Re: [DNSOP] Call for Adoption: draft-arends-private-use-tld
Brian Dickson <brian.peter.dickson@gmail.com> Tue, 16 June 2020 01:51 UTC
Return-Path: <brian.peter.dickson@gmail.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
by ietfa.amsl.com (Postfix) with ESMTP id DAD913A0F79
for <dnsop@ietfa.amsl.com>; Mon, 15 Jun 2020 18:51:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5
tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001,
HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001,
URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key)
header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44])
by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id gJ1MB3vehhMG for <dnsop@ietfa.amsl.com>;
Mon, 15 Jun 2020 18:51:35 -0700 (PDT)
Received: from mail-vk1-xa33.google.com (mail-vk1-xa33.google.com
[IPv6:2607:f8b0:4864:20::a33])
(using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
(No client certificate requested)
by ietfa.amsl.com (Postfix) with ESMTPS id 92F9D3A09BB
for <dnsop@ietf.org>; Mon, 15 Jun 2020 18:51:35 -0700 (PDT)
Received: by mail-vk1-xa33.google.com with SMTP id n22so4421913vkm.7
for <dnsop@ietf.org>; Mon, 15 Jun 2020 18:51:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;
h=mime-version:references:in-reply-to:from:date:message-id:subject:to
:cc; bh=/4xmhJEcEkkwKYzqpVPD3sakPvKZXFuD4BDSufawTdw=;
b=sWcN1GZJnlM/stc7VPIDKaE6etnxglEbOLnSIhwiQMlMogBPbYcPSTceM63AqyjF05
JyPAZOF9TsqJFnJuXd4Q4WrRiYnY/GOcoE6jk+HtV27G8Rmt1P2PsfNe+qYry6H8LKc7
2qC1R39DCcCpL00/MRKEng34pQbhB5/KrS4SUieIjLo+bkryukZYCayxyLDXxsdS20+e
uouYllrruXX4ZV8yJYcElXekoNOHJWyLr+9ps+IbL7SiSFDjGNdjNaK3reX1U0iTf5f4
jHnRr0J6INiA2U3kEyXvK6FcmGkK08Gdmpn7fWcqX2ew4Cbufbl/Zzkn3H6rvbRSvLYQ
UfPQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20161025;
h=x-gm-message-state:mime-version:references:in-reply-to:from:date
:message-id:subject:to:cc;
bh=/4xmhJEcEkkwKYzqpVPD3sakPvKZXFuD4BDSufawTdw=;
b=F7cXBfOaueBwFnCcc6kqrqDRpE5D98NYV0pQehl8q3kWW6Ab4/dmje61jJ6/Gg2gVI
h6IIO4jECTSZqhD6yjfpZEB7MABhIqaMj5dUBtQtnPGGXbnulEFk+OpDOCTUyTS8mQ8C
5YnL/zWr69mrWTb8ERrmu5xeMTuUEQ+Kt6FdmlltRR4prVLRd1y6bsonvrxMLvWoH0Ec
HUSq1CRieOz1UBzozE+RM5EJcInQrvA6Jt9rqyaXAxjYwamjKvA0rnMKle1B3wDlArxs
N2zv/rXT02oNW3RJ4WG+DGdVAG0VWCATx/NybsMz75nxPpswLq8mZH9YnxuSjAHStOiu
aUSQ==
X-Gm-Message-State: AOAM530DP6CXXCbFnJ6wV1U9G8XKYPrlEC62TCtzFkOaJyvatzP0lIDl
XNYp5i6E3KlTszWuIh+gMnrcp6L0nciotdjVcEg=
X-Google-Smtp-Source: ABdhPJz7+p97sE0p3NL+vy192irkTGB2sxPk1boOk14UkaeGqx2W7Qw5kgTb3pgd7/hL5nwSq50rlLIV8hV5wJQyFJ0=
X-Received: by 2002:a1f:4303:: with SMTP id q3mr26916vka.65.1592272294579;
Mon, 15 Jun 2020 18:51:34 -0700 (PDT)
MIME-Version: 1.0
References: <CAH1iCiouFfMRYoREwhhTbQfnNserw3RVUPs8Pzc8CvNEhysYCw@mail.gmail.com>
<20200615174753.225EC1ABFFA1@ary.qy>
<CADyWQ+Em0Qh+TeGudz2Zgx4cEd4AUqKf9CcivotKYUZWyKPCPA@mail.gmail.com>
<2629924.6WoLTOkaPB@linux-9daj>
<alpine.DEB.2.20.2006152244380.28941@grey.csi.cam.ac.uk>
<CAH1iCioLL1dZtMzsXEVPE9SaHR9Hza8MLRRSnKH1eJ8+EW+KEA@mail.gmail.com>
<alpine.DEB.2.20.2006160156000.28941@grey.csi.cam.ac.uk>
<CAH1iCiq9sj-27_=M8Uquby0NAkg4HK+vipcjnzBtQktwgRXdyA@mail.gmail.com>
<alpine.DEB.2.20.2006160222430.28941@grey.csi.cam.ac.uk>
In-Reply-To: <alpine.DEB.2.20.2006160222430.28941@grey.csi.cam.ac.uk>
From: Brian Dickson <brian.peter.dickson@gmail.com>
Date: Mon, 15 Jun 2020 18:51:23 -0700
Message-ID: <CAH1iCipHxbRGjekvxpEOvPhtYFCP6hxUY=OVB-kVgdECD718hA@mail.gmail.com>
To: Tony Finch <dot@dotat.at>
Cc: Paul Vixie <paul@redbarn.org>, John Levine <johnl@taugh.com>,
dnsop <dnsop@ietf.org>, Tim Wicinski <tjw.ietf@gmail.com>
Content-Type: multipart/alternative; boundary="00000000000081142005a829c825"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/ohCgMCutJeFDaL3Cmy0mBUNvRlE>
Subject: Re: [DNSOP] Call for Adoption: draft-arends-private-use-tld
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>,
<mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>,
<mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 16 Jun 2020 01:51:37 -0000
On Mon, Jun 15, 2020 at 6:30 PM Tony Finch <dot@dotat.at> wrote: > Brian Dickson <brian.peter.dickson@gmail.com> wrote: > > - In addition to leaking information, these names generally should > > not have any presence in DNS caches, which makes them excellent > > candidates > > for easy poisoning > > These issues happen in exactly the same way whether you squat on a tld or > use a private subdomain. > Actually, no, or rather, it (susceptibility to poisoning) might depend. Here's why: The root zone is DNSSEC signed with NSEC. It is literally impossible for anyone to poison any name at or below a non-TLD. A private subdomain of a real domain, only has the same properties if the real domain is DNSSEC signed (chained from the root), and the public version of that domain's zone denies the existence of the private subdomain. I.e. that isn't going to be 100% true ever, and today has only a small statistical chance of being true (DNSSEC uptake globally being about 1%). In any case, the argument I'm making is 100% is tautologically optimal, and the best any single enterprise can do is match that. It's likely more reliable and easier to go the non-TLD route for all but the most technically savvy enterprises (who probably won't rely on this document regardless.) Brian
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Shumon Huque
- Re: [DNSOP] Call for Adoption: draft-arends-priva… John Levine
- [DNSOP] Call for Adoption: draft-arends-private-u… Tim Wicinski
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Bob Harold
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Dmitry Belyavsky
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Roy Arends
