[dnsext] Re: I-D ACTION:draft-vandergaast-edns-client-ip-00.txt

Stephane Bortzmeyer <bortzmeyer@nic.fr> Mon, 01 February 2010 15:22 UTC

Return-Path: <owner-namedroppers@ops.ietf.org>
X-Original-To: ietfarch-dnsext-archive@core3.amsl.com
Delivered-To: ietfarch-dnsext-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id A8AD63A6959; Mon, 1 Feb 2010 07:22:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -106.237
X-Spam-Level:
X-Spam-Status: No, score=-106.237 tagged_above=-999 required=5 tests=[AWL=0.012, BAYES_00=-2.599, HELO_EQ_FR=0.35, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id svCWjvu6Zg84; Mon, 1 Feb 2010 07:22:57 -0800 (PST)
Received: from psg.com (psg.com [147.28.0.62]) by core3.amsl.com (Postfix) with ESMTP id DAE983A688B; Mon, 1 Feb 2010 07:22:57 -0800 (PST)
Received: from majordom by psg.com with local (Exim 4.71 (FreeBSD)) (envelope-from <owner-namedroppers@ops.ietf.org>) id 1Nby1q-000HTh-Al for namedroppers-data0@psg.com; Mon, 01 Feb 2010 15:17:30 +0000
Received: from [2001:660:3003:2::4:11] (helo=mx2.nic.fr) by psg.com with esmtp (Exim 4.71 (FreeBSD)) (envelope-from <bortzmeyer@nic.fr>) id 1Nby1j-000HS8-K7 for namedroppers@ops.ietf.org; Mon, 01 Feb 2010 15:17:23 +0000
Received: from mx2.nic.fr (localhost [127.0.0.1]) by mx2.nic.fr (Postfix) with SMTP id 08A561C018D; Mon, 1 Feb 2010 16:17:22 +0100 (CET)
Received: from relay1.nic.fr (relay1.nic.fr [192.134.4.162]) by mx2.nic.fr (Postfix) with ESMTP id 03EB81C0180; Mon, 1 Feb 2010 16:17:22 +0100 (CET)
Received: from bortzmeyer.nic.fr (batilda.nic.fr [192.134.4.69]) by relay1.nic.fr (Postfix) with ESMTP id 01891A1D9A8; Mon, 1 Feb 2010 16:17:22 +0100 (CET)
Date: Mon, 01 Feb 2010 16:17:21 +0100
From: Stephane Bortzmeyer <bortzmeyer@nic.fr>
To: Martin Barry <marty@supine.com>
Cc: namedroppers@ops.ietf.org
Subject: [dnsext] Re: I-D ACTION:draft-vandergaast-edns-client-ip-00.txt
Message-ID: <20100201151721.GA25870@nic.fr>
References: <7c31c8cc1001271556w4918093er6e94e07cb92c4dc4@mail.gmail.com> <6e04e83a1001281107r470b104dj5d3b66919ce69977@mail.gmail.com> <7c31c8cc1001281125l2605b5d0tc528abdb2d35a48@mail.gmail.com> <6e04e83a1001281155y8961ddfy763d4f79d5d45c3f@mail.gmail.com> <4C393F4E-4DAF-4514-ACE4-E0DBB8C63B34@icsi.berkeley.edu> <4B66E625.2070708@nic.cz> <20100201145746.GA29691@tigger.mamista.net>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <20100201145746.GA29691@tigger.mamista.net>
X-Operating-System: Debian GNU/Linux 5.0.3
X-Kernel: Linux 2.6.26-2-686 i686
Organization: NIC France
X-URL: http://www.nic.fr/
User-Agent: Mutt/1.5.18 (2008-05-17)
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
List-ID: <namedroppers.ops.ietf.org>
List-Unsubscribe: To unsubscribe send a message to namedroppers-request@ops.ietf.org with
List-Unsubscribe: the word 'unsubscribe' in a single line as the message text body.
List-Archive: <http://ops.ietf.org/lists/namedroppers/>

On Tue, Feb 02, 2010 at 01:57:46AM +1100,
 Martin Barry <marty@supine.com> wrote 
 a message of 24 lines which said:

> I'm not sure I understand this concern. 

Then you did not read the whole thread:

From: Stephane Bortzmeyer <bortzmeyer@nic.fr>
To: Alex Bligh <alex@alex.org.uk>
Cc: namedroppers@ops.ietf.org
Date: Fri, 29 Jan 2010 12:38:13 +0100


This would lose a lot of privacy since the IP address of the "desktop"
client would be transmitted in full, not only to the HTTP server but
also to middlemen, the authoritative servers of the root, the TLD,
etc.

The draft has a provision for this (section 4.1) but it is just a MAY
and does not blend well with the general zone cut rules.

Also, the HTTP request may be through a proxy, too, so you cannot even
say that the HTTP server would know the address.