvlrcgpiyFp8j2OqjeCZLVfDuww9QeUlzwSXnKbFO WoaQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=6mlf1r7dGOLiCOQegQELdvjFxn0OFwTf9k0PD9edoN0=; b=ZiceGaUleIDp1Q7TCLSvgpq2mtns7UKhFWpJjjDClpsPCkz37I9+0ftzGc2ACG3lZi 6NhXIqKe6Sh7qwKYXz9Z4JgqzmR05NGnO1ywX08fGEM7zO2SFQXziCpRvFAuFptWjVO9 UmmzlxK9rLCT3YRvGycdxzstpr+wwrORGX6dANtSxy5ID3496ZD2AE2Zl2rKx+PkSHNZ FE5UGKjyecgqpKUFCYuR3gyyEmmKhM9CSEJ8ueusXDVPbjoesAhqZcLFlHCVcjPRJgFb re4zMcTsUB0SqFZ08+L0IphjViXboVr0pFdweyOZPlMOsl7/dveemDDfJnOewyTkG17T ibRA==
X-Gm-Message-State: AGi0PuYc20CPm7ij/Yl4JWiEmY/UOe4iIgSHcUeFCDEgSBSjeOUCCOQv 9CfN3tJ3xvEkLjIk03eneD6XplqtNsSwB5TiwfklHw==
X-Google-Smtp-Source: APiQypJWHhBuQZeYtXydqQtSOJWeBAZEdofxBsTysgcMTEEurfXeC4NlVzy9jTItF1Vx1SVsBjedu/EViFtaeODbIeE=
X-Received: by 2002:a1c:6a1a:: with SMTP id f26mr59571wmc.170.1586275877617; Tue, 07 Apr 2020 09:11:17 -0700 (PDT)
MIME-Version: 1.0
References: <157955609351.1744.15099511006231348523.idtracker@ietfa.amsl.com> <417BE033-4DE5-452A-BE93-0657C83051BC@cisco.com> <CABcZeBPK3yAaoai4ccd=hSffk5cAhoSC7gnBNqs36x-xJf=R-Q@mail.gmail.com> <503E2696-AB4A-4020-90CC-802D312D23AF@sinodun.com> <CABcZeBOiEu8qO_VHtHc7Fs47Wh0tGDn3ywM5LDZtWoxuHZ_isw@mail.gmail.com> <721AD54C-0324-4400-8492-4AA19A64699D@sinodun.com> <CABcZeBP4CknS=9Y96CqgykChg4H_jrgkaWmHPN4319+nXe=10w@mail.gmail.com> <CAH1iCiobuYitR26Hh0pbYpA_JZoB1a1iMyHJs1FAgW9GtOk56g@mail.gmail.com> <CABcZeBNa-OTEYjnL=+-F=WK3hZiOWmty1S=FC43Fr3CxuCPE_g@mail.gmail.com> <32D26638-2464-4E7B-8869-C65F773EF5F2@sinodun.com> <CABcZeBNnAZ1ttKHdtZMwWZGvWAYn3jZBps+hXOBMHQXgaKPUEA@mail.gmail.com> <00AF0382-CD8B-46F3-9838-50602379FE9F@sinodun.com> <CABcZeBOELM=d0xXgYN+r4cNsRO6=oyQscdwwdSTqypV5gNra0A@mail.gmail.com> <F6C06842-9D76-45DF-84A0-B0C4D724E66E@sinodun.com> <CABcZeBPVocy593=WJM2k3Ytrwg36qc_1d4VQH3otRM5qyvZwLA@mail.gmail.com> <1388052392.1781.1586274052101@appsuite-gw1.open-xchange.com> <CABcZeBNi2LKvGFcmTM0uC+rFEVm5tgw6Zo1LS_CoO5=Zo0zqSA@mail.gmail.com>
In-Reply-To: <CABcZeBNi2LKvGFcmTM0uC+rFEVm5tgw6Zo1LS_CoO5=Zo0zqSA@mail.gmail.com>
From: Eric Orth <ericorth@google.com>
Date: Tue, 07 Apr 2020 12:11:05 -0400
Message-ID: <CAMOjQcG+A6pt9PgJYKam6qSjXnOAdmvoARFBroC+9Xq2LQ1JWw@mail.gmail.com>
To: Eric Rescorla <ekr@rtfm.com>
Cc: Vittorio Bertola <vittorio.bertola@open-xchange.com>, "dns-privacy@ietf.org" <dns-privacy@ietf.org>, "Eric Vyncke (evyncke)" <evyncke@cisco.com>, Sara Dickinson <sara@sinodun.com>, "draft-ietf-dprive-rfc7626-bis@ietf.org" <draft-ietf-dprive-rfc7626-bis@ietf.org>, "dprive-chairs@ietf.org" <dprive-chairs@ietf.org>
Content-Type: multipart/alternative; boundary="00000000000033e05605a2b5a224"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dns-privacy/fvSd0EwnnlE3oqTsSW8n0tlTrjQ>
Subject: Re: [dns-privacy] Datatracker State Update Notice: <draft-ietf-dprive-rfc7626-bis-04.txt>
X-BeenThere: dns-privacy@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <dns-privacy.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dns-privacy/>
List-Post: <mailto:dns-privacy@ietf.org>
List-Help: <mailto:dns-privacy-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 07 Apr 2020 16:11:32 -0000

It is currently a very common* misunderstanding that system or
browser/application DNS configuration can somehow control malware
resolution.  Common enough that, IMO, any text on how to "control" or
configure resolution or "disable" features like DoH should include at least
a small clarification on the point of the scope/limitations of that
configuration.

*Anecdotal evidence is the large number of times I have been asked for
guidance on "stopping malware" through disabling Chrome DoH.  I always have
to give the reminder that I can only help with controlling resolutions
which go through Chrome, which malware will often not do.