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Brian Dickson
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Erwin Lansing
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Joe Abley
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Jaap Akkerhuis
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Geoff Huston
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Paul Wouters
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Joe Abley
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Paul Vixie
- Re: [DNSOP] Call for Adoption: draft-arends-priva… John Levine
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Dr Eberhard W Lisse
- Re: [DNSOP] Call for Adoption: draft-arends-priva… John R Levine
- Re: [DNSOP] [Ext] Call for Adoption: draft-arends… Paul Hoffman
- Re: [DNSOP] Call for Adoption: draft-arends-priva… S Moonesamy
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Roy Arends
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Rubens Kuhl
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Michael StJohns
- Re: [DNSOP] [Ext] Call for Adoption: draft-arends… Paul Hoffman
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Paul Wouters
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Michael StJohns
- Re: [DNSOP] Call for Adoption: draft-arends-priva… John Levine
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Wes Hardaker
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Tony Finch
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Brian Dickson
- Re: [DNSOP] Call for Adoption: draft-arends-priva… John Levine
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Tim Wicinski
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Scott Morizot
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Brian Dickson
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Paul Vixie
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Suzanne Woolf
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Wes Hardaker
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Tony Finch
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Paul Wouters
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Paul Vixie
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Tony Finch
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Roy Arends
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Paul Vixie
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Geoff Huston
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Roy Arends
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Tony Finch
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Christian Huitema
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Wes Hardaker
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Roy Arends
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Brian Dickson
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Joe Abley
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Tony Finch
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Brian Dickson
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Tony Finch
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Tony Finch
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Joe Abley
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Brian Dickson
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Tony Finch
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Petr Špaček
- Re: [DNSOP] Call for Adoption: draft-arends-priva… John R Levine
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Mats Dufberg
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Jim Reid
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Mats Dufberg
- Re: [DNSOP] Call for Adoption: draft-arends-priva… John Levine
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Ted Lemon
- Re: [DNSOP] Call for Adoption: draft-arends-priva… John Levine
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Roy Arends
- Re: [DNSOP] Call for Adoption: draft-arends-priva… John R Levine
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Roy Arends
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Warren Kumari
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Dr Eberhard W Lisse
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Petr Špaček
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Paul Vixie
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Robert Mortimer
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Roy Arends
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Ted Lemon
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Paul Wouters
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Joe Abley
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Philip Homburg
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Paul Wouters
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Philip Homburg
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Roy Arends
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Roy Arends
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Ted Lemon
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Vladimír Čunát
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Ted Lemon
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Joe Abley
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Warren Kumari
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Ted Lemon
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Philip Homburg
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Roy Arends
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Tim Wicinski
- Re: [DNSOP] Call for Adoption: draft-arends-priva… Roy Arends