Re: [dnssd] Reviewing DNS-SD privacy issues

Christian Huitema <huitema@huitema.net> Mon, 15 January 2018 00:47 UTC

Return-Path: <huitema@huitema.net>
X-Original-To: dnssd@ietfa.amsl.com
Delivered-To: dnssd@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3FDEA12D854 for <dnssd@ietfa.amsl.com>; Sun, 14 Jan 2018 16:47:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.1
X-Spam-Level:
X-Spam-Status: No, score=0.1 tagged_above=-999 required=5 tests=[BAYES_50=0.8, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nTZhMYgTMPQv for <dnssd@ietfa.amsl.com>; Sun, 14 Jan 2018 16:47:32 -0800 (PST)
Received: from mx43-out1.antispamcloud.com (mx43-out1.antispamcloud.com [138.201.61.189]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 90E4F126DED for <dnssd@ietf.org>; Sun, 14 Jan 2018 16:47:32 -0800 (PST)
Received: from xsmtp02.mail2web.com ([168.144.250.215]) by mx12.antispamcloud.com with esmtps (TLSv1:AES256-SHA:256) (Exim 4.89) (envelope-from <huitema@huitema.net>) id 1easvx-0001xf-JY for dnssd@ietf.org; Mon, 15 Jan 2018 01:47:30 +0100
Received: from [10.5.2.35] (helo=xmail10.myhosting.com) by xsmtp02.mail2web.com with esmtps (TLS-1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.63) (envelope-from <huitema@huitema.net>) id 1easvq-0007Lg-Hf for dnssd@ietf.org; Sun, 14 Jan 2018 19:47:26 -0500
Received: (qmail 11697 invoked from network); 15 Jan 2018 00:47:21 -0000
Received: from unknown (HELO [192.168.200.68]) (Authenticated-user:_huitema@huitema.net@[72.235.171.77]) (envelope-sender <huitema@huitema.net>) by xmail10.myhosting.com (qmail-ldap-1.03) with ESMTPA for <dnssd@ietf.org>; 15 Jan 2018 00:47:21 -0000
To: dnssd@ietf.org
References: <4b8fad55-b283-e0fc-4af1-7fcfa4603193@huitema.net> <CABkgnnVLiYy1Rv3DTMHn0xsVLyU8s1KfZwa_YLz7a-BWY_r2=Q@mail.gmail.com>
From: Christian Huitema <huitema@huitema.net>
Message-ID: <4f9f4425-1482-b94a-4f7f-1c43974874c1@huitema.net>
Date: Sun, 14 Jan 2018 14:47:20 -1000
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.8.0
MIME-Version: 1.0
In-Reply-To: <CABkgnnVLiYy1Rv3DTMHn0xsVLyU8s1KfZwa_YLz7a-BWY_r2=Q@mail.gmail.com>
Content-Type: text/plain; charset="windows-1252"
Content-Transfer-Encoding: quoted-printable
X-Originating-IP: 168.144.250.215
X-AntiSpamCloud-Domain: xsmtpout.mail2web.com
X-AntiSpamCloud-Username: 168.144.250.0/24
Authentication-Results: antispamcloud.com; auth=pass smtp.auth=168.144.250.0/24@xsmtpout.mail2web.com
X-AntiSpamCloud-Outgoing-Class: unsure
X-AntiSpamCloud-Outgoing-Evidence: Combined (0.25)
X-Recommended-Action: accept
X-Filter-ID: EX5BVjFpneJeBchSMxfU5gaFm2KB0DmVtOm1/jvydDgXv9krsgRhBn0ayn6qsUc7oeDwbaJnZ2Ta Zhv/Bk6d8K1PdOWeIW8R8TgUu5HhPnKRoMYKnfuB7zSI/MJgyXiQTGulXfuaNr1V9B1E4+3dI3nk BRYAruZ5hO/GfxnCDKdWynZUxsMC1E3ExQzsigr+jj0HlFDoqoWF20+xKQ35+nd/nGlMBQ0xDQkm A/S/XltWjP649SQzhF817kql58kAx71HfxpF/K3Kf4qEIfLm3dpo8E55I3oL4X/9gaBZfvr6VL1B tSX2x7FdoqxZLLNInsq4c1pop2DuIERl592w1UzGVaY28QIxbnHhmVmUg//xFvReUB/vUq9cRUSN fRacYvJxnE2uvPYPCbpmnXes/ii2IAbWxB6xZ+NuqELn3pmRVYKU9W9tbmVXJBqdHHDm4W04ooUi IegHnDOOrq+/aMk+XoreKQ2SPH1UIIzo7c35l4zT/9O3Fa5t/wfTM8Lj3qPsymJWvDwykKJqs6rg CShtfWEBSErP+Z0pzyRxh9Lh9PobrbwB1Jj4vRnvuFdQKx3Zprq3ZEpafGy+zLjUntilh9dvYvV/ 5Pg3UZt3l4cobM5+AwD0A5qDgSPsXJ3GYnRqIO2TPU1F0bSG6T2DJZnHEeB4hpRrmo/duzUUp/K9 ZRlGTBNbjFFp2EGWMpOZ6Fd7qWsQvIr61TrKdKGtuHLYM3A6BXfvel8OEFDbU529jj6VuEkkQiOd 2CLFCAI+G45OmBNdsUklj47JM2Zh1oj2lB9TLiDMfXuvSrucRXry8B6sEcpHNQcjlAOoToGvpsib JQz6bCR19sO/++nnSqCDBedeB75TJ0VuxRY+unEnaeycva4NRXu2m3j3Y8zB9xGo0bndvIE+SDBs cm+vLiZuZ5OAUoGBziSYFLZuu6wTRhJez+ibxiREoUwadL3g
X-Report-Abuse-To: spam@quarantine5.antispamcloud.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnssd/Cvth2Mqy9Ii9mkLFbG7JNe0r-N0>
Subject: Re: [dnssd] Reviewing DNS-SD privacy issues
X-BeenThere: dnssd@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "Discussion of extensions to DNS-based service discovery for routed networks." <dnssd.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnssd>, <mailto:dnssd-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnssd/>
List-Post: <mailto:dnssd@ietf.org>
List-Help: <mailto:dnssd-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnssd>, <mailto:dnssd-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 15 Jan 2018 00:47:34 -0000


On 1/1/2018 2:11 PM, Martin Thomson wrote:
> I agree with your analysis regarding granularity.  Particularly on
> mobile platforms, mutual distrust between applications is the
> benchmark we want to apply.  Browsers are already there.

I have entered three issues in GitHub to keep track of various ideas
regarding the three points: granularity of trust, type of trust token,
and pairing algorithm:

* https://github.com/huitema/dnssdprivacy/issues/7: Granularity of trust

* https://github.com/huitema/dnssdprivacy/issues/8: Scaling issues with
different kinds of trust tokens

* https://github.com/huitema/pairing/issues/1: Users might press OK
without actually looking at the SAS

You are all welcome to add your own comments on these issues, or of
course on the mailing list if you prefer.

-- Christian Huitema