Re: [dnsext] Re: Privacy vs EDNS Client IP...

bmanning@vacation.karoshi.com Thu, 04 February 2010 03:40 UTC

Return-Path: <owner-namedroppers@ops.ietf.org>
X-Original-To: ietfarch-dnsext-archive@core3.amsl.com
Delivered-To: ietfarch-dnsext-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 942223A6A4F; Wed, 3 Feb 2010 19:40:30 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.599
X-Spam-Level:
X-Spam-Status: No, score=-102.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZZfIdYr3Lv3L; Wed, 3 Feb 2010 19:40:29 -0800 (PST)
Received: from psg.com (psg.com [IPv6:2001:418:1::62]) by core3.amsl.com (Postfix) with ESMTP id A048D3A63D3; Wed, 3 Feb 2010 19:40:29 -0800 (PST)
Received: from majordom by psg.com with local (Exim 4.71 (FreeBSD)) (envelope-from <owner-namedroppers@ops.ietf.org>) id 1NcsVF-000EuX-4p for namedroppers-data0@psg.com; Thu, 04 Feb 2010 03:35:37 +0000
Received: from [2001:478:6:0:230:48ff:fe11:220a] (helo=vacation.karoshi.com) by psg.com with esmtps (TLSv1:AES256-SHA:256) (Exim 4.71 (FreeBSD)) (envelope-from <bmanning@karoshi.com>) id 1NcsV9-000Ejb-2d for namedroppers@ops.ietf.org; Thu, 04 Feb 2010 03:35:33 +0000
Received: from karoshi.com (localhost.localdomain [127.0.0.1]) by vacation.karoshi.com (8.12.8/8.12.8) with ESMTP id o143Xntv014064; Thu, 4 Feb 2010 03:33:49 GMT
Received: (from bmanning@localhost) by karoshi.com (8.12.8/8.12.8/Submit) id o143XgLq014063; Thu, 4 Feb 2010 03:33:42 GMT
Date: Thu, 04 Feb 2010 03:33:42 +0000
From: bmanning@vacation.karoshi.com
To: Wilmer van der Gaast <wilmer@google.com>
Cc: bmanning@vacation.karoshi.com, Nicholas Weaver <nweaver@icsi.berkeley.edu>, Ted Hardie <ted.ietf@gmail.com>, John Payne <john@sackheads.org>, Roy Arends <roy@nominet.org.uk>, namedroppers@ops.ietf.org
Subject: Re: [dnsext] Re: Privacy vs EDNS Client IP...
Message-ID: <20100204033342.GA13940@vacation.karoshi.com.>
References: <6e04e83a1002011109u1cd55c99k8b584648184cdc73@mail.gmail.com> <162E0DB1-EC86-4206-AB36-6FEFA786B24C@ICSI.Berkeley.EDU> <6e04e83a1002011402u395f599g74180d28fdbe5707@mail.gmail.com> <D8848FB8-3523-4580-A93F-764494531788@ICSI.Berkeley.EDU> <6e04e83a1002011640t1b637e30gd7d0150eeb0fae8d@mail.gmail.com> <E9A13A5C-73A7-4F66-9617-482551A9BA84@ICSI.Berkeley.EDU> <6e04e83a1002021155kcb908b1v71d362e03e7c4002@mail.gmail.com> <AB78D628-8A01-4742-B32A-90FC6806201E@ICSI.Berkeley.EDU> <20100203031042.GE1374@vacation.karoshi.com.> <7c31c8cc1002030135w183db140vd1c638bbdc999800@mail.gmail.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
In-Reply-To: <7c31c8cc1002030135w183db140vd1c638bbdc999800@mail.gmail.com>
User-Agent: Mutt/1.4.1i
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
List-ID: <namedroppers.ops.ietf.org>
List-Unsubscribe: To unsubscribe send a message to namedroppers-request@ops.ietf.org with
List-Unsubscribe: the word 'unsubscribe' in a single line as the message text body.
List-Archive: <http://ops.ietf.org/lists/namedroppers/>

On Wed, Feb 03, 2010 at 09:35:52AM +0000, Wilmer van der Gaast wrote:
> On 3 February 2010 03:10,  <bmanning@vacation.karoshi.com> wrote:
> >        hum... this leaps out.  being in a situation where your choice is:
> >
> >        a) leave the computer off and read a book
> >        or
> >        b) use the DHCP server in the hotel and get forced into using the DNS resolvers
> >           they hand you...  while never knowing if their resolvers have set the "ravish-me" bit.
> >
> How is the /24 of the (probably heavily NATted) external IP address of
> a hotel you're staying at possibly showing up in packets going to
> authorities a privacy concern?

	the privacy concern was releated tot he line you elided - the (in)ability
	to select a third party.  Some folks like using DNS resolvers/forwarders
	in the same fashion as some use TOR onion routers - as a way to preserve
	anonymity.  Not being able to chose your DNS resolution path is problematic.

--bill

> 
> 
> Wilmer.
> 
> -- 
> Wilmer van der Gaast, Dublin Traffic SRE.
> Google Ireland.