From nobody Fri Nov 12 09:01:35 2021
Return-Path: <pspacek@isc.org>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id CB8163A156F
 for <dnsop@ietfa.amsl.com>; Fri, 12 Nov 2021 09:01:27 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.449
X-Spam-Level: 
X-Spam-Status: No, score=-5.449 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
 DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, NICE_REPLY_A=-3.33,
 RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_NONE=0.001,
 SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key)
 header.d=isc.org header.b=XEdQ/AIN;
 dkim=pass (1024-bit key)
 header.d=isc.org header.b=d7kqJN09
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id k5D8hJjzEzv1 for <dnsop@ietfa.amsl.com>;
 Fri, 12 Nov 2021 09:01:22 -0800 (PST)
Received: from mx.pao1.isc.org (mx.pao1.isc.org [149.20.64.53])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 32B1B3A120F
 for <dnsop@ietf.org>; Fri, 12 Nov 2021 09:00:35 -0800 (PST)
Received: from zimbrang.isc.org (zimbrang.isc.org [149.20.1.12])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
 (Client did not present a certificate)
 by mx.pao1.isc.org (Postfix) with ESMTPS id 82C4A4344F7;
 Fri, 12 Nov 2021 17:00:34 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=isc.org; s=ostpay;
 t=1636736434; bh=IZwc5t8SvLqJbqkW/y9wxlzx2zAUALudS9c1UlCCokU=;
 h=Date:To:References:Cc:From:Subject:In-Reply-To;
 b=XEdQ/AINyhL/An3fExk1oBvSp87U1ZWVmfblE0HBMrQVJ1TtOd76jdB29WeWMIZbc
 H9PZxe2kl0f+FCTu9vM3pIK9Qten7e7C4ONcJKm62qNkKrjaap31Rh1g45K5NMXkfI
 EM076GE8itd1caSfLCr1fJgfrqPgHYPYnqL+mItI=
Received: from zimbrang.isc.org (localhost.localdomain [127.0.0.1])
 by zimbrang.isc.org (Postfix) with ESMTPS id 7405AF064BF;
 Fri, 12 Nov 2021 17:00:34 +0000 (UTC)
Received: from localhost (localhost.localdomain [127.0.0.1])
 by zimbrang.isc.org (Postfix) with ESMTP id 4994DF09E71;
 Fri, 12 Nov 2021 17:00:34 +0000 (UTC)
DKIM-Filter: OpenDKIM Filter v2.10.3 zimbrang.isc.org 4994DF09E71
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=isc.org;
 s=05DFB016-56A2-11EB-AEC0-15368D323330; t=1636736434;
 bh=MrCjY+8x7mnRFjCrrN+TObjw8oQFW+kxET4mYn43ASI=;
 h=Message-ID:Date:MIME-Version:To:From;
 b=d7kqJN09ViYs9ZL4kbAwszW0UAs+SNlJIPfWg2Szz3r4LWWlK/v/PX46MctyXDp+N
 JbQG+rpUMmdOXYDTpp9I5W0W9a/BaQS6IwVgtecPIBV0Ub/Y6dKsFf5HAOaI/8lPSv
 vzn1nHs/s/tNmIBHkpJwTb9XwVp7qG4j6EX4VqnQ=
Received: from zimbrang.isc.org ([127.0.0.1])
 by localhost (zimbrang.isc.org [127.0.0.1]) (amavisd-new, port 10026)
 with ESMTP id 7l7nLem7fIcM; Fri, 12 Nov 2021 17:00:34 +0000 (UTC)
Received: from [192.168.0.157] (ip-86-49-254-49.net.upcbroadband.cz
 [86.49.254.49])
 by zimbrang.isc.org (Postfix) with ESMTPSA id F3C53F064BF;
 Fri, 12 Nov 2021 17:00:32 +0000 (UTC)
Message-ID: <5193d399-859a-ef45-2dff-e1c112adc0e4@isc.org>
Date: Fri, 12 Nov 2021 18:00:30 +0100
MIME-Version: 1.0
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101
 Thunderbird/91.3.0
Content-Language: en-US
To: dnsop@ietf.org, Ben Schwartz <bemasc@google.com>,
 Eric Orth <ericorth@google.com>, Eric Rescorla <ekr@rtfm.com>
References: <D1CF0779-EAB3-4759-8F50-643E9EC8C490@gmail.com>
 <d7f55c0d-0746-9c74-2ff1-ebdcec7ad45e@isc.org>
Cc: Daniel Kahn Gillmor <dkg@fifthhorseman.net>, Dan Wing <danwing@gmail.com>
From: =?UTF-8?B?UGV0ciDFoHBhxI1law==?= <pspacek@isc.org>
In-Reply-To: <d7f55c0d-0746-9c74-2ff1-ebdcec7ad45e@isc.org>
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/op9hcM_1W9VgVj_r5mwgA1WhAiE>
Subject: Re: [DNSOP] updated to draft-wing-dnsop-structured-dns-error-page-01
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>,
 <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>,
 <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 12 Nov 2021 17:01:33 -0000

