Re: [DNSOP] Proposal: Whois over DNS

Bjarni Rúnar Einarsson <bre@isnic.is> Tue, 09 July 2019 14:17 UTC

Return-Path: <bre@isnic.is>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8F7C8120180 for <dnsop@ietfa.amsl.com>; Tue, 9 Jul 2019 07:17:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3anKdorn0e6z for <dnsop@ietfa.amsl.com>; Tue, 9 Jul 2019 07:17:16 -0700 (PDT)
Received: from lugh.isnic.is (lugh.isnic.is [193.4.58.86]) by ietfa.amsl.com (Postfix) with ESMTP id A5B3C12028F for <dnsop@ietf.org>; Tue, 9 Jul 2019 07:16:51 -0700 (PDT)
Received: by lugh.isnic.is (Postfix, from userid 2516) id 407EEABB77; Tue, 9 Jul 2019 14:16:50 +0000 (GMT)
Content-Type: multipart/mixed; boundary="==CgoBhZ7n9ErmSGgu2gVfRURk7imYcG=="
MIME-Version: 1.0
From: Bjarni Rúnar Einarsson <bre@isnic.is>
To: Jim Reid <jim@rfc1035.com>
Cc: John Bambenek <jcb=40bambenekconsulting.com@dmarc.ietf.org>, dnsop@ietf.org
In-Reply-To: <233E0AD8-97FE-466C-9B6C-D7A376031C3B@rfc1035.com>
References: <233E0AD8-97FE-466C-9B6C-D7A376031C3B@rfc1035.com>
User-Agent: Mailpile
Message-Id: <FUkLTVMXAgJMiDybUjWJmf4VMxMskCZdtairxrSf2353@mailpile>
Date: Tue, 09 Jul 2019 14:15:12 -0000
Autocrypt: addr=bre@isnic.is; keydata=xsDNBFyh/HMBDADeTUDSeFjLIlG/S4OkGDwsdHgc cAjnWun+MhVHlm/AK5nQ+Nr+dMgPoDKgtTz9TZgmewpvEWnGIdBhsBSFMAncFaGxWBjvNRjcy3QZZ ndwfKRBUsbbkhQbQ8qIxKYZxw8cY4JGPIUiqNZjIYORKuchN0MXqsUjkmsSrMQEw3n8Nsi+aQT/w/ lnKJO9cCPTaCThTN0odwva2QWe8WWLQ3Fr5UBuhb/LzbMVZn61ASjehnTt2YKYXsiRcLRs/XfqaqU vIwM3WqFKH9IZl49V+wQBHu4kljLchLw2DPLpf+mv2VoZMaks2DmTJDTlKkXp3X9YXvGUBcHGyF7S 4KqsKTZnplVxNE89X4Fg1FjGdHHAsXVBpOibKGpPqc91hsj5SbcipfXfIBl0FzLlGZvWUTtQsq46k fa4k06oSpcr89g5zVnLOHL0ftpSX6ScIVgKsV1uEYgWhjWjATBuUdKXG93rSluZDVIrf34Jb/EsTf bT8ff0SipaiYizRTLXZ4KiDZ8AEQEAAc0mQmphcm5pIFLDum5hciBFaW5hcnNzb24gPGJyZUBpc25 pYy5pcz7CwQ4EEwEKADgWIQQs8AwZMbeQyjfTmy5ZC1sMA8ImhQUCXKH8cwIbAwULCQgHAgYVCgkI CwIEFgIDAQIeAQIXgAAKCRBZC1sMA8ImhZYHC/9cd4KB4EwhvFm3sNwv2iTUouDGQCsDeK0WMvozS ZwR/vG0s8katBlCL1XOmKGDGADS3FcmmjlguvOT572WXLZvx2Tn0U9g5N69htB0VeUJjaGpVNzUwf I+W6M6NDYQolQ2y4Ndm7HCjwDPStelZyE2cXMVBsxZYl3UMoUfScI6BNneA+EiUxit/PU+LbFc59a oTEVOtBcID/3RmFHDL7WyZjEvZh2UVzu+dIsJuINd+G+GPnvS1UfHsMsEQhk84VCCG4VYkbwN81Wa zoL7mWCNjjJnqh9ERjVwYyUhRVw+9VcimUrsZf6s1GlEtEI2kquSsTH1BZ5v0POYVJ/mHK/kCDCAP 6B2I78ExppGi1mL52YwuwovO//OVkCiVBciCA/NKtk3mGnhMWoB4vDmaFY2H+gOeV/sSxGnsuUicR zcPlUjwtUx1+T6/b/ib0px2JXzOYBV2gCNzUDC7iQ3Ahsf7V1Yi4nCDN9gJsCDEj/JItWIAz2rUKB dQiMKSpF6LOjOwM0EXKH8cwEMAMmjYLjn/M7kxb0Uasyeg6jv7KDS92jdkh3fjV2TsgL1gTRqQrNH gejBP19Wwg6oc7cRmmoDfQ6mtNyXvNfd+5cF5MdR62q01TGb4ciatUbpoMA8IfyqeopuafMwteoE+ M8oO5OfHc0PeXORr059KK9P8vLcnit8GM6y/DkTZPnZOwDnM4SoPFSZZXcBogsHPjbklIzGoqwjMA ehmo2riJOrgL1XR3U83cOY45mLsw68mCGiYTtFG+gNW0wq4Hkj8kizMJ3nlEuIkhQ+wVQ+BIU+xQo bNhoorY3oK7aeJf2dmpF49nNUFSORYrcSzADP9a9Fj9fThfK0yJ7RgLQeCAZgxuYyDHeF6v03UVyo WIx1KMm3K/PHhHhxr4f1oZl+Y35czg9I8UkyCuoSa4Vrb8neBTJaOq+7ZQqSk0xBKf+NIHEBlb4zt Niru+WQv0PkJypUDQZvKhB5frnId5brpUUPfGOX/EL7w2LVlHQVEkPeUCyewIKBcCCW0wdtSrrzew ARAQABwsD2BBgBCgAgFiEELPAMGTG3kMo305suWQtbDAPCJoUFAlyh/HMCGwwACgkQWQtbDAPCJoU 0cQwAy+0RUc+JERn2V7bP/04aH+mmcpRtQQxrRRxTdzYSA6laCMhmzBZkCJA38ESuD3cCLu9zGJkR j1iu/FO4PejB0G0+1EMv9BNWqyOcehQH2ZjNPSQX2kCdBuGdqXuJIapV0EpIUi735h8u5igTUbagO tGZ4fifo4B2tOVtfoC82EA9jsdyUELGy/irLQG0DVqqD5yV+OmWVNd3kErJYjVBd0EWtSeqedLVSF hL5xT3xNo7UbzvqeS6X1c6hF7CyH6mgzYN0N3+r5ZikN9tWXamVW7FImnDl58ydUm9um0T6IIP7Ah +KkMEHwZX3Ndfyy+DAXfB5Irs013wL8nLCprTFylHPrQP0F7yOsOt9v1aVgoHC3Z7Kg+ejGYHkq4A NixzuzrMNjqZHxkwC6MYH2vvrKsB3rLII7vee1eskSXMupx+8FZuZ04IPfTC8qaAoDNUqUqn1ZwT+ uSA0ner6+/oJP9ImxEcJdP40hmHjc6EsnkwG6fuLmeQodh2twspeFQr
OpenPGP: id=2CF00C1931B790CA37D39B2E590B5B0C03C22685; preference=sign
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/IEJkrJIcshiC6Rd6b3Q4AKl1slA>
Subject: Re: [DNSOP] Proposal: Whois over DNS
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 09 Jul 2019 14:17:19 -0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hello everyone,

