Re: [DNSOP] draft-ietf-dnsop-structured-dns-error: suberr registration policy
tirumal reddy <kondtir@gmail.com> Wed, 19 April 2023 14:04 UTC
Return-Path: <kondtir@gmail.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AB17DC137392; Wed, 19 Apr 2023 07:04:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.095
X-Spam-Level:
X-Spam-Status: No, score=-2.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RVhp4WlPZxYW; Wed, 19 Apr 2023 07:04:15 -0700 (PDT)
Received: from mail-lj1-x22a.google.com (mail-lj1-x22a.google.com [IPv6:2a00:1450:4864:20::22a]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EA1C8C137395; Wed, 19 Apr 2023 07:04:14 -0700 (PDT)
Received: by mail-lj1-x22a.google.com with SMTP id l15so9798497ljq.8; Wed, 19 Apr 2023 07:04:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20221208; t=1681913053; x=1684505053; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=xvmp5WFtFKpgDKrX5NMRZLSKZn6t3itiiJGSOdLXWgY=; b=XomqDqQfk1/B8NvAVXEWMtThAk6+jWZOrHVEyE4LQrqrcZhQY61TqTZi7F4x7h5x0N 9b8E5wBhm2W4DYNuUus9mwEcWL5zN32UDf0ULQV1huE7ni2ke8/GpeJplolpD1l1ynHi yVADLgggADO8svFG/JWi0belV4iJua1Wa62EDd3UgErKCu2jwYIbkdxDsRx+i+l2xcOR RhVrVlfChkvG5Yh/qv8dGOiDXU4MoeB4feUIG5WLTtUy2PrBx0e1kFUc1pS7icJkh+z1 RTH5k+YGG8Uz9yu0hh5TLifHXTTeKX+I+KlJCh3Pl7REZC9f2bHt/+7+gzX3rQq1L3/Y O7xA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1681913053; x=1684505053; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=xvmp5WFtFKpgDKrX5NMRZLSKZn6t3itiiJGSOdLXWgY=; b=ZQ56OfNk76Y855DbRDZkQ/DG/+FX4CIUzHNVER7Kb9vYJsq4Cw358ri/p5jzobR87V ydISsSLy8rLH9BZs6WBHDgsznyTDhHqe0kHFtZyIz0Jitn1rbPthnLUpE6/oq4rI3Ed3 g1Dk4k6HFjmOQ3Xc3AwFJC7totDzzMl9sczIQ0EzdfMnGol0JxqeOtBkUP/YnvyX1wQO eq0J0BaLxgBhadpY/BHdU2LxGCE34NVG618+B4G39t74AdZvx5rQ/PoUpMFlspF7tOID RoH9+nQn4feh71iIi5jVNo1SfmBawp9VLv3nHj1kkClRdf/uYuzcfxyYTyj8YsrrN4zo 9hng==
X-Gm-Message-State: AAQBX9ex8llRtx2XrMmJg5Q+23RZ9196W4RRWc6hDvF2w3BYRq3X2Z5s wfT6YrbHDxsxntdCHBU3HGKcekGabgdTF/Bqw6A=
X-Google-Smtp-Source: AKy350bSDcJxYUst35BAf5MclXaoXkh4YOTVHPsDk8pktu6HlaoLpqQ6W4IoenFMjPtr2o4LyBP3MuM/vDwmV4kjUXE=
X-Received: by 2002:a2e:b049:0:b0:2a8:aed7:4f48 with SMTP id d9-20020a2eb049000000b002a8aed74f48mr2030042ljl.9.1681913052803; Wed, 19 Apr 2023 07:04:12 -0700 (PDT)
MIME-Version: 1.0
References: <4561_1680881181_6430361D_4561_496_1_cbba461734d74dbf8116d7f476960f88@orange.com> <CAJF-iTRHVS8asiaf-fvtWZqpNdzou4zEsb36roaK-S_HMAEX2g@mail.gmail.com>
In-Reply-To: <CAJF-iTRHVS8asiaf-fvtWZqpNdzou4zEsb36roaK-S_HMAEX2g@mail.gmail.com>
From: tirumal reddy <kondtir@gmail.com>
Date: Wed, 19 Apr 2023 19:34:01 +0530
Message-ID: <CAFpG3ge6b6LjeBahy2hS6CnHW00dhgHJ5gdS9eTxj0WxU7fbYg@mail.gmail.com>
To: Benjamin Schwartz <ietf@bemasc.net>
Cc: mohamed.boucadair@orange.com, dnsop <dnsop@ietf.org>, "draft-ietf-dnsop-structured-dns-error@ietf.org" <draft-ietf-dnsop-structured-dns-error@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000000e3bbf05f9b0e607"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/MNhdG925e5zwLZWFvTRYLhxeejc>
Subject: Re: [DNSOP] draft-ietf-dnsop-structured-dns-error: suberr registration policy
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 19 Apr 2023 14:04:18 -0000
On Tue, 18 Apr 2023 at 16:41, Benjamin Schwartz <ietf@bemasc.net> wrote: > The draft's opening words are "DNS filtering is widely deployed for > network security". This is true, but by far the "widest" deployment of DNS > filtering is for authoritarian national censorship, to prevent citizens > from engaging with forbidden ideas. > > The EDE draft acknowledges and rebukes this rather directly with the > "Censored" code, expressing that this filtering was performed _against_ the > preference of the resolver operator. Although the EDE registry is FCFS, > the presence of this registry entry at the outset ensures that any attempt > to whitewash this sort of behavior would be duplicative. > > The "structured errors" draft risks undermining this norm and diluting the > intent of the "Censored" code. For example, the "Malware", "Phishing", > "Spam", and "Spyware" suberrors are listed as applicable to the "Censored" > code, which is rather strange. What is a "Spam" domain, and when would a > resolver be forced to filter it "due to an external requirement imposed by > an entity other than the operator"? > Yes, "Spam" is not suitable with "Censored" code. The other suberror codes may be applicable with "Censored" code. For instance, in