Re: [dnsext] Re: need new flag bit in EDNS, "do me no favours" (DMNF)

Andreas Gustafsson <gson@araneus.fi> Fri, 05 November 2010 11:46 UTC

Return-Path: <owner-namedroppers@ops.ietf.org>
X-Original-To: ietfarch-dnsext-archive@core3.amsl.com
Delivered-To: ietfarch-dnsext-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 60D903A68AD; Fri, 5 Nov 2010 04:46:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.11
X-Spam-Level:
X-Spam-Status: No, score=-1.11 tagged_above=-999 required=5 tests=[BAYES_05=-1.11]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OaDXe83kDG1P; Fri, 5 Nov 2010 04:46:44 -0700 (PDT)
Received: from psg.com (psg.com [IPv6:2001:418:1::62]) by core3.amsl.com (Postfix) with ESMTP id 83D7F3A688C; Fri, 5 Nov 2010 04:46:44 -0700 (PDT)
Received: from majordom by psg.com with local (Exim 4.72 (FreeBSD)) (envelope-from <owner-namedroppers@ops.ietf.org>) id 1PEKgi-0002Xl-KG for namedroppers-data0@psg.com; Fri, 05 Nov 2010 11:42:32 +0000
Received: from gusev.araneus.fi ([83.145.227.89]) by psg.com with esmtp (Exim 4.72 (FreeBSD)) (envelope-from <gson@araneus.fi>) id 1PEKgg-0002X6-2A for namedroppers@ops.ietf.org; Fri, 05 Nov 2010 11:42:30 +0000
Received: from guava.gson.org (guava.gson.org [83.145.227.105]) by gusev.araneus.fi (Postfix) with ESMTP id 5830592578; Fri, 5 Nov 2010 13:42:27 +0200 (EET)
Received: by guava.gson.org (Postfix, from userid 101) id DA44275E94; Fri, 5 Nov 2010 13:42:26 +0200 (EET)
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Message-ID: <19667.60834.801609.327061@guava.gson.org>
Date: Fri, 05 Nov 2010 13:42:26 +0200
To: Florian Weimer <fweimer@bfk.de>
Cc: IETF DNSEXT WG <namedroppers@ops.ietf.org>
Subject: Re: [dnsext] Re: need new flag bit in EDNS, "do me no favours" (DMNF)
In-Reply-To: <8262wcm5mr.fsf@mid.bfk.de>
References: <59023.1287939121@nsa.vix.com> <20101025094523.GA5187@nic.fr> <41281.1288025835@nsa.vix.com> <20101025233215.4A495606495@drugs.dv.isc.org> <72674.1288058394@nsa.vix.com> <AANLkTimwXkUrYHveahqTMZe=V8zu8LG1MJ3HtQEZAoDW@mail.gmail.com> <78766.1288064363@nsa.vix.com> <8262wcm5mr.fsf@mid.bfk.de>
X-Mailer: VM 8.0.14 under 21.4.1 (i386--netbsdelf)
From: Andreas Gustafsson <gson@araneus.fi>
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
List-ID: <namedroppers.ops.ietf.org>
List-Unsubscribe: To unsubscribe send a message to namedroppers-request@ops.ietf.org with
List-Unsubscribe: the word 'unsubscribe' in a single line as the message text body.
List-Archive: <http://ops.ietf.org/lists/namedroppers/>

Florian Weimer wrote:
> Redirection to search seems important because most users do not care
> about the difference between DNS-based and search-engine-based
> lookups.

Indeed - important enough that at least one browser is taking
defensive measures to ensure that this redirection to search
is not broken by NXDOMAIN spoofing:

  http://groups.google.com/a/chromium.org/group/chromium-discuss/msg/5891e258e6015fc5

-- 
Andreas Gustafsson, gson@araneus.fi