[DNSOP] Re: [TLS] Re: Re: Re: AD review draft-ietf-tls-svcb-ech

"Salz, Rich" <rsalz@akamai.com> Fri, 04 October 2024 19:48 UTC

Return-Path: <rsalz@akamai.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0C92AC15199B; Fri, 4 Oct 2024 12:48:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.252
X-Spam-Level:
X-Spam-Status: No, score=-2.252 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.148, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=akamai.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OsHxQPFtllgx; Fri, 4 Oct 2024 12:48:44 -0700 (PDT)
Received: from mx0a-00190b01.pphosted.com (mx0a-00190b01.pphosted.com [IPv6:2620:100:9001:583::1]) by ietfa.amsl.com (Postfix) with ESMTP id 651D0C14F702; Fri, 4 Oct 2024 12:48:44 -0700 (PDT)
Received: from pps.filterd (m0050093.ppops.net [127.0.0.1]) by m0050093.ppops.net-00190b01. (8.18.1.2/8.18.1.2) with ESMTP id 4945cnv7026399; Fri, 4 Oct 2024 20:48:37 +0100
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai.com; h=cc :content-type:date:from:in-reply-to:message-id:mime-version :references:subject:to; s=jan2016.eng; bh=6JbJq0Yfyg8MbR6K/MVRZz B+cJOpObBQhpgK77tIY/g=; b=LDMmlT68adBHaPaM1Sbp9wdiHlSf/YtKNN1GLY UoPv2OQwiS33roXvUPV2ronuc+j8a34V7MiM1xt5F70O1F5Zg6zGi0W0ZKbPSQ2M SAGgmwnt08Q1gw2Xce1urhFjXFdNrdFsY6NNujKT6K9MFE5/m2WrvgpYsX7Kj4ya YJ0CmLjxsf5LcN+Dx/USBw+///k4zB/5rW3Y6a2h74qVIC2cH1TzBmG2Wgli4pbg BcbGZxSnvWHfgckcj7c9gOXZoqwRJEy72BNn/acCVZTkJ8Sl+PnLcYf8Giufu5lp SjciBqkYOa01y8/PSa4yFR28Vz6B3cu87wwfPrP20w523t1Q==
Received: from prod-mail-ppoint1 (prod-mail-ppoint1.akamai.com [184.51.33.18] (may be forged)) by m0050093.ppops.net-00190b01. (PPS) with ESMTPS id 42205jpd0s-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 04 Oct 2024 20:48:37 +0100 (BST)
Received: from pps.filterd (prod-mail-ppoint1.akamai.com [127.0.0.1]) by prod-mail-ppoint1.akamai.com (8.18.1.2/8.18.1.2) with ESMTP id 494F6Z62027380; Fri, 4 Oct 2024 15:48:24 -0400
Received: from email.msg.corp.akamai.com ([172.27.50.203]) by prod-mail-ppoint1.akamai.com (PPS) with ESMTPS id 42206rm7jd-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 04 Oct 2024 15:48:23 -0400
Received: from ustx2ex-dag4mb4.msg.corp.akamai.com (172.27.50.203) by ustx2ex-dag4mb4.msg.corp.akamai.com (172.27.50.203) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Fri, 4 Oct 2024 12:48:23 -0700
Received: from ustx2ex-dag4mb4.msg.corp.akamai.com ([172.27.50.203]) by ustx2ex-dag4mb4.msg.corp.akamai.com ([172.27.50.203]) with mapi id 15.02.1544.011; Fri, 4 Oct 2024 12:48:23 -0700
From: "Salz, Rich" <rsalz@akamai.com>
To: Erik Nygren <erik+ietf@nygren.org>, Stephen Farrell <stephen.farrell@cs.tcd.ie>
Thread-Topic: [DNSOP] Re: [TLS] Re: Re: Re: AD review draft-ietf-tls-svcb-ech
Thread-Index: AQHbFlYZWO0opJcCzk+DlGBjro/IyrJ3Ff2AgABJmICAAA4AgIAAAlcA///CbgA=
Date: Fri, 04 Oct 2024 19:48:22 +0000
Message-ID: <6592485B-04E7-4EC5-A92E-F35B3709D835@akamai.com>
