Re: [DNSOP] Blog Post: DNS over TLS support in Android P Developer Preview

Marek Vavruša <mvavrusa@cloudflare.com> Fri, 13 April 2018 20:02 UTC

Return-Path: <mvavrusa@cloudflare.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 500D2128896 for <dnsop@ietfa.amsl.com>; Fri, 13 Apr 2018 13:02:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.011
X-Spam-Level:
X-Spam-Status: No, score=-2.011 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_DKIMWL_WL_HIGH=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cloudflare.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bwqKCAGFCG1u for <dnsop@ietfa.amsl.com>; Fri, 13 Apr 2018 13:02:44 -0700 (PDT)
Received: from mail-yb0-x22e.google.com (mail-yb0-x22e.google.com [IPv6:2607:f8b0:4002:c09::22e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7F36E127978 for <dnsop@ietf.org>; Fri, 13 Apr 2018 13:02:44 -0700 (PDT)
Received: by mail-yb0-x22e.google.com with SMTP id c1-v6so4880461ybm.2 for <dnsop@ietf.org>; Fri, 13 Apr 2018 13:02:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudflare.com; s=google; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=WHu85NoUCEByWIbLJo4zGC3l2CoUMciVY3nOFU8EzJI=; b=U+fLFngx2pvwvlFJHtuqnetZC/uste0VVFzNLKIXr7qt+iH7gcQ2/fkuCu6djb2ICq U2NThffkLSrIvor1XUqTHaLUO0+Wx5fnx4S+DLfIIfMU5Ye01n7KCzBQMPt14QIGv8Ua 7lqUQ4maLUAmtJhvfEc2GIRHp2ucQBqZFxc4w=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=WHu85NoUCEByWIbLJo4zGC3l2CoUMciVY3nOFU8EzJI=; b=jUZM2WJA1qpV5lzjgsuY+wtxL5pxQ82Hgr1atK8ed/D7gah5HMk4vGIgv4HKU010IN a4sERJa0wsmm92IOKAl2Y+Z/jjFwlt1kgjT63OzBoq/oNsriqHS77cBMkzy780grpwAD MzG4IiMX8EvuLyE+oRiq3bAnN/uAsoeVFqmYsUOPqvpCTkcdWLIJwavx09ZIx+pkeh6T xRIRz64UBMzoBazgFybp8g3cwBlhIIB1a4DVRiE7m+AXZrm2K7E0nQ8u+edWrIeyckza YPUe5ECfGCE5E6R0V8IhT5n8RGQq65fHZ1wAHVf4LTDXP2wBgUx2G5D33FMKH2B7Hz/D AglQ==
X-Gm-Message-State: ALQs6tAv/RsblmpZPr2EuuDEathGlld9XoP97vlXxHUvomPmEHa3RnHX D3aCFiI0cAV1t2IADoJnyyat+ystPbCSyYxEYUhAIQ==
X-Google-Smtp-Source: AIpwx49tlMhLraSJ8kB/FwGmixn8nG66lPqrgZzLUejXl+XhllIf2j6eNadEIXYoF2fGyn4O6pR1zb22PCA5N8b0Z84=
X-Received: by 2002:a25:7685:: with SMTP id r127-v6mr4405541ybc.408.1523649763536; Fri, 13 Apr 2018 13:02:43 -0700 (PDT)
MIME-Version: 1.0
Received: by 2002:a25:a303:0:0:0:0:0 with HTTP; Fri, 13 Apr 2018 13:02:42 -0700 (PDT)
In-Reply-To: <CAHw9_iKax=0hGwAj_X0m0Dqckutb+qMtMwnHRj54qicSsYKk0w@mail.gmail.com>
References: <CAHw9_iKax=0hGwAj_X0m0Dqckutb+qMtMwnHRj54qicSsYKk0w@mail.gmail.com>
From: Marek Vavruša <mvavrusa@cloudflare.com>
Date: Fri, 13 Apr 2018 13:02:42 -0700
Message-ID: <CAC=TB11ADLhvbuRLXeokVdY5ASPb1BVWzjBO+baKV-wmPjOjbg@mail.gmail.com>
To: Warren Kumari <warren@kumari.net>
Cc: dnsop <dnsop@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/RninHwTODQUnd2fXJfHCRTq_PkY>
Subject: Re: [DNSOP] Blog Post: DNS over TLS support in Android P Developer Preview
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Apr 2018 20:02:46 -0000

This is great, well done.

On Fri, Apr 13, 2018 at 12:49 PM, Warren Kumari <warren@kumari.net> wrote:
> Hi all,
>
> As Erik Kline and Ben Schwartz seem to be too modest to toot their own
> horn, I'll do it for them:
> https://android-developers.googleblog.com/2018/04/dns-over-tls-support-in-android-p.html
>
> Snippet from the above:
> "The Android P Developer Preview includes built-in support for DNS
> over TLS. We added a Private DNS mode to the Network & internet
> settings.
>
> By default, devices automatically upgrade to DNS over TLS if a
> network's DNS server supports it. But users who don't want to use DNS
> over TLS can turn it off."
>
> W
>  (Also posted to dprive)
> --
> I don't think the execution is relevant when it was obviously a bad
> idea in the first place.
> This is like putting rabid weasels in your pants, and later expressing
> regret at having chosen those particular rabid weasels and that pair
> of pants.
>    ---maf
>
> _______________________________________________
> DNSOP mailing list
> DNSOP@ietf.org
> https://www.ietf.org/mailman/listinfo/dnsop