Re: [dns-privacy] [DNSOP] [Doh] New: draft-bertola-bcp-doh-clients

Christian Huitema <huitema@huitema.net> Wed, 13 March 2019 19:18 UTC

Return-Path: <huitema@huitema.net>
X-Original-To: dns-privacy@ietfa.amsl.com
Delivered-To: dns-privacy@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4B57D128AFB for <dns-privacy@ietfa.amsl.com>; Wed, 13 Mar 2019 12:18:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vhf8FKG-R96r for <dns-privacy@ietfa.amsl.com>; Wed, 13 Mar 2019 12:18:28 -0700 (PDT)
Received: from mx36-out10.antispamcloud.com (mx36-out10.antispamcloud.com [209.126.121.30]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E6C7F130EE6 for <dns-privacy@ietf.org>; Wed, 13 Mar 2019 12:18:25 -0700 (PDT)
Received: from xsmtp05.mail2web.com ([168.144.250.245]) by mx120.antispamcloud.com with esmtps (TLSv1:AES256-SHA:256) (Exim 4.89) (envelope-from <huitema@huitema.net>) id 1h49OS-000WVD-8c for dns-privacy@ietf.org; Wed, 13 Mar 2019 20:18:25 +0100
Received: from [10.5.2.12] (helo=xmail02.myhosting.com) by xsmtp05.mail2web.com with esmtps (TLS-1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.63) (envelope-from <huitema@huitema.net>) id 1h49OM-0005ii-3K for dns-privacy@ietf.org; Wed, 13 Mar 2019 15:18:22 -0400
Received: (qmail 32445 invoked from network); 13 Mar 2019 19:18:17 -0000
Received: from unknown (HELO [192.168.1.103]) (Authenticated-user:_huitema@huitema.net@[172.56.42.166]) (envelope-sender <huitema@huitema.net>) by xmail02.myhosting.com (qmail-ldap-1.03) with ESMTPA for <dnsop@ietf.org>; 13 Mar 2019 19:18:16 -0000
To: "Livingood, Jason" <Jason_Livingood@comcast.com>
Cc: "dns-privacy@ietf.org" <dns-privacy@ietf.org>, "doh@ietf.org" <doh@ietf.org>, "dnsop@ietf.org" <dnsop@ietf.org>
References: <1700920918.12557.1552229700654@appsuite.open-xchange.com> <76386691-c1aa-c48a-9b0d-67eb36a08a4f@redbarn.org> <CABcZeBOWM0Ps-j3V-CK6VPy0LAqeo7-t7odUZy+dk9d-oCSDsg@mail.gmail.com> <4935758.NkxX2Kjbm0@linux-9daj> <c2c2be47-0855-a9d1-dd53-2404edf4d02b@huitema.net> <807193999.19916.1552445819087@appsuite.open-xchange.com> <9e40ac38-fa10-bbdc-1bfc-302e0ca170df@huitema.net> <C72A7196-98CF-40DC-84C7-DA95BADD24B8@cable.comcast.com>
From: Christian Huitema <huitema@huitema.net>
Openpgp: preference=signencrypt