References: <CAGL5yWbDFjqxX9JhD6jL=iktamprOWSWjjzGVO1iMTYuADCe0A@mail.gmail.com> <CABcZeBO-d1JdBBoChomponbkqAA=x1YQyMLxmpAZnXmX___MqA@mail.gmail.com> <PH0PR15MB4381A7D9689244A565489331B3762@PH0PR15MB4381.namprd15.prod.outlook.com> <CAFR824y6G6mfWQ4iKMwJoZV7X7oE_xjw-KaLAp4bVaPfi38fBw@mail.gmail.com> <11c797bf-993e-037f-7b9f-6a64947aed75@redbarn.org> <BADE6224-0B10-426F-A381-28D2ED1014FE@broadcom.com> <MW4PR15MB4379D7A2BCD8DDA2D024107BB3702@MW4PR15MB4379.namprd15.prod.outlook.com> <2F26A523-D6D8-44E9-B54D-9C9C7CDD6722@broadcom.com> <65C0B64D-052F-4E58-B462-7C0C4D56DCFF@akamai.com> <CABcZeBPL6FGgRPYg1O_ca_QZ0_obEVRhFZOC-zJy2_4wz6cWeQ@mail.gmail.com> <PH0PR15MB438160E625A016AD9AB898A4B3722@PH0PR15MB4381.namprd15.prod.outlook.com> <CAGL5yWbaW8CaDwpCDNTGdum=zHpZn=MPfygHUWKC0vwqDdxoLA@mail.gmail.com> <a96000f4-4a66-405b-a6a3-8998e6416bcb@cs.tcd.ie> <CAKC-DJhzmtJkPOm9krOUJX_-Hu3creswW=9Qy-kP-QA8LQ+1Bg@mail.gmail.com>
In-Reply-To: <CAKC-DJhzmtJkPOm9krOUJX_-Hu3creswW=9Qy-kP-QA8LQ+1Bg@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.89.24091630
x-originating-ip: [172.27.118.139]
Content-Type: multipart/alternative; boundary="_000_6592485B04E74EC5A92EF35B3709D835akamaicom_"
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1051,Hydra:6.0.680,FMLib:17.12.62.30 definitions=2024-10-04_17,2024-10-04_01,2024-09-30_01
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 malwarescore=0 adultscore=0 bulkscore=0 mlxscore=0 phishscore=0 spamscore=0 mlxlogscore=543 suspectscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2409260000 definitions=main-2410040136
X-Proofpoint-GUID: Th7Eo-kFxDsn90IDt99xz5mZNeNOJVJI
X-Proofpoint-ORIG-GUID: Th7Eo-kFxDsn90IDt99xz5mZNeNOJVJI
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1039,Hydra:6.0.680,FMLib:17.12.60.29 definitions=2024-09-06_09,2024-09-06_01,2024-09-02_01
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 malwarescore=0 clxscore=1011 lowpriorityscore=0 mlxlogscore=372 bulkscore=0 mlxscore=0 suspectscore=0 spamscore=0 adultscore=0 priorityscore=1501 phishscore=0 impostorscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.19.0-2409260000 definitions=main-2410040137
Message-ID-Hash: DV6FSYBWVFJIOSI7HMMJL3BVBDWEXLHS
X-Message-ID-Hash: DV6FSYBWVFJIOSI7HMMJL3BVBDWEXLHS
X-MailFrom: rsalz@akamai.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Paul Wouters <paul.wouters=40aiven.io@dmarc.ietf.org>, Ben Schwartz <bemasc@meta.com>, Eric Rescorla <ekr@rtfm.com>, Arnaud Taddei <arnaud.taddei@broadcom.com>, Paul Vixie <paul@redbarn.org>, "draft-ietf-tls-svcb-ech.authors@ietf.org" <draft-ietf-tls-svcb-ech.authors@ietf.org>, "TLS@ietf.org" <tls@ietf.org>, "dnsop@ietf.org WG" <dnsop@ietf.org>
X-Mailman-Version: 3.3.9rc5
Precedence: list
Subject: [DNSOP] Re: [TLS] Re: Re: Re: AD review draft-ietf-tls-svcb-ech
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/iy1FmKKTr7o242nvdjAZXFRMCQI>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

This is explicitly prohibited rfc9460 as it would provide linkability.

So what?  We’re not the protocol police and if someone wants to track, RFC9460 compliance isn’t going to stop them. Especially for something as controversial as ECH.