Re: [dnsext] Re: I-D ACTION:draft-vandergaast-edns-client-ip-00.txt

Marco Davids <marco.davids@sidn.nl> Fri, 29 January 2010 13:02 UTC

Return-Path: <owner-namedroppers@ops.ietf.org>
X-Original-To: ietfarch-dnsext-archive@core3.amsl.com
Delivered-To: ietfarch-dnsext-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 4D9D228C157; Fri, 29 Jan 2010 05:02:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -106.599
X-Spam-Level:
X-Spam-Status: No, score=-106.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EPH8IyqP3mJi; Fri, 29 Jan 2010 05:02:33 -0800 (PST)
Received: from psg.com (psg.com [147.28.0.62]) by core3.amsl.com (Postfix) with ESMTP id 4B68428B23E; Fri, 29 Jan 2010 05:02:33 -0800 (PST)
Received: from majordom by psg.com with local (Exim 4.71 (FreeBSD)) (envelope-from <owner-namedroppers@ops.ietf.org>) id 1NaqPw-00086L-11 for namedroppers-data0@psg.com; Fri, 29 Jan 2010 12:57:44 +0000
Received: from [94.198.152.69] (helo=ede1-kamx.sidn.nl) by psg.com with esmtps (TLSv1:AES256-SHA:256) (Exim 4.71 (FreeBSD)) (envelope-from <Marco.Davids@sidn.nl>) id 1NaqPi-00083x-4h for namedroppers@ops.ietf.org; Fri, 29 Jan 2010 12:57:30 +0000
Received: from sidn.nl ([192.168.2.12]) by ede1-kamx.sidn.nl with ESMTP id o0TCvRr2017804 for <namedroppers@ops.ietf.org>; Fri, 29 Jan 2010 13:57:27 +0100
Received: from [127.0.0.1] ([192.168.129.4]) by sidn.nl with Microsoft SMTPSVC(6.0.3790.3959); Fri, 29 Jan 2010 13:57:27 +0100
Message-ID: <4B62DB37.5030606@sidn.nl>
Date: Fri, 29 Jan 2010 13:57:27 +0100
From: Marco Davids <marco.davids@sidn.nl>
Organization: Stichting Internet Domeinregistratie Nederland
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; nl; rv:1.9.1.7) Gecko/20100111 Thunderbird/3.0.1
MIME-Version: 1.0
To: Florian Weimer <fweimer@bfk.de>
CC: Stephane Bortzmeyer <bortzmeyer@nic.fr>, namedroppers@ops.ietf.org
Subject: Re: [dnsext] Re: I-D ACTION:draft-vandergaast-edns-client-ip-00.txt
References: <7c31c8cc1001271556w4918093er6e94e07cb92c4dc4@mail.gmail.com> <6184.1264657589@nsa.vix.com> <20100129113254.GA32401@nic.fr> <827hr16r1s.fsf@mid.bfk.de>
In-Reply-To: <827hr16r1s.fsf@mid.bfk.de>
X-Enigmail-Version: 1.0
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-OriginalArrivalTime: 29 Jan 2010 12:57:27.0913 (UTC) FILETIME=[9C51A590:01CAA0E2]
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
List-ID: <namedroppers.ops.ietf.org>
List-Unsubscribe: To unsubscribe send a message to namedroppers-request@ops.ietf.org with
List-Unsubscribe: the word 'unsubscribe' in a single line as the message text body.
List-Archive: <http://ops.ietf.org/lists/namedroppers/>

Op 29-1-2010 13:20, schreef Florian Weimer:
> * Stephane Bortzmeyer:
> 
>> 2) A more ambitious one (may be too ambitious), to have an EDNS option
>> code "Client info", with sub-codes and various fields (and a registry
>> at IANA to register these fields) to carry absolutely everything from
>> the desktop client to the authoritative name server. IP address
>> information would then be just a special case.
> 
> I think this approach would be a lot better.  It's also inherently
> opt-in, which seems the best way to side-step privacy issues these
> days.
> 

+1

Sounds promising. Especially with opt-in functionality.

iPhone/Andoid with GPS might then indeed take you to the nearest
'pizza.restaurants.local'. Or even better: 'nearest.aed.local' in case
the pizza got stuck in your esophagus or something...

And I can think of a lot of other applications to bring new life to our
beloved friend DNS.

But... DNS-queries are not yet 'protected' with DNSSEC, right? A query
might be modified along the way. Resulting in useless answers...

So I also forsee another interesting 'attack vector'.

-- 
Marco Davids


SIDN | Utrechtseweg 310 | 6812 AR | Postbus 5022 | 6802 EA | ARNHEM
T +31 (0)26 352 55 83 | M +31 (0)6 52 37 34 35  | F +31 (0)26 352 55 05
marco.davids@sidn.nl | www.sidn.nl | enum:+31652373435 | sip:583@sidn.nl