a deployment where the network-provided DNS forwarder is configured to use a public resolver to filter malware domains. -Tiru > > I think the idea of "suberrors" for the "Censored" EDE code probably just > doesn't make sense. By definition, this code indicates that the resolver > _doesn't_ know why the result was filtered. (The resolver operator may > know a _claimed_ reason, but it has no way to know whether this rationale > is the real motivation.) Thus, one way forward might be to exclude this > code from the suberror registry. > > Even for the other codes, I think this registry opens a terrible can of > worms that the IETF can and should avoid. Shall we add codes for "adult > content"? "advertising"? "social media"? "political extremism"? "terrorist > content"? "CSAM"? "fake news"? > > The EDE draft manages this to some extent by presenting an initial list of > codes that are plainly technical or structural in nature. This draft does > the opposite, by starting to enumerate all the perceived evils of the > Internet. > > Let's not go down that road. > > On Fri, Apr 7, 2023 at 11:26 AM <mohamed.boucadair@orange.com> wrote: > >> Hi all, >> >> >> >> We are implementing the changes to address the feedback we received in >> IETF#116. The candidate changes can be seen at Diff: >> draft-ietf-dnsop-structured-dns-error-01.txt - >> draft-ietf-dnsop-structured-dns-error.txt >> <https://author-tools.ietf.org/api/iddiff?doc_1=draft-ietf-dnsop-structured-dns-error&url_2=https://ietf-wg-dnsop.github.io/draft-ietf-dnsop-structured-dns-error/draft-ietf-dnsop-structured-dns-error.txt> >> >> >> >> The current version of the draft indicates that the policy for >> registering a new suberr is via DE. We added a guard to prevent that DEs >> modify entries set via IETF review. >> >> >> >> I know that Ben indicated a preference for requiring IETF review for the >> registry. This seems to me too restrictive, especially that the policy for >> the EDE itself is FCFS. The argument that DEs will be pressured is not >> specific to this registry and would a priori apply for every registry with >> a DE policy. >> >> >> >> I think that we need a good balance to allow for useful suberr codes to >> be registered without requiring much heaviness in the process that is >> induced by an IETF review. >> >> >> >> Ben, if your concern is to have some control, what about requiring that >> new registrations should be sent to the DEs and also to dnsop (or another >> list), and that DEs should listen to whatever feedback received from the >> list? >> >> >> >> Thank you. >> >> >> >> Cheers, >> >> Med >> >> _________________________________________________________________________________________________________________________ >> >> Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc >> pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler >> a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration, >> Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci. >> >> This message and its attachments may contain confidential or privileged information that may be protected by law; >> they should not be distributed, used or copied without authorisation. >> If you have received this email in error, please notify the sender and delete this message and its attachments. >> As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified. >> Thank you. >> >> _______________________________________________ >> DNSOP mailing list >> DNSOP@ietf.org >> https://www.ietf.org/mailman/listinfo/dnsop >> >
- [DNSOP] draft-ietf-dnsop-structured-dns-error: su… mohamed.boucadair
- Re: [DNSOP] draft-ietf-dnsop-structured-dns-error… Ralf Weber
- Re: [DNSOP] draft-ietf-dnsop-structured-dns-error… Benjamin Schwartz
- Re: [DNSOP] draft-ietf-dnsop-structured-dns-error… Stephen Farrell
- Re: [DNSOP] draft-ietf-dnsop-structured-dns-error… Paul Wouters
- Re: [DNSOP] draft-ietf-dnsop-structured-dns-error… Benjamin Schwartz
- Re: [DNSOP] draft-ietf-dnsop-structured-dns-error… Ralf Weber
- Re: [DNSOP] draft-ietf-dnsop-structured-dns-error… Benjamin Schwartz
- Re: [DNSOP] draft-ietf-dnsop-structured-dns-error… tirumal reddy
- Re: [DNSOP] draft-ietf-dnsop-structured-dns-error… tirumal reddy
- Re: [DNSOP] draft-ietf-dnsop-structured-dns-error… Benjamin Schwartz
- Re: [DNSOP] draft-ietf-dnsop-structured-dns-error… tirumal reddy
- Re: [DNSOP] draft-ietf-dnsop-structured-dns-error… Vittorio Bertola