Re: [DNSOP] Review of draft-livingood-dns-redirect-00

Jim Reid <jim@rfc1035.com> Fri, 17 July 2009 10:10 UTC

Return-Path: <jim@rfc1035.com>
X-Original-To: dnsop@core3.amsl.com
Delivered-To: dnsop@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id ADFF73A69E8 for <dnsop@core3.amsl.com>; Fri, 17 Jul 2009 03:10:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.603
X-Spam-Level:
X-Spam-Status: No, score=-1.603 tagged_above=-999 required=5 tests=[AWL=0.996, BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id onSehIoW+ZXh for <dnsop@core3.amsl.com>; Fri, 17 Jul 2009 03:10:01 -0700 (PDT)
Received: from hutch.rfc1035.com (hutch.rfc1035.com [195.54.233.70]) by core3.amsl.com (Postfix) with ESMTP id 0D0F33A659B for <dnsop@ietf.org>; Fri, 17 Jul 2009 03:10:01 -0700 (PDT)
Received: from gromit.rfc1035.com (gromit.rfc1035.com [195.54.233.69]) by hutch.rfc1035.com (Postfix) with ESMTP id 6E7DB2071C; Fri, 17 Jul 2009 11:10:29 +0100 (BST)
Message-Id: <05300B40-6F6B-4748-A594-B78FB895572E@rfc1035.com>
From: Jim Reid <jim@rfc1035.com>
To: Andreas Gustafsson <gson@araneus.fi>
In-Reply-To: <19040.16522.807363.932474@guava.gson.org>
Content-Type: text/plain; charset="US-ASCII"; format="flowed"; delsp="yes"
Content-Transfer-Encoding: 7bit
Mime-Version: 1.0 (Apple Message framework v935.3)
Date: Fri, 17 Jul 2009 11:10:28 +0100
References: <19038.59859.828808.448502@guava.gson.org> <C6849631.EF40%Jason_Livingood@cable.comcast.com> <19040.16522.807363.932474@guava.gson.org>
X-Mailer: Apple Mail (2.935.3)
Cc: dnsop@ietf.org, "Livingood, Jason" <Jason_Livingood@cable.comcast.com>
Subject: Re: [DNSOP] Review of draft-livingood-dns-redirect-00
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 17 Jul 2009 10:10:06 -0000

On 17 Jul 2009, at 10:12, Andreas Gustafsson wrote:

> But to give one concrete example, DNS-based blacklists and whitelists
> will be impacted as they rely on NXDOMAIN responses to indicate that
> an address or name is not listed.

To give another, Internet Explorer uses NXDOMAIN responses to do a  
google search of what was in the browser bar and display the results  
of that search IIUC. This is equally as evil IMO as doing DNS  
redirection and sending the user to some ISP-supplied landing page.  
There's no need to explore this rat-hole. so please don't. The point  
here is that DNS redirection breaks the default, expected behaviour of  
a very commonly used application because the browser no longer sees  
NXDOMAIN.