Hello everyone,

let me try to to restart the discussion about "Structured Data for=20
Filtered DNS" draft. See below.

On 14. 10. 21 19:36, Dan Wing wrote:
 > We recently published -01 of Structured Data for Filtered DNS based=20
on WG feedback from IETF 111.  We also incorporated both motivational=20
and normative text from draft-reddy-dnsop-error-page.  New version at:=20
https://datatracker.ietf.org/doc/html/draft-wing-dnsop-structured-dns-err=
or-page-01

On 10. 11. 21 17:17, Petr =C5=A0pa=C4=8Dek wrote:
> Let's=C2=A0start=C2=A0from=C2=A0the=C2=A0hardest=C2=A0questions:
>=20
> 1.=C2=A0Input=C2=A0from=C2=A0browser=C2=A0vendors
> -----------------------------
> I believe we really really _really_ need input from end-client vendors,=
=20
> most importantly Google Chrome and Safari. Is there any indication that=
=20
> they=C2=A0might=C2=A0be=C2=A0interested?=C2=A0If=C2=A0not,=C2=A0why?
>=20
> In my experience browser people have much better idea about UX design=20
> and HTTP ecosystem security than we DNS people do, and they might have=20
> different requirements on the data we plan to send back to clients, or=20
> reasons=C2=A0why=C2=A0the=C2=A0idea=C2=A0cannot=C2=A0be=C2=A0implemente=
d=C2=A0in=C2=A0browsers=C2=A0as=C2=A0is.

I'm CCing known Google and Mozilla people on this e-mail. Please kindly=20
ask Safari people if you know any to contribute here as well.


So, to really start again, I think we need to make step back and ask=20
what browsers are willing to work with.

Currently the user experience with any sort of blocking follows.

This is what user sees if:
- blocking is done via forged NXDOMAIN
- the the site has a DNS outage
- there is a typo in the domain name

Chromium:
> This site can=E2=80=99t be blockedsite.example=E2=80=99s server IP addr=
ess could not be found.
> Try:
> Checking the connection
> Checking the proxy, firewall, and DNS configuration
> ERR_NAME_NOT_RESOLVED

Firefox:
> Hmm. We=E2=80=99re having trouble finding that site.
>=20
> We can=E2=80=99t connect to the server at blockedsite.example.
>=20
> If that address is correct, here are three other things you can try:
>=20
>     Try again later.
>     Check your network connection.
>     If you are connected but behind a firewall, check that Firefox has =
permission to access the Web.

Safari:
> Safari Can't Find the Server
> Safari can't open the page "blockedsite.example" because Safari can't f=
ind the server "blockedsite.example".


This is what happens if blocking is done with forged A RR answer=20
pointing to a web server serving "this is blocked" web page:

Chromium:
> Your connection is not private
> Attackers might be trying to steal your information from blockedsite.ex=
ample (for example, passwords, messages, or credit cards). Learn more
> NET::ERR_CERT_COMMON_NAME_INVALID

Firefox:
> Warning: Potential Security Risk Ahead
>=20
> Firefox detected a potential security threat and did not continue to bl=
ockedsite.example. If you visit this site, attackers could try to steal i=
nformation like your passwords, emails, or credit card details.
>=20
> What can you do about it?
>=20
> The issue is most likely with the website, and there is nothing you can=
 do to resolve it. You can notify the website=E2=80=99s administrator abo=
ut the problem.

Safari:
> This Connection Is Not Private
> This website may be impersonating "blockedsite.example" to steal you pe=
rsonal or financial information. You should go back to the previous page.


Finally, The Question for web browser vendors is:
Do you have an interest in improving this user experience?

If the answer is yes, what extra information from the resolver you need?

Thank you for your time.

--=20
Petr =C5=A0pa=C4=8Dek

