Re: [DNSOP] DNSOP Call for Adoption - draft-west-let-localhost-be-localhost
Ted Lemon <mellon@fugue.com> Thu, 14 September 2017 01:05 UTC
Return-Path: <mellon@fugue.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 518B9132F73 for <dnsop@ietfa.amsl.com>; Wed, 13 Sep 2017 18:05:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fugue-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Xyk0813yP_CL for <dnsop@ietfa.amsl.com>; Wed, 13 Sep 2017 18:05:00 -0700 (PDT)
Received: from mail-pf0-x22a.google.com (mail-pf0-x22a.google.com [IPv6:2607:f8b0:400e:c00::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2D153132F69 for <dnsop@ietf.org>; Wed, 13 Sep 2017 18:05:00 -0700 (PDT)
Received: by mail-pf0-x22a.google.com with SMTP id q76so2758119pfq.2 for <dnsop@ietf.org>; Wed, 13 Sep 2017 18:05:00 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fugue-com.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=X8yVV5c+K0MWZMEI5crtTvnbpV8tE87LE8morYasfcg=; b=pFqeQYkOhTqnFZGMZy6dX4WAfxD6b0EkhbtOBnap0erYKQiNqg7cz990xU+OU68p5d AKNz+Vs2BPi6wkz/MtufaiITsV0oTIT12ny9rirWwm9p2jc7oJAaSZUlBnocV777LAnT ad8Esbb4UBEda/RZ24thg/X+xBYCAE/46Kv0bP6VkF9nENvxJJ18XJTv24rWc1Z/MXyt WW8us/k/p5d6qUbLSi+ithXxRsaz3wQcJePvtWHo1f7FmpwRpYCVsBs3kI3BMWnxkwo2 ReSsr6DTbg+7ylILKDgac42sdx7h/6OnmV6hcjIZZxjJ/yFwR8ICGSqcR5WV4jDdQhvw m63w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=X8yVV5c+K0MWZMEI5crtTvnbpV8tE87LE8morYasfcg=; b=s7uNTxpqDuy9No+74Td5m7ccqNOEeDUUgi6TqQys9BFK59JTWl5QgAM1p0uNw09HYK QGT39zEy3xmtI/0zrVL8hnBB03j0xUEHDbos8h7/8+CEMd7CciAhah+TJMGagO4zXSAp 5mtiK5Zt1YHD4xGkUaYTMNeD9/0l+i875LBPXW4es51SlDT2MHmzIvomz2n630N2Nm3Y PPNFepjnVD7/2ls31uJ8n8h6E8I0H+YRKobJ6VvtYoZmNqF3vunegGBnxhpYPE6LCSyu Myhr4EahXXFBFRd6U2udsTPSHxIoKThYhF2p85XZu16MG4yIRB3972bDThgY4+hoOCpH ivtg==
X-Gm-Message-State: AHPjjUgFAdKB/r/JsQ4XIXJeez/HTfnbie1Fjxk1co5hUwnCXZUw9xfe dyc1ApONpfA0+K+KbOVGWQn01lXpb5IzLvdboNTKkg==
X-Google-Smtp-Source: AOwi7QDemdmUa9XfOQ4QPOM8raTpe2yaFAgR1LiCKJSQeyk2Wk3Uv+UCYKIFLbzCkMHRQ+d9b0QHUvNGi990ScaLjvw=
X-Received: by 10.101.67.137 with SMTP id m9mr476182pgp.63.1505351099758; Wed, 13 Sep 2017 18:04:59 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.100.152.98 with HTTP; Wed, 13 Sep 2017 18:04:58 -0700 (PDT)
Received: by 10.100.152.98 with HTTP; Wed, 13 Sep 2017 18:04:58 -0700 (PDT)
In-Reply-To: <20170914005446.DA4C1859D924@rock.dv.isc.org>
References: <20170913171915.1194.qmail@ary.lan> <714677EA-E3C8-4145-825C-5BA8EABD018C@fugue.com> <20170914005446.DA4C1859D924@rock.dv.isc.org>
From: Ted Lemon <mellon@fugue.com>
Date: Wed, 13 Sep 2017 21:04:58 -0400
Message-ID: <CAPt1N1kAGrm6DXJty8xfm1P8ZEutD+7C1o=CmdnFEdSMrXmXOw@mail.gmail.com>
To: Mark Andrews <marka@isc.org>
Cc: dnsop WG <dnsop@ietf.org>
Content-Type: multipart/alternative; boundary="089e08200b64904c6905591bdd1f"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/n5QOXQjYAY3v7agslubLPJepe9g>
Subject: Re: [DNSOP] DNSOP Call for Adoption - draft-west-let-localhost-be-localhost
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Sep 2017 01:05:02 -0000
You've made your position clear, thanks. On Sep 13, 2017 20:54, "Mark Andrews" <marka@isc.org> wrote: > > In message <714677EA-E3C8-4145-825C-5BA8EABD018C@fugue.com>, Ted Lemon > writes: > > > > On Sep 13, 2017, at 1:19 PM, John Levine <johnl@taugh.com> wrote: > > > I concur with Mark that while localhost.<foo> is a problem, > > > <foo>.localhost is not. I've occasionally used that hack to pass > > > traffice to various servers running on 127/8 addresses other than > > > 127.0.0.1. > > > > So we should expose end-users to attack because it's "occasionally" = > > convenient for you to do this hack? > > The biggest problem is that HTTP says that hostnames in URLs may > be relative. Close that grand canyon sized security hole. There > is zero need for relative names in URL's in html documents, email > etc. There is some need for them in address bars but that is UI. > What goes over the wire should be treated as absolute, always. > > Treat "localhost" as always being absolute. No searching if that > is the entered hostname. Yes, this will break somethings that > depend on searching to find localhost.