Re: [DNSOP] How Slack didn't turn on DNSSEC

Mark Andrews <marka@isc.org> Wed, 01 December 2021 15:41 UTC

Return-Path: <marka@isc.org>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8FAA23A0808 for <dnsop@ietfa.amsl.com>; Wed, 1 Dec 2021 07:41:06 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=isc.org header.b=BLzW5Ba9; dkim=pass (1024-bit key) header.d=isc.org header.b=PU+MmIGB
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vXu-AO29lSh0 for <dnsop@ietfa.amsl.com>; Wed, 1 Dec 2021 07:41:01 -0800 (PST)
Received: from mx.pao1.isc.org (mx.pao1.isc.org [149.20.64.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 480A03A0812 for <dnsop@ietf.org>; Wed, 1 Dec 2021 07:41:01 -0800 (PST)
Received: from zimbrang.isc.org (zimbrang.isc.org [149.20.1.12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx.pao1.isc.org (Postfix) with ESMTPS id 16BE6433F01; Wed, 1 Dec 2021 15:41:00 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=isc.org; s=ostpay; t=1638373260; bh=m5WyPF5mzrEHqNG6aNi2cK4H7GBLXnOEomwMnjbo/6c=; h=Subject:From:In-Reply-To:Date:Cc:References:To; b=BLzW5Ba91v4Kg1COR1ybpEo9Qts/ThKUT4gLTvrSLev/JFtgTGvR3jEGiG59KYgx0 5Ub5Ez+jKehCvXtmqdL5omyx2wLM5BL3wh6yAnax3Ml/v6/5F9zrB/o8jI05f0jjE7 tjjErRPjjcfNynHpD25INgYnJ0yn+gADFWEBFtuc=
Received: from zimbrang.isc.org (localhost.localdomain [127.0.0.1]) by zimbrang.isc.org (Postfix) with ESMTPS id 0D864F25B45; Wed, 1 Dec 2021 15:41:00 +0000 (UTC)
Received: from localhost (localhost.localdomain [127.0.0.1]) by zimbrang.isc.org (Postfix) with ESMTP id D6B36F25B4B; Wed, 1 Dec 2021 15:40:59 +0000 (UTC)
DKIM-Filter: OpenDKIM Filter v2.10.3 zimbrang.isc.org D6B36F25B4B
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=isc.org; s=05DFB016-56A2-11EB-AEC0-15368D323330; t=1638373259; bh=oNdRAnkVJJf8LjS5ZMG2jp8OJrBvDAx1O8oNuwOd39M=; h=Mime-Version:From:Date:Message-Id:To; b=PU+MmIGBVv2QymXJ6SF0cJY5tKMP2TmqgQPaU5zkhuLulQYk47Hm4U/NsDzcoUxr0 g7zB2fSyMa08IStXGlWE8uhWuNb2cO8ZdPpZSh/+9Lclj81VKosJU8Mi0QK/sCROFf pNc3C4n7AXi/R097qH5lFVGn2qX57vOAmxl49VJk=
Received: from zimbrang.isc.org ([127.0.0.1]) by localhost (zimbrang.isc.org [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id zornxx9s-RFQ; Wed, 1 Dec 2021 15:40:59 +0000 (UTC)
Received: from smtpclient.apple (n114-74-30-70.bla4.nsw.optusnet.com.au [114.74.30.70]) by zimbrang.isc.org (Postfix) with ESMTPSA id 37AA2F25B45; Wed, 1 Dec 2021 15:40:59 +0000 (UTC)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 14.0 \(3654.120.0.1.13\))
From: Mark Andrews <marka@isc.org>
In-Reply-To: <840356c1-fcb5-7043-595b-0719bce8428e@nic.cz>
Date: Thu, 02 Dec 2021 02:40:56 +1100
Cc: dnsop@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <A5EBCA50-7A25-47A2-8A24-38AC2FA3C337@isc.org>
References: <m1msK9b-0000HrC@stereo.hq.phicoh.net> <C3D5AC3A-CA5A-4F33-8BDA-DDFADD23649C@isc.org> <5f987ab1-c28a-b169-becf-1c44bdac60f4@nic.cz> <B12FC011-582F-46BC-BDEC-23AB45D33932@isc.org> <7b446404-65ec-99b8-7485-3b4b7204ebb7@nic.cz> <A38653D4-AEF0-4381-A924-80DF9E28D9E6@isc.org> <840356c1-fcb5-7043-595b-0719bce8428e@nic.cz>
To: Vladimír Čunát <vladimir.cunat+ietf@nic.cz>
X-Mailer: Apple Mail (2.3654.120.0.1.13)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/1DK4OPA6iOfUIfHMusofLQLCl84>
Subject: Re: [DNSOP] How Slack didn't turn on DNSSEC
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 01 Dec 2021 15:41:07 -0000


> On 2 Dec 2021, at 01:57, Vladimír Čunát <vladimir.cunat+ietf@nic.cz> wrote:
> 
> On 01/12/2021 15.49, Mark Andrews wrote:
>> Black lies is “QNAME NSEC \000.QNAME NSEC RRSIG”.  There is no churn for "black lies”.  Black lies turns NXDOMAIN into NODATA.
>> 
>> "DNS Shotgun" can produce churn of NSEC if you ask for a type that is listed as existing but it doesn’t actually exist.  The NSEC returned is still valid for DNSSEC synthesis.
> 
> Oh, I'm sorry; a terminological problem.  I used "black-lies" for the overall behavior of Cloudflare auths, as described in that blog article.  Maybe we could extend the current terminology draft :-D
> 
> (Nit: about random QTYPE attacks, I can't see a point when you leave random QNAME attacks undefended.)

Dropping them also sets a bad precedent as one then has to deal with “but foobar works with the bad type map” complaints.
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742              INTERNET: marka@isc.org