Autocrypt: addr=huitema@huitema.net; prefer-encrypt=mutual; keydata= mQENBFIRX8gBCAC26usy/Ya38IqaLBSu33vKD6hP5Yw390XsWLaAZTeQR64OJEkoOdXpvcOS HWfMIlD5s5+oHfLe8jjmErFAXYJ8yytPj1fD2OdSKAe1TccUBiOXT8wdVxSr5d0alExVv/LO I/vA2aU1TwOkVHKSapD7j8/HZBrqIWRrXUSj2f5n9tY2nJzG9KRzSG0giaJWBfUFiGb4lvsy IaCaIU0YpfkDDk6PtK5YYzuCeF0B+O7N9LhDu/foUUc4MNq4K3EKDPb2FL1Hrv0XHpkXeMRZ olpH8SUFUJbmi+zYRuUgcXgMZRmZFL1tu6z9h6gY4/KPyF9aYot6zG28Qk/BFQRtj7V1ABEB AAG0J0NocmlzdGlhbiBIdWl0ZW1hIDxodWl0ZW1hQGh1aXRlbWEubmV0PokBOQQTAQIAIwUC UhFfyAIbLwcLCQgHAwIBBhUIAgkKCwQWAgMBAh4BAheAAAoJEJNDCbJVyA1yhbYH/1ud6x6m VqGIp0JcZUfSQO8w+TjugqxCyGNn+w/6Qb5O/xENxNQ4HaMQ5uSRK9n8WKKDDRSzwZ4syKKf wbkfj05vgFxrjCynVbm1zs2X2aGXh+PxPL/WHUaxzEP7KjYbLtCUZDRzOOrm+0LMktngT/k3 6+EZoLEM52hwwpIAzJoscyEz7QfqMOZtFm6xQnlvDQeIrHx0KUvwo/vgDLK3SuruG1CSHcR0 D24kEEUa044AIUKBS3b0b8AR7f6mP2NcnLpdsibtpabi9BzqAidcY/EjTaoea46HXALk/eJd 6OLkLE6UQe1PPzQC4jB7rErX2BxnSkHDw50xMgLRcl5/b1a5AQ0EUhFfyAEIAKp7Cp8lqKTV CC9QiAf6QTIjW+lie5J44Ad++0k8gRgANZVWubQuCQ71gxDWLtxYfFkEXjG4TXV/MUtnOliG 5rc2E+ih6Dg61Y5PQakm9OwPIsOx+2R+iSW325ngln2UQrVPgloO83QiUoi7mBJPbcHlxkhZ bd3+EjFxSLIQogt29sTcg2oSh4oljUpz5niTt69IOfZx21kf29NfDE+Iw56gfrxI2ywZbu5o G+d0ZSp0lsovygpk4jK04fDTq0vxjEU5HjPcsXC4CSZdq5E2DrF4nOh1UHkHzeaXdYR2Bn1Y wTePfaHBFlvQzI+Li/Q6AD/uxbTM0vIcsUxrv3MNHCUAEQEAAYkCPgQYAQIACQUCUhFfyAIb LgEpCRCTQwmyVcgNcsBdIAQZAQIABgUCUhFfyAAKCRC22tOSFDh1UOlBB/94RsCJepNvmi/c YiNmMnm0mKb6vjv43OsHkqrrCqJSfo95KHyl5Up4JEp8tiJMyYT2mp4IsirZHxz/5lqkw9Az tcGAF3GlFsj++xTyD07DXlNeddwTKlqPRi/b8sppjtWur6Pm+wnAHp0mQ7GidhxHccFCl65w uT7S/ocb1MjrTgnAMiz+x87d48n1UJ7yIdI41Wpg2XFZiA9xPBiDuuoPwFj14/nK0elV5Dvq 4/HVgfurb4+fd74PV/CC/dmd7hg0ZRlgnB5rFUcFO7ywb7/TvICIIaLWcI42OJDSZjZ/MAzz BeXm263lHh+kFxkh2LxEHnQGHCHGpTYyi4Z3dv03HtkH/1SI8joQMQq00Bv+RdEbJXfEExrT u4gtdZAihwvy97OPA2nCdTAHm/phkzryMeOaOztI4PS8u2Ce5lUB6P/HcGtK/038KdX5MYST Fn8KUDt4o29bkv0CUXwDzS3oTzPNtGdryBkRMc9b+yn9+AdwFEH4auhiTQXPMnl0+G3nhKr7 jvzVFJCRif3OAhEm4vmBNDE3uuaXFQnbK56GJrnqVN+KX5Z3M7X3fA8UcVCGOEHXRP/aubiw Ngawj0V9x+43kUapFp+nF69R53UI65YtJ95ec4PTO/Edvap8h1UbdEOc4+TiYwY1TBuIKltY 1cnrjgAWUh/Ucvr++/KbD9tD6C8=
Message-ID: <b52e7891-da9f-6972-fc42-bf3aeea0a10f@huitema.net>
Date: Wed, 13 Mar 2019 12:18:17 -0700
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:60.0) Gecko/20100101 Thunderbird/60.5.3
MIME-Version: 1.0
In-Reply-To: <C72A7196-98CF-40DC-84C7-DA95BADD24B8@cable.comcast.com>
Content-Type: multipart/alternative; boundary="------------67D03749B66F24A949D9AE15"
Content-Language: en-US
X-Originating-IP: 168.144.250.245
X-Spampanel-Domain: xsmtpout.mail2web.com
X-Spampanel-Username: 168.144.250.0/24
Authentication-Results: antispamcloud.com; auth=pass smtp.auth=168.144.250.0/24@xsmtpout.mail2web.com
X-Spampanel-Outgoing-Class: unsure
X-Spampanel-Outgoing-Evidence: Combined (0.18)
X-Recommended-Action: accept
