Re: [dns-privacy] Datatracker State Update Notice: <draft-ietf-dprive-rfc7626-bis-04.txt>

Eric Rescorla <ekr@rtfm.com> Tue, 07 April 2020 15:48 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: dns-privacy@ietfa.amsl.com
Delivered-To: dns-privacy@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1C97E3A0D3A for <dns-privacy@ietfa.amsl.com>; Tue, 7 Apr 2020 08:48:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.896
X-Spam-Level:
X-Spam-Status: No, score=-1.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=rtfm-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rgainDCvVCrg for <dns-privacy@ietfa.amsl.com>; Tue, 7 Apr 2020 08:48:35 -0700 (PDT)
Received: from mail-lj1-x234.google.com (mail-lj1-x234.google.com [IPv6:2a00:1450:4864:20::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 82A003A0D40 for <dns-privacy@ietf.org>; Tue, 7 Apr 2020 08:48:35 -0700 (PDT)
Received: by mail-lj1-x234.google.com with SMTP id g27so4236232ljn.10 for <dns-privacy@ietf.org>; Tue, 07 Apr 2020 08:48:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rtfm-com.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=sOJjQuXsJzRVufMiaRAlMO5a+UgZyAEwSQva/6qwgb8=; b=mzVXdt5VSLQB8ed1roVt5sGcWioiq9o1Kf7KkmjlUurBNTGub1CREX0OurK9+aWboF mm0m0rmMLylIs6i4r9llmlM01RRu4J0UAqTETc7NZanlX7qX7SSpsZSFFZWGSQPwp5kZ Bw4tqnNMxVF8BiZo+K0SyvvYHuvVs71iG0BlpbKuhllQ/EER8VQJ1nl862A/9VAtXpBq qfQ6EeWhxG3poCPH2OLAoF3vjVnLANZZEpMyzVA2+CcMB1wIfHIeczzrTot2wuj5xa36 uttdM1uvoyTCGcK+Vid0WFy3KA2XNFCu4c2rt5552SVTWBhijEw4NL6EJ6GqfySNPLrh U/gw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=sOJjQuXsJzRVufMiaRAlMO5a+UgZyAEwSQva/6qwgb8=; b=hpuz8L2rPqaOAm7Dsi4Drw8YKXuYnFzUeKzAQQ5m5KzctWUaeo7KvhNE0oSGJECep9 tdCOO+Dx9qtbEVcuGtA3rRxT5cQRKi55AYO5EWG8qaJojtVr7UZdFn2z0MI0LOLdbH8P Ky4GEzDbP+4ADldiDA/IXGH6z4LdFpUGl16b9Nd+62t9i0K20eGo4uJNhnC3sW+Nscld zXSpr3x+Fk/EpNhAXE//gZRj6b293lt/AzZC6It5757MQ3wY8LOz1/huneyulW9zTTWZ tK26J+D43Me3/Fq4iYhgqa6CSNC0HlZDdMW/sKbL76EA4H5fa663vTywLlwZuTE0JY45 QvJw==
X-Gm-Message-State: AGi0Puaxwa6I/GZi0ZDkgQlfDPSzOkhAOIeu7bFOT1oEp479Su70nWBB 9IIV8LiusVIOZELpSM1B31FczmR9GJMutn5vm3WC+g==
X-Google-Smtp-Source: APiQypL5T37a3+Gv/n56WwIndBc914WgoJn3KMy2v4MKMh8/OZ3VHFo+4D6L0nFQLrAgidHmclBT376d4MVymGSUf0U=
X-Received: by 2002:a2e:7a0b:: with SMTP id v11mr2039037ljc.120.1586274513716; Tue, 07 Apr 2020 08:48:33 -0700 (PDT)
MIME-Version: 1.0
References: <157955609351.1744.15099511006231348523.idtracker@ietfa.amsl.com> <417BE033-4DE5-452A-BE93-0657C83051BC@cisco.com> <CABcZeBPK3yAaoai4ccd=hSffk5cAhoSC7gnBNqs36x-xJf=R-Q@mail.gmail.com> <503E2696-AB4A-4020-90CC-802D312D23AF@sinodun.com> <CABcZeBOiEu8qO_VHtHc7Fs47Wh0tGDn3ywM5LDZtWoxuHZ_isw@mail.gmail.com> <721AD54C-0324-4400-8492-4AA19A64699D@sinodun.com> <CABcZeBP4CknS=9Y96CqgykChg4H_jrgkaWmHPN4319+nXe=10w@mail.gmail.com> <CAH1iCiobuYitR26Hh0pbYpA_JZoB1a1iMyHJs1FAgW9GtOk56g@mail.gmail.com> <CABcZeBNa-OTEYjnL=+-F=WK3hZiOWmty1S=FC43Fr3CxuCPE_g@mail.gmail.com> <32D26638-2464-4E7B-8869-C65F773EF5F2@sinodun.com> <CABcZeBNnAZ1ttKHdtZMwWZGvWAYn3jZBps+hXOBMHQXgaKPUEA@mail.gmail.com> <00AF0382-CD8B-46F3-9838-50602379FE9F@sinodun.com> <CABcZeBOELM=d0xXgYN+r4cNsRO6=oyQscdwwdSTqypV5gNra0A@mail.gmail.com> <F6C06842-9D76-45DF-84A0-B0C4D724E66E@sinodun.com> <CABcZeBPVocy593=WJM2k3Ytrwg36qc_1d4VQH3otRM5qyvZwLA@mail.gmail.com> <1388052392.1781.1586274052101@appsuite-gw1.open-xchange.com>
In-Reply-To: <1388052392.1781.1586274052101@appsuite-gw1.open-xchange.com>
From: Eric Rescorla <ekr@rtfm.com>
Date: Tue, 07 Apr 2020 08:47:57 -0700
Message-ID: <CABcZeBNi2LKvGFcmTM0uC+rFEVm5tgw6Zo1LS_CoO5=Zo0zqSA@mail.gmail.com>
To: Vittorio Bertola <vittorio.bertola@open-xchange.com>
Cc: Sara Dickinson <sara@sinodun.com>, "Eric Vyncke (evyncke)" <evyncke@cisco.com>, "draft-ietf-dprive-rfc7626-bis@ietf.org" <draft-ietf-dprive-rfc7626-bis@ietf.org>, "dns-privacy@ietf.org" <dns-privacy@ietf.org>, "dprive-chairs@ietf.org" <dprive-chairs@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000e8170205a2b550d7"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dns-privacy/tLnP8Mqc_D_bFaPBUy9q7fhgCWU>
Subject: Re: [dns-privacy] Datatracker State Update Notice: <draft-ietf-dprive-rfc7626-bis-04.txt>
X-BeenThere: dns-privacy@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <dns-privacy.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dns-privacy/>
List-Post: <mailto:dns-privacy@ietf.org>
List-Help: <mailto:dns-privacy-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 07 Apr 2020 15:48:37 -0000

