Re: [DNSOP] New Version Notification for draft-bortzmeyer-dname-root-02.txt
Shane Kerr <shane@time-travellers.org> Fri, 29 April 2016 14:31 UTC
Return-Path: <shane@time-travellers.org>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 29F1E12D180 for <dnsop@ietfa.amsl.com>; Fri, 29 Apr 2016 07:31:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9YJofyCZtdfy for <dnsop@ietfa.amsl.com>; Fri, 29 Apr 2016 07:31:21 -0700 (PDT)
Received: from time-travellers.nl.eu.org (c.time-travellers.nl.eu.org [IPv6:2a02:2770::21a:4aff:fea3:eeaa]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A573612D157 for <dnsop@ietf.org>; Fri, 29 Apr 2016 07:31:21 -0700 (PDT)
Received: from [2001:470:78c8:2:224:9bff:fe13:3a9c] (helo=pallas.home.time-travellers.org) by time-travellers.nl.eu.org with esmtpsa (TLS1.2:RSA_AES_128_CBC_SHA1:128) (Exim 4.80) (envelope-from <shane@time-travellers.org>) id 1aw9Rt-0005x1-SH; Fri, 29 Apr 2016 14:31:17 +0000
Date: Fri, 29 Apr 2016 16:31:15 +0200
From: Shane Kerr <shane@time-travellers.org>
To: Stephane Bortzmeyer <bortzmeyer+ietf@nic.fr>
Message-ID: <20160429163115.797f4b84@pallas.home.time-travellers.org>
In-Reply-To: <20160429135727.GB314@nic.fr>
References: <20160429135727.GB314@nic.fr>
X-Mailer: Claws Mail 3.13.2 (GTK+ 2.24.30; x86_64-pc-linux-gnu)
MIME-Version: 1.0
Content-Type: multipart/signed; micalg="pgp-sha1"; boundary="Sig_/mdddn=HTYmNs0AlRVdcL=za"; protocol="application/pgp-signature"
Archived-At: <http://mailarchive.ietf.org/arch/msg/dnsop/9SMSgU2P84dWjqzfquqdkufh7oQ>
Cc: dnsop@ietf.org
Subject: Re: [DNSOP] New Version Notification for draft-bortzmeyer-dname-root-02.txt
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 29 Apr 2016 14:31:24 -0000
Stephane, At 2016-04-29 15:57:27 +0200 Stephane Bortzmeyer <bortzmeyer+ietf@nic.fr> wrote: > No objection from the AS112 operators was received. Now, what do you > think of this draft? Should we continue or is it a bad idea (or a good > one, but hopeless?) I think I said this in person but I don't know if I ever wrote it down. I think that there may be some decreased privacy since queries for these zones are going to be sent to basically anonymous servers instead of root servers. Certainly for something like .ONION this is less desirable. OTOH, anyone using such a zone faces operator error causing such leaks in any case. Indeed having these queries show up at the root is also the result of DNS administrator misconfiguration. Also, any attacker interested in looking at such queries has alternate ways of seeing such traffic even today (via BGP tricks at least). The actual extra leakage is minimal. If the proposal does go forward (I really have no feeling whether it is useful or not), then perhaps this can be mentioned in the "Possible issues" section? Cheers, -- Shane
- [DNSOP] New Version Notification for draft-bortzm… Stephane Bortzmeyer
- Re: [DNSOP] New Version Notification for draft-bo… Shane Kerr
- Re: [DNSOP] New Version Notification for draft-bo… Stephane Bortzmeyer
- Re: [DNSOP] New Version Notification for draft-bo… Shane Kerr