Re: [DNSOP] New Version Notification for draft-bortzmeyer-dname-root-02.txt

Shane Kerr <shane@time-travellers.org> Fri, 29 April 2016 14:31 UTC

Return-Path: <shane@time-travellers.org>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 29F1E12D180 for <dnsop@ietfa.amsl.com>; Fri, 29 Apr 2016 07:31:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9YJofyCZtdfy for <dnsop@ietfa.amsl.com>; Fri, 29 Apr 2016 07:31:21 -0700 (PDT)
Received: from time-travellers.nl.eu.org (c.time-travellers.nl.eu.org [IPv6:2a02:2770::21a:4aff:fea3:eeaa]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A573612D157 for <dnsop@ietf.org>; Fri, 29 Apr 2016 07:31:21 -0700 (PDT)
Received: from [2001:470:78c8:2:224:9bff:fe13:3a9c] (helo=pallas.home.time-travellers.org) by time-travellers.nl.eu.org with esmtpsa (TLS1.2:RSA_AES_128_CBC_SHA1:128) (Exim 4.80) (envelope-from <shane@time-travellers.org>) id 1aw9Rt-0005x1-SH; Fri, 29 Apr 2016 14:31:17 +0000
Date: Fri, 29 Apr 2016 16:31:15 +0200
From: Shane Kerr <shane@time-travellers.org>
To: Stephane Bortzmeyer <bortzmeyer+ietf@nic.fr>
Message-ID: <20160429163115.797f4b84@pallas.home.time-travellers.org>
In-Reply-To: <20160429135727.GB314@nic.fr>
References: <20160429135727.GB314@nic.fr>
X-Mailer: Claws Mail 3.13.2 (GTK+ 2.24.30; x86_64-pc-linux-gnu)
MIME-Version: 1.0
Content-Type: multipart/signed; micalg="pgp-sha1"; boundary="Sig_/mdddn=HTYmNs0AlRVdcL=za"; protocol="application/pgp-signature"
Archived-At: <http://mailarchive.ietf.org/arch/msg/dnsop/9SMSgU2P84dWjqzfquqdkufh7oQ>
Cc: dnsop@ietf.org
Subject: Re: [DNSOP] New Version Notification for draft-bortzmeyer-dname-root-02.txt
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 29 Apr 2016 14:31:24 -0000

Stephane,

At 2016-04-29 15:57:27 +0200
Stephane Bortzmeyer <bortzmeyer+ietf@nic.fr> wrote:

> No objection from the AS112 operators was received. Now, what do you
> think of this draft? Should we continue or is it a bad idea (or a good
> one, but hopeless?)

I think I said this in person but I don't know if I ever wrote it down.

I think that there may be some decreased privacy since queries for
these zones are going to be sent to basically anonymous servers instead
of root servers. Certainly for something like .ONION this is less
desirable.

OTOH, anyone using such a zone faces operator error causing such leaks
in any case. Indeed having these queries show up at the root is also
the result of DNS administrator misconfiguration. Also, any attacker
interested in looking at such queries has alternate ways of seeing such
traffic even today (via BGP tricks at least). The actual extra leakage
is minimal.

If the proposal does go forward (I really have no feeling whether it is
useful or not), then perhaps this can be mentioned in the "Possible
issues" section?

Cheers,

--
Shane