On Tue, Apr 7, 2020 at 8:40 AM Vittorio Bertola <
vittorio.bertola@open-xchange.com> wrote:

>
> Il 07/04/2020 17:23 Eric Rescorla <ekr@rtfm.com> ha scritto:
>
>
>
> On Tue, Apr 7, 2020 at 7:38 AM Sara Dickinson < sara@sinodun.com> wrote:
>
> The goal of this text is to enumerate for the end user the privacy
> considerations of using such an application so I propose this text:
>
> "For users to have the ability to manage the application-specific DNS
> settings in a similar fashion to the OS DNS settings, each application also
> needs to expose the default settings to the user, provide a configuration
> interface to change them, and support configuration of user specified
> resolvers.
>
> If all of the applications used on a given device also provide a setting
> to use the system resolver, then the device can be reverted to a single
> point of control for all DNS queries. If not, then (depending on the
> application and transport used for DNS queries) users should take note that
> they may not be able to inspect all their DNS queries or manage them to set
> device wide controls e.g. domain based query re-direction or filtering. “
>
>
> I don't think this addresses my concern, because "revert" implies that
> this is somehow the default situation, which, as I said, is not clearly the
> case because applications have been doing their own resolution for some
> time.
>
> In the interest of moving forward, i suggest you change the term
> "reverted" to "configured" and add at the end "Note that this does not
> guarantee controlling malware name resolution as it can simply ignore
> whatever the system resolver and any user configuration settings.."
>
> I don't understand where in the proposed text there was a reference to
> malware that prompted further discussion of the effectiveness of using DNS
> to counter it. In any case, if we think that we need to discuss this topic
> at that point in the draft, one should also note that there also are ways
> to prevent malware from reaching a different resolver, though they are less
> likely to work once connections are encrypted, etc. But I think that this
> would make reaching consensus even harder, so perhaps we could avoid doing
> so and just focus on suggestions related to application configuration.
>

Well, I would be happy to strike this text entirely. However, the text
speaks of "control" and if we're going to say that, we should acknowledge
that the system DNS is not going to let you control malicious applications
because malware can just do its own resolution. As it is, I think the text
gives a false impression

-Ekr

-- 
>
> Vittorio Bertola | Head of Policy & Innovation, Open-Xchange
> vittorio.bertola@open-xchange.com
> Office @ Via Treviso 12, 10144 Torino, Italy
>
>