Re: [DNSOP] Privacy and DNSSEC

Paul Vixie <paul@redbarn.org> Sat, 25 April 2020 06:56 UTC

Return-Path: <paul@redbarn.org>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 257F73A0B8F for <dnsop@ietfa.amsl.com>; Fri, 24 Apr 2020 23:56:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id K_n2TsKUbhLG for <dnsop@ietfa.amsl.com>; Fri, 24 Apr 2020 23:56:39 -0700 (PDT)
Received: from family.redbarn.org (family.redbarn.org [IPv6:2001:559:8000:cd::5]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7088D3A0B8C for <dnsop@ietf.org>; Fri, 24 Apr 2020 23:56:39 -0700 (PDT)
Received: from linux-9daj.localnet (vixp1.redbarn.org [24.104.150.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by family.redbarn.org (Postfix) with ESMTPSA id 2E51FB074A for <dnsop@ietf.org>; Sat, 25 Apr 2020 06:56:39 +0000 (UTC)
From: Paul Vixie <paul@redbarn.org>
To: dnsop@ietf.org
Date: Sat, 25 Apr 2020 06:56:38 +0000
Message-ID: <2119709.gsHikbp680@linux-9daj>
Organization: none
In-Reply-To: <71d22908-b0a9-5f0c-585e-0d10aa3edc8a@nic.cz>
References: <CAHPuVdV9eSCLQOqMF0cq8fHcuSZs7nCgjhHMfMoaV5H=ekbtSA@mail.gmail.com> <CAHPuVdUh4UTP5pH_X83pm8OvY7juEotSYT6FLbVyE4_S-ev9Bg@mail.gmail.com> <71d22908-b0a9-5f0c-585e-0d10aa3edc8a@nic.cz>
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/PsuUIOuJc30C9Mt9f5VpGaKB9dY>
Subject: Re: [DNSOP] Privacy and DNSSEC
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 25 Apr 2020 06:56:41 -0000

mind if i cut in?

On Saturday, 25 April 2020 06:23:54 UTC Vladimír Čunát wrote:
> Original subject: New draft on delegation revalidation
> 
> On 4/24/20 4:49 PM, Shumon Huque wrote:
> > ...
> 
> ...

(agreeableness.)

> Still, note that for some consumers the secure transport may be an
> argument to drop validating DNSSEC themselves.  If they choose some DNS
> provider that they trust with privacy (it might be their ISP), it seems
> not a huge leap to trust them with DNS integrity as well (say, the
> provider doing DNSSEC validation).  Especially as today "regular users"
> don't get that much benefit from validation, mostly relying on
> https/tls.

i hope there's some use for DNS results beyond introducing me to an X.509 
authenticated web server. for example i might use DNS to validate an X.509 
self-signed certificate along the lines of DANE. to me this means the goal we 
followed for DNSSEC (authenticate what goes into an RDNS cache) was too 
narrow, and the difficulties of getting stub validation working should have 
been avoided from the outset (in 1996, that was.)

> Some of them also want a variant of DNS filtering, which
> still clashes with validation a bit (if done *after* filtering).

it will be necessary for filtered results to be separately (hop by hop) signed 
using something like SIG(0) or TSIG. (stubs ought to choose who can filter.) 
but this isn't a substitute for stub validation (end to end). one ought not 
trust a coffee shop or even one's own ISP to make a trusted introduction to 
one's bank (more or less quoting dan kaminsky from back in 2008 or so.)

-- 
Paul