Re: [dns-privacy] Last Call: <draft-ietf-dprive-rfc7626-bis-03.txt> (DNS Privacy Considerations) to Informational RFC

Brian Haberman <brian@innovationslab.net> Thu, 23 January 2020 14:35 UTC

Return-Path: <brian@innovationslab.net>
X-Original-To: dns-privacy@ietfa.amsl.com
Delivered-To: dns-privacy@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A47A4120801 for <dns-privacy@ietfa.amsl.com>; Thu, 23 Jan 2020 06:35:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.437
X-Spam-Level: *
X-Spam-Status: No, score=1.437 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=innovationslab-net.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FpX9sTcBRjTi for <dns-privacy@ietfa.amsl.com>; Thu, 23 Jan 2020 06:35:04 -0800 (PST)
Received: from mail-qk1-x730.google.com (mail-qk1-x730.google.com [IPv6:2607:f8b0:4864:20::730]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5CF5A12029C for <dns-privacy@ietf.org>; Thu, 23 Jan 2020 06:35:04 -0800 (PST)
Received: by mail-qk1-x730.google.com with SMTP id x1so3545934qkl.12 for <dns-privacy@ietf.org>; Thu, 23 Jan 2020 06:35:04 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=innovationslab-net.20150623.gappssmtp.com; s=20150623; h=references:to:from:autocrypt:subject:message-id:date:user-agent :mime-version:in-reply-to; bh=kqBnyE9StI8z9ktVaPm5yV4UxYB80xIWIP6wsb5q6NM=; b=VeF5FA5vNos+jN+Xw1oUUx8D89fs1zIh3FnbbxzZdhbZlhjkBM6xQ5pdRYa1O+ODvs i0GaqP/QYT5oQ9zk7tb9+/qjMNxf+zpl+FLSuZ27sPbXJXmAAOD1PN1WrEGc5YqohM/d yttAb7ke7NJXZq+jEziPmYRZmdTZJ9gB/3cVrk7j7OB72fV/01rRhOJnybVE7j/xfXmP RrwFvSM60e+Kq1G58iy/1e6QZzNOcJ+Ejv0Mlt7eAveoyEqqwov/Z5H+IAetuTsO2E4+ XKVWVwjtZAwg6k1qoIxqhgdA2D05JQMIWTa9zUGFCkTcUMwdp3qzXhuVTB8FJHanVFJv QtbA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:references:to:from:autocrypt:subject:message-id :date:user-agent:mime-version:in-reply-to; bh=kqBnyE9StI8z9ktVaPm5yV4UxYB80xIWIP6wsb5q6NM=; b=Y1TyA2Tzz5sKkEAuQnJhRy99e9ddes8B09agBEg+n0VbktJ9kb/4UYfqdkb1uy6gEB 9x6sHNxZzRXlta86oNZD9RbB41v85wu9OCXuowNXZtd0omtxUXXcXaITt18ya5dR+6mC oFdWwgHWvBvp72U0ItrlHXAxPVWOhHro0S3oK80rnQ5Hc52IDfQPZUFyyYgF3f8v1OlA RzDv1EVXG48KE/Ky5/VMYm+/3eYypbhNOAB+42IhxWZtYD4dIwp7XosGFAOeA8edLiix A9JDgTC2iGNJdccYE4O8huXDts01nQw0fxBv90WTldK4jwHgAdMgNmMckRVz01wljVCE RP2g==
X-Gm-Message-State: APjAAAWrpKl2/7bptjeFxh/mo0A7wA2zJoOEDf9wUP25LSJXLJhG8XSi 4ZMzieAaVdix724vMo3EQC9sVvUae3w=
X-Google-Smtp-Source: APXvYqyUUAnNcv3cJm15BpESf7sbHYKyR10NMwi6PsMwU7/TlhnkCzGhhEsZEvk1D7JpZMZ+JwV2FQ==
X-Received: by 2002:a37:3d8:: with SMTP id 207mr15840824qkd.335.1579790103195; Thu, 23 Jan 2020 06:35:03 -0800 (PST)
Received: from clemson.local (nat-guest-wifi.jhuapl.edu. [128.244.87.232]) by smtp.gmail.com with ESMTPSA id u55sm1029491qtc.28.2020.01.23.06.35.01 for <dns-privacy@ietf.org> (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 23 Jan 2020 06:35:02 -0800 (PST)
References: <157412591286.14148.8912544206473080519.idtracker@ietfa.amsl.com> <6.2.5.6.2.20200101181705.081679d0@elandnews.com> <5C842DC4-0D89-4348-B810-9441F381B588@sinodun.com> <6.2.5.6.2.20200123054531.0be20578@elandnews.com>
To: DNS Privacy Working Group <dns-privacy@ietf.org>
From: Brian Haberman <brian@innovationslab.net>