*. It is the one hangover > from the flat global namespace we still have. > > Have public DNS return unsigned NODATA for localhost (qtype != SOA, > NS, DS) and signed NODATA for localhost DS. > > getaddrinfo() et al. is still free to hardcode localhost -> (::1, > 127.0.0.1) if the implementation wants to. Make it a requirement > for *browsers* (includes curl, fetch, lynx etc.) to do this if you > want. > > Recommend that recursive servers have a "localhost." zone with ::1 > and 127.0.0.1 for "localhost." built in by default. > > You don't need to sabatage the DNS. > > Mark > -- > Mark Andrews, ISC > 1 Seymour St., Dundas Valley, NSW 2117, Australia > PHONE: +61 2 9871 4742 INTERNET: marka@isc.org >
- [DNSOP] DNSOP Call for Adoption - draft-west-let-… tjw ietf
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Ted Lemon
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Richard Barnes
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… tjw ietf
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Ted Lemon
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Tony Finch
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Warren Kumari
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Jacob Hoffman-Andrews
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Mark Andrews
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Ted Lemon
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Mark Andrews
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Ted Lemon
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Mark Andrews
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Ted Lemon
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Mark Andrews
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Ted Lemon
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… John Levine
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Warren Kumari
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… 神明達哉
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Wes Hardaker
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Tony Finch
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Peter van Dijk
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Paul Vixie
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Tony Finch
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Richard Barnes
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… John R Levine
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… John Levine
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Joe Abley
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… John R Levine
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Mark Andrews
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… John Levine
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Paul Vixie
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Ted Lemon
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Mark Andrews
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Ted Lemon
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Peter van Dijk
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… John Levine
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Matthew Pounsett
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… John Levine
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Wes Hardaker
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Ted Lemon
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Ted Lemon
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Mark Andrews
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Ted Lemon
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Lanlan Pan
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Peter van Dijk
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… =JeffH
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Wendy Seltzer
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Warren Kumari
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Jacob Hoffman-Andrews
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… Petr Špaček
- Re: [DNSOP] DNSOP Call for Adoption - draft-west-… tjw ietf