Re: [DNSOP] Review of draft-livingood-dns-redirect-00

"Livingood, Jason" <Jason_Livingood@cable.comcast.com> Thu, 16 July 2009 12:31 UTC

Return-Path: <jason_livingood@cable.comcast.com>
X-Original-To: dnsop@core3.amsl.com
Delivered-To: dnsop@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 79B8B3A6D3C for <dnsop@core3.amsl.com>; Thu, 16 Jul 2009 05:31:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.142
X-Spam-Level:
X-Spam-Status: No, score=0.142 tagged_above=-999 required=5 tests=[AWL=-1.462, BAYES_00=-2.599, HELO_EQ_MODEMCABLE=0.768, HOST_EQ_MODEMCABLE=1.368, RCVD_NUMERIC_HELO=2.067]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id juSJbjykg2y5 for <dnsop@core3.amsl.com>; Thu, 16 Jul 2009 05:31:25 -0700 (PDT)
Received: from paoakoavas09.cable.comcast.com (paoakoavas09.cable.comcast.com [208.17.35.58]) by core3.amsl.com (Postfix) with ESMTP id 6EBF23A6D46 for <dnsop@ietf.org>; Thu, 16 Jul 2009 05:31:25 -0700 (PDT)
Received: from ([10.52.116.30]) by paoakoavas09.cable.comcast.com with ESMTP id KP-NTF18.75019483; Thu, 16 Jul 2009 08:31:41 -0400
Received: from PACDCEXCMB04.cable.comcast.com ([24.40.15.86]) by PAOAKEXCSMTP01.cable.comcast.com with Microsoft SMTPSVC(6.0.3790.3959); Thu, 16 Jul 2009 08:31:42 -0400
Received: from 68.83.175.155 ([68.83.175.155]) by PACDCEXCMB04.cable.comcast.com ([24.40.15.86]) via Exchange Front-End Server webmail.comcast.com ([24.40.8.153]) with Microsoft Exchange Server HTTP-DAV ; Thu, 16 Jul 2009 12:31:04 +0000
User-Agent: Microsoft-Entourage/12.19.0.090515
Date: Thu, 16 Jul 2009 08:31:01 -0400
From: "Livingood, Jason" <Jason_Livingood@cable.comcast.com>
To: Stephane Bortzmeyer <bortzmeyer@nic.fr>, Roy Arends <roy@dnss.ec>
Message-ID: <C68495C5.EF3F%Jason_Livingood@cable.comcast.com>
Thread-Topic: [DNSOP] Review of draft-livingood-dns-redirect-00
Thread-Index: AcoGEUcRgQKgRWyeW0+K9AyGj46kNw==
In-Reply-To: <20090716071553.GA5985@nic.fr>
Mime-version: 1.0
Content-type: text/plain; charset="US-ASCII"
Content-transfer-encoding: 7bit
X-OriginalArrivalTime: 16 Jul 2009 12:31:42.0203 (UTC) FILETIME=[5FA044B0:01CA0611]
Cc: dnsop@ietf.org
Subject: Re: [DNSOP] Review of draft-livingood-dns-redirect-00
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Jul 2009 12:31:26 -0000

>> SSAC's Report on DNS Response Modification
>> http://www.icann.org/en/committees/security/sac032.pdf
> 
> Indeed. Good document. There is no need to discuss about


> draft-livingood-dns-lie,

Is that really necessary?

> all the issues raised here in this WG were
> already in the SSAC document one year ago.

Indeed.  **However,** the SSAC document seems to me to speak to TLD
operators and registries, not ISPs.  To wit, please refer to page 16,
Preliminary Recommendations.  With the exception of recommendation #4, these
appear to me to all be related to actions by registrars and TLD operators.

And Preliminary Recommendation #4 states that "Third parties [defined in the
paper to include ISPs] should disclose that they practice NXDomain response
modification and provide opportunities for customers to opt out."

You may wish to note that I expand at length on this preliminary
recommendation from the SSAC paper in my draft.
 
Regards,
Jason