Autocrypt: addr=brian@innovationslab.net; keydata= mQINBFm5KgYBEACs2icafejrG19L5DRNFq8Q2O+K+LRxjR4qAElZDnXFXNA2ipFWPeT0J2wa KJ+h9UdfhDm8DzULB553CYm+Q3XF1N56TglkIRMZYc7mYXZEr3x7e4fmX4kD4qMjBLG8cL26 rEe3Q0qaiMGY69/4o5coVMT0qmHjgCH1tkG+L2Y8MKr1gFxS18eO8MVoWe1yDKuyxFSElHGB 3mZn4gcqeCaemPGG3CiVNlp4KnijpNcSgvseXbkQEA4IXEsIvUL8MIwOTXg9Gh5cbtisZpuf +4B0LNMUSqWlqyKd9M3KCMj+dW4vsFytc00Z+GyQ+ArOR9GwTdAwJ5qqVODTvbjKqOR1zolJ 1JxLUtSiv7Lx5x2OrCexPYXkzlTkjG9Imtg2XNh55R/JKMC3KU1NQL3nS9tJXeoRWNgWSZrG MsrbeejbqLVb9LblXNpgLciJ96XHMvYAXX7p4LAwivzSRrVg46vErYIAV6EvDvwVENWW8JCU 0vX5iTGfkEwU4KxCa7WAmmD8yiNspHP1J0uk93Sta5K0PuTi7b+EZlCjdrqOEWLGPv6qXlIu FwLLcCaDs3XdVvwgNM+UFRxFH1aOVQQKCiCOCcNlwgYG1u4ZbD2T6hd/d2tOAKu/MNnQVF7d Cfi2BtSjzglLcY61e37zqTM04BgU+LniZ7V99yneM6DM2UzgkwARAQABtClCcmlhbiBIYWJl cm1hbiA8YnJpYW5AaW5ub3ZhdGlvbnNsYWIubmV0PokCQAQTAQoAKgIbAwUJB4YfgAULCQgH AwUVCgkICwUWAgMBAAIeAQIXgAUCWbkqSAIZAQAKCRBo1jycU9GLYQixD/9UX0uiAvbJ+4dK z3Ne3kUdDK0Lk73RGfFgE/ezsc9I6ED82h+arC8pAoDnBWgzTxugZdbexek983bgMq02XFsG pJf7hudeKnB8UmtjTc0j1UUgi129FYyBmINS2Lz1gpEOygFfbeOGLJK5qZJwD3I3O6yN8SUZ uwahXXd1aEB+d1eGhNqxkjQ+L7vdfTlN662GWog3ROMwUbrg0+QAbn/Vlp2iIYO6VERUZ9Yr GfFJX9b9LKa6AHxzAaqFIix1h2wBiIacpIBGU/4+3+wL5zkCbGSRzoIHW8srllj7ehgwwfNx QevibuZWJ4XpHpIxrtsmBO7ERFk8pN7oiQ9M3b2Cg9OBD5vgxyMCHEKIblWyKz8GLtz5357L ORU1EBWB8BoJPBHz3u7bZE+jH9+w5PpI087Ae78KCDkTNj7o2wbkRoYLmLpMo8DOwAumyy5R 2DuRu0cn5Rw5pFjlJkyfM0Wf80Ml/SINrUORWeqSbsHSX8i+Y0Oyt5JNo9NFbgN0Gn/Qo364 I8cLgbvUAyFHwhnmbHB+QXFCGAy73NOQ+g2fCRPeSbihhYa34ugfmd4oa6W2w805ixzM7iGr P+wDB1dhA7eHKVmoo9Kxvm9VzU+2homYGEROd/H6n0BMvWtp1oFh/JvEgZN6dVLg3p+XX5Zj Ggy568bIY4P5kP7pAxh017kCDQRZuSoGARAAtCWxW1cRne/iGbFuibvB8d3upcbCB7oz4LWk LSE20Db2ymn04ici9V+wBSWX57me5jQdwMi/gzVVZcupbzWTg5Yhv7Qt7CKORJLEKo6nULbb 4aEpdOXD9s7wwx+foFjzjtDOH/JYoB+OEe2oW39VmK6EsIx7ClsLf6+cih5yApZHtmV+2M3J YSxD2kCUE619ITFLAkMf203ap5vJ6DDaaKnVoNhF9qV7jlJEceGqHTBG4KkBX/zNCehMIfhr ViY/B2IWAHeuZ99lnCPx2mehGGa4XLjQauUkY9KB7dOq/ODyt+7SL0dfWrOVf3BnU3C308b4 9YdId8KI4dJ30nfXn6ifTK9STZHZE+Mt1sIVmtEguqMXEk/axZmT14x194c7ZPmU/uCQTE3U y1NFs4Yof50WF1ze0CyN2ycmqx11mHjP5+L23TqcdIWmJG+EtdHUAFpu42kbB0fML3Oc/cEU SmWK3WpF5YPljLM2gyh3RXjuiBnaGoJaKTOj5zXQ2G2l3/ijbn9FbqmFup+R352dxUyakXEP xNe3HdyjfyUcy/RJNeZz/lgUIhkxWQjOOU1RIN41RtCKcF9tJjMwgQvI51QmPvf90/6ab3I/ vwEpjlRb4AbuWfPWe89J+Z3TG97V9sntlMcQ6MGiPLbyFpiXIf2150e6FxZdJtipVwY2d/kA EQEAAYkCJQQYAQoADwUCWbkqBgIbDAUJB4YfgAAKCRBo1jycU9GLYfy0EACYrxb4nWtOnIu0 N7rXXo/0ZjaBTyUhJ6hzy2D7rt3vv/qj2ui+N21ui/yMDS928za/XRfP25qN9A1puioHqN4l SAsxwCC3mT9GJXVXVgivg3MeciqBXoOdnk1hUkP1CTKL3qZ9pSuw8bPlNE7+b1xF7Oce37YH +QRVmBXbGwTxtDTCZ9Js0/IpiUtg9QCfmryB1r/fD0TFb8b9aCBuVeKocWSuX9UXRt7zRGM8 BJwOLvdLdGvV8us1imlBKFLai4L8CPgihuc/s7ZB0r3pgW697hXScWhGHF3OUWbPFVkNyivM xtDcq+9ZlUMrxFbwUEABi8NFwvzwn+YJQqlrPiF4xxsScYpnIlfWEuP6Vpp6Z/u5x+1MNyZb oxNWWaevMVeo3tdRV9F6/YFqucw4JQ9HqlCKQ62sW9+e5SSlxGNlV4j9cchG6a4fAZqxL+pS ks+KitK3ap/R4RUG+nbjLlhCwGJIti8lxvdYAoPqjtwEUmMJv4dIl0/2h1495cwBIi7XeRKZ Rx38TV3G3LCx0J8dFhkyTG5TxUZQFgHjznkIX7bzeSQX72MxT0b/tc38yM71WpAgAY+MlHCT FQRKqIQsH/4MFir+g/oV2uPNGwmg0QEOnv9zZ79JJ/nBmuXC2RwUVTtZgtiZXhaP0afvR0eg WPEzptIZZCSmtBOOYkfsAw==
Message-ID: <8aeb86ef-f4f8-b532-5f87-47e35438a50a@innovationslab.net>
Date: Thu, 23 Jan 2020 09:35:01 -0500
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:68.0) Gecko/20100101 Thunderbird/68.3.1
MIME-Version: 1.0
In-Reply-To: <6.2.5.6.2.20200123054531.0be20578@elandnews.com>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="xdQXIPA1dv3FUNzfj0niGo34MvKzwKfmV"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dns-privacy/tr6ZNtxgScyDWwwyy3pUIpJxmY0>
Subject: Re: [dns-privacy] Last Call: <draft-ietf-dprive-rfc7626-bis-03.txt> (DNS Privacy Considerations) to Informational RFC
X-BeenThere: dns-privacy@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <dns-privacy.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dns-privacy/>
List-Post: <mailto:dns-privacy@ietf.org>
List-Help: <mailto:dns-privacy-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 23 Jan 2020 14:35:06 -0000