X-Filter-ID: EX5BVjFpneJeBchSMxfU5pTTN8PgWDqTDEcWeZII/NF602E9L7XzfQH6nu9C/Fh9KJzpNe6xgvOx q3u0UDjvO0M1y7GhFqFbn9vtlWAr1mJsHgxiuwQbOUzhOZq2mlTVyE/gTaK2cmPQHuTv1n43nlpr jQPFk8m4tSTfORUp3ynEm+h0A2koB3qKN5bbUQlCA8n4I1VTPCCkocApr/h8ypFVgpT1b21uZVck Gp0ccOYNj3IsPxUoOvqBoVWc32LibjGdSRNeAsqwADJIlioxB+Ri1Gwjhmdwj/RC7BTJQIETmEFB zGJ4I3iI+cUBLpxHZqMsFXHkY4b0tMjYHlbEsVUR7komHinqJ9ie4Zp7sD61uaPSJwE5NDmBcvCQ 7WXhlOFLt8X6SDUJLm68sooWCjjvhxRy8c+nflOBK9anR8rhYqKMUAYnLVUObpdhqXEkVDMv1b5a 3y9lGk6Ly6eKprQOZqSwHQbKW7LKNYtkeUHTo9En0RQoZi/HX1Q44zhPDAt+ygPihlE/dMSsshhD WXtzJzDXtW19p+oSJq/sPNTtv2aJZQXcqeLlo9ZlOwRP3cjWjdZTNpJcOy3iewwYtAqZpqqBz8B0 bbNcFDlP4+f79hMBTMgoQOF0lAMSbHYtKx3Zprq3ZEpafGy+zLjUnkMiCusAUxIiAEXecszeEC63 QM22Wm73+PngL70p9A+Wd9pNR0Pp7mNmweApkyj+L4kfxnHypUV0eLjDnV4DMpuq613YX/Jpkaqf AljBKlD3+pZosIiKP9kEfhX9UPNRfnRGXyWPpKrCkv+3/fyHcyMWxVzw6JTxlEBcF0wHBO63leuU RqSnB2jnQBhMjuGnrP1bzG3zUTlzWaSe575jTPRZ3Wp92Kw4yIvr1Y+C5LXE/WRbdco3pKNX9x7s 84ASznZ1QGFtCCvu9wtWu8FpV7t85WDgADyx2vqgF4gItj3R8t3Xj/LzZ5s/OJg1L2asZ5I2ODNr J0shvKoIDg9/v5hit+Tbitbng8tMN6ZfSvO2wujQhRtrC8jEKaisMWlfmA==
X-Report-Abuse-To: spam@quarantine9.antispamcloud.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/dns-privacy/u3ey70dBvDj4n14kaf-uV47bMqs>
Subject: Re: [dns-privacy] [DNSOP] [Doh] New: draft-bertola-bcp-doh-clients
X-BeenThere: dns-privacy@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <dns-privacy.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dns-privacy/>
List-Post: <mailto:dns-privacy@ietf.org>
List-Help: <mailto:dns-privacy-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Mar 2019 19:18:30 -0000

On 3/13/2019 9:56 AM, Livingood, Jason wrote:
> On 3/12/19, 11:40 PM, "Doh on behalf of Christian Huitema" <doh-bounces@ietf.org on behalf of huitema@huitema.net> wrote:
>
>> Why do you think you can filter content? Who made you king?
> [JL] End users may have opted into / subscribed to such a parental control system. An enterprise may say we'll only connect to the Internet and allow traffic of X or Y type in/out for security reasons. And a primary school may be legally required to filter out adult content in exchange for a government grant to fund their network/computers/connectivity. There are many more examples that can be considered.


Take the example of end users who may have opted in a parental control
system. Some may have, and some may not have. If we want a productive
conversation, we need to start from scenarios like that. If an end user
has opted in a specific parental control system, then applications
performing their own name resolution should follow the end user
preference, and it would be nice to have a management interface exposing
that. But then, if the user has not opted in such system, it would be
nice if the ISP refrained from interfering with name resolution for that
user. How do we achieve those two goals in practice?

-- Christian Huitema