Re: [dnsoverhttp] New draft: draft-hoffman-dns-over-http-00.txt

Martin Thomson <martin.thomson@gmail.com> Thu, 22 September 2016 01:24 UTC

Return-Path: <martin.thomson@gmail.com>
X-Original-To: dnsoverhttp@ietfa.amsl.com
Delivered-To: dnsoverhttp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 82D0F12B98F for <dnsoverhttp@ietfa.amsl.com>; Wed, 21 Sep 2016 18:24:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level:
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qQfN6vwFsDTO for <dnsoverhttp@ietfa.amsl.com>; Wed, 21 Sep 2016 18:24:30 -0700 (PDT)
Received: from mail-qk0-x235.google.com (mail-qk0-x235.google.com [IPv6:2607:f8b0:400d:c09::235]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5090912B8DF for <dnsoverhttp@ietf.org>; Wed, 21 Sep 2016 18:24:24 -0700 (PDT)
Received: by mail-qk0-x235.google.com with SMTP id n185so63346118qke.1 for <dnsoverhttp@ietf.org>; Wed, 21 Sep 2016 18:24:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=eLWJ1cq6k33TjSOFqK26bq0SrnC6yYbikkJUjs3qKo8=; b=NdZrJ3XJaq6lHcAD3rnVt2/OTGTEdjeh1PUWc0L//HzU5dTW7Q8KzclZrE1vOsPHgB a8k5j1mturoYqCopmsmWPdEgQmk6NxUsuK5H8sgblcfIZiCrj1YRNOljg/WdSnZKtwx1 DxiezYHMrjFNPsQ+up++9NJMGqBHOZJP+/JffatTr9W/6jq4hb+gBKoJ/cH7cOfIDKe2 AEb2cLgCbKL7gW+rdbu1tQKYQAlntI35F9is9xe6LgsRCxhwllzMY/zJrvNh0YNYPQeC BTspPwjW6rKWgbCoK39GRSrTJS+/wpvZTPDgh9aIY9GfBmf8TQ4petSdd7He5Fn1RalK Bl0g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=eLWJ1cq6k33TjSOFqK26bq0SrnC6yYbikkJUjs3qKo8=; b=Q4uIa4+GgpVsSX/LVIVU+v/+sYTz7g2EDgv+fRkVzjwyEV+lhvvgylAUY0+SENMW7T PupRRbd7eV3m+IrCE1DwFp17J/Jjss+RjH4/rbS0FEBam5zGFsSAOj4yOvFcpEihDqrG kBOIIO5/PKqzZ5GSBCvxRzxTxbOhToCKO8z94EjNA4KqiREi9Ms8wthvND0GJFHoh0Hf /QBd3ckGltlKuKR9GytqL7IJOUyPtvCic5+27Y8Pv9DvwcVfyt1nYASxM0PUPk2rex3F V18PqDx0tjLnvWKOhbCks/ENQUokY3kq1E/8S+vaNsnWCP2uLD/vptdTV6nJtWRxq5sr mVvQ==
X-Gm-Message-State: AE9vXwMeaajWc4z4mrsGMV1XMRlTKW5kRqkec14uBS4mNOlFqEa46Q1eGVIq4Hwi9oll3pEtxk4be6lVxpP9sA==
X-Received: by 10.55.113.197 with SMTP id m188mr43114273qkc.55.1474507463552; Wed, 21 Sep 2016 18:24:23 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.140.22.146 with HTTP; Wed, 21 Sep 2016 18:24:22 -0700 (PDT)
In-Reply-To: <CA+9kkMBx=5GHrm5ogJRTXRwi6dGe3=VxH-mUW0pjc3MXfqPpow@mail.gmail.com>
References: <147438228195.28999.4355943522486567954.idtracker@ietfa.amsl.com> <D1E3CC44-FE5A-4ACE-90A1-EF9B5EE975D7@icann.org> <CA+9kkMATL4RVv=RCmS0nqks2OWB1aQSeNcZ_-zyqHBnv5eYmLg@mail.gmail.com> <AF616D4B-A22B-4CB7-AD20-29B4E6107276@icann.org> <CA+9kkMCsX9=+uWmAAydW5yuda_Jzs+qX6MBZBq0ztQKOsEDndQ@mail.gmail.com> <14CE5326-52FD-405F-A17F-1BBE5FC32929@icann.org> <CA+9kkMBqN8Y-h27C7Cde4omO9jLsYpvhsyieFfG9YyS9+K_j9g@mail.gmail.com> <CABkgnnUnKezkspqFBW4JFaQr2q4=BmUTwy3MWEtF62rt_TvCRQ@mail.gmail.com> <CA+9kkMBx=5GHrm5ogJRTXRwi6dGe3=VxH-mUW0pjc3MXfqPpow@mail.gmail.com>
From: Martin Thomson <martin.thomson@gmail.com>
Date: Thu, 22 Sep 2016 11:24:22 +1000
Message-ID: <CABkgnnWSRP=9GxK74O2Z4mE_Hu55snxtg-vTZoQ_K3hvnmO4qQ@mail.gmail.com>
To: Ted Hardie <ted.ietf@gmail.com>
Content-Type: text/plain; charset=UTF-8
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsoverhttp/TaSrnsfHs2PQWrT8i6nGdL5m_Oo>
Cc: "dnsoverhttp@ietf.org" <dnsoverhttp@ietf.org>, Paul Hoffman <paul.hoffman@icann.org>
Subject: Re: [dnsoverhttp] New draft: draft-hoffman-dns-over-http-00.txt
X-BeenThere: dnsoverhttp@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Discussion of DNS over HTTP <dnsoverhttp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsoverhttp>, <mailto:dnsoverhttp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsoverhttp/>
List-Post: <mailto:dnsoverhttp@ietf.org>
List-Help: <mailto:dnsoverhttp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsoverhttp>, <mailto:dnsoverhttp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 22 Sep 2016 01:24:31 -0000

On 22 September 2016 at 03:21, Ted Hardie <ted.ietf@gmail.com> wrote:
> You'll get a different answer if you make another request using a different
> method or DNS API server.

Well, you might assume that the last response is the best, otherwise
we're into the whole "man with two clocks" paradigm of protocol
engineering.  The point I was trying to make being that if you don't
trust a particular server to provide you an answer that is generally
usable, then ask a server you do trust to that end.

Sure, the answers might be different, but the worst outcome I can
currently imagine is bad routing.  That is, assuming the next thing
you do is authenticate as all good boys and girls have been taught to
do.