Hi SM,

On 1/23/20 9:11 AM, S Moonesamy wrote:
> Dear Sara,
> At 05:15 AM 23-01-2020, Sara Dickinson wrote:
>> > Section 3.2 discusses what a user does and use a DNS query related
>> to email as an example.  Is the MUA expected to validated the MX RR or
>> is it the role of the MSA?
>>
>> I think questions of validation are out of scope for this draft.
> 
> Apologies for not explaining this correctly.  The draft is described as
> a document about the use of DNS.  Section 3.2 has the following: "It
> gives information about what the user does ("What are the MX records of
> example.net?" means he probably wants to send email to someone at
> example.net ..."  My question was about that DNS query.  Could you or
> the WG Chairs please explain why the question which I asked is out of
> scope for this draft?
> 

I believe the text in question is:

   The QNAME is the full name sent by the user.  It gives information
   about what the user does ("What are the MX records of example.net?"
   means he probably wants to send email to someone at example.net,
   which may be a domain used by only a few persons and is therefore
   very revealing about communication relationships).

Given that the section is focused on the risk of the data included in
the DNS request, I interpret the above to be describing what privacy
risks exist by simply having the DNS payload be visible to observers. In
this case, an observer can see that a particular IP address is looking
up DNS info for a domain that may only be accessed by a small number people.

The document does not purport to explain how various
applications/services should/could perform any type of "validation" on
the returned information. I am also unclear on where the concept of
validation came out of that text.

Regards,
Brian