Jim Reid <jim@rfc1035.com> wrote:
> 
> BTW, whois was originally intended to provide a way to publish
> out-of-band contact data so the domain holder could be
> contacted whenever their DNS or email was broken. Putting this
> info in the DNS would defeat that.

Implementation details aside, I think having a technical
specification like this would be quite interesting from the point
of view of automatically updates to existing Whois databases,
without requiring the registrant directly (or indirectly)
interact with complex APIs or provider-specific web interfaces.

Much like CDS for DS records, and CSYNC for NS records, having a
well defined vocabulary for this data in DNS could be a useful
step towards such automation. Assuming a cautious implementation,
this need not make whois any less reliable.

So, that's a potential use-case which I haven't seen mentioned
here yet.

That said, I agree it cannot solve GDPR or other policy concerns.

Also, I really don't see this data as meaningfully useful in
fighting abuse, if only because it's very unlikely to see wide
adoption in the near future, and because it will be incredibly
easy to just create plausible looking (or maliciously
Joe-jobbing) fake records. This will largely boil down to 2 bits
of information: "did someone in the domain's chain of tools &
admins decide to implement this standard?" and "did anybody
decide to fill out the relevant forms?" - neither of which are
meaningful when combating abuse. I am extremely skeptical of any
claims that there's more information to be extracted here.

The fact that it will be easier to programmatically look up this
information seems to me unlikely to actually make things better,
I see it mostly adding complexity and more GI for the GO. Just my
opinion, obviously.

But I remain vaguely excited about the potential for automation!

Cheers,
 - Bjarni

- -- 
Sent using Mailpile, Free Software from www.mailpile.is

-----BEGIN PGP SIGNATURE-----

iQGzBAEBCgAdFiEELPAMGTG3kMo305suWQtbDAPCJoUFAl0koYMACgkQWQtbDAPC
JoWELQv/TfNARJISejOLP+17xUyMKBHo6gCSOodY+v6PE5fwElbRTjBynQCs2/yM
E7qyt96cDKzDuU6iak82znm0cKE+bDN/sLq5Ww/0qO5HT18ZEz78BAS8yWZsiLiY
oxsPdtCxYPlzJqKA8DeZ6/dJ+ljTyZk5Jr8nw86Ji9vQdE+R1EY02FO6+9EpOjcA
0cnCHD1My4AvY34e7LwRy/4zlJlfvkblu2d7s+XlUTz151ipnTfkAKJNi1zDfcaw
Anae5N7Dnq+CArI+wkZNX+Hq1YK10R6RQk7OM2ZjD9s+9eSnpPG0+NbkSaHVIqkT
udcVeo50zuXoEYtK2OGi4ojnFQbB+rPMegTHOaR0o+UxfHsoMv7kfHe9sA2u+jAn
b/+Xiz7kJtYD0pFalJBPOMXwt+jK1bFqoFrZ5+D431p8os2LVc2QYiFckmgwnpGF
sn3Lj4EOp9T1qLjQwy/Mm5BRq0Z7IFf6Cn/BGctv/m6JEF+bg0ljXahbHA0Uzn0K
L6p2KZAN
=plYr
-----END PGP SIGNATURE-----