Re: [Doh] Goals of DOH

Ted Lemon <mellon@fugue.com> Tue, 24 April 2018 00:27 UTC

Return-Path: <mellon@fugue.com>
X-Original-To: doh@ietfa.amsl.com
Delivered-To: doh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4B44412DB6B for <doh@ietfa.amsl.com>; Mon, 23 Apr 2018 17:27:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.611
X-Spam-Level:
X-Spam-Status: No, score=-2.611 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, T_DKIMWL_WL_MED=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fugue-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tHvCQ0NHbfjN for <doh@ietfa.amsl.com>; Mon, 23 Apr 2018 17:27:10 -0700 (PDT)
Received: from mail-qk0-x22a.google.com (mail-qk0-x22a.google.com [IPv6:2607:f8b0:400d:c09::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4434912DA6B for <doh@ietf.org>; Mon, 23 Apr 2018 17:27:10 -0700 (PDT)
Received: by mail-qk0-x22a.google.com with SMTP id v2so18009684qkh.10 for <doh@ietf.org>; Mon, 23 Apr 2018 17:27:10 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fugue-com.20150623.gappssmtp.com; s=20150623; h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=/fDJv0vgJTdJahlenA8TMYQ3jPYcRLCia7SFF4Jtfzw=; b=0LfvwDclATkkh/6AIZWVP4upbW1aOuSTBgDOTW3wCNkKdF5cgYOfGJxRaHlIL+HjSo hW4y2S1ZFTQ1HxlospxoiJuOH4yYV1254POadADETdJJAKRxXBwY3Ydf5qqbNPlEwnDv JVaj4oV/+wmMtBnU4G/dftR4wHSaknWa/IbBfahKw/cMUSwLeiV5EqR9bFCoh/B8EMfS odK8el/k/C3hquunF900ldYBzyou+Ciz+ucGwXwMehRceSrHFANQNYmjnpHNi3WR8ion G85q/5WlYjlE5Zw6sHdBH8+PaQaVsG4UwRKwS4jmsRLK1q28YtOvtrkfFnGBIej1xMLQ jGfA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=/fDJv0vgJTdJahlenA8TMYQ3jPYcRLCia7SFF4Jtfzw=; b=mBImTJ2wO4OWlBOnN0E/AnB6wyvAT+SNpYAhAj24SjKT5jEoGFK1ahfYCVlMundX3P pEX06bdEAwmx2g8AbdTyOuRr+w8Fb2MlHuyy8lUNoOq4iW+qfSSUf6rlOdxmb3yjCFx9 ax6FhWAYy1dPVWWAt/GnpSOzJ42hUzspufu7mgxRKPxz6SJOubUf1k7EIXBCfdPGaBhq WjWMbep2owSJY+1yKL6PkUiV7fzf8yARWY877UskOEz6GnHx7hxb3hOIMEnbJZ3MnVhG ShCAwZp+jYy8xiphSPaAXBLTis6ncy3IFfrOi6BP2ruCS9noSf2/CS1Ykp+ikIT5leev 0Xjw==
X-Gm-Message-State: ALQs6tCmwCdh1fYqEm385HwqraYeec22x2mXjmNBhO928aJkqsbMMpyw a3EA92EWm9B+uOgGXB2AwCC1ssDgzgo=
X-Google-Smtp-Source: AIpwx49OOB+t++DutzrlP9cZmsVo5yo7U/IdIOLkgomDPlbZm5nohQTPYaGHBH2EXP5RPwWSN3qLww==
X-Received: by 10.55.22.66 with SMTP id g63mr24583012qkh.294.1524529629405; Mon, 23 Apr 2018 17:27:09 -0700 (PDT)
Received: from cavall.lan (c-24-60-163-103.hsd1.ma.comcast.net. [24.60.163.103]) by smtp.gmail.com with ESMTPSA id e23-v6sm10951477qtp.6.2018.04.23.17.27.08 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 23 Apr 2018 17:27:08 -0700 (PDT)
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 11.3 \(3445.6.18\))
From: Ted Lemon <mellon@fugue.com>
In-Reply-To: <AD8D65FE-E2AE-4922-B6E0-98BC0C295C2D@icann.org>
Date: Mon, 23 Apr 2018 20:27:07 -0400
Cc: DoH WG <doh@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <88005194-4B09-4682-BE0A-0085EFF5A338@fugue.com>
References: <f17cbdf0-cd88-9fa9-c83d-26e2cf13b8c1@o2.pl> <21B4DD30-46B0-4E63-833E-FDE66EF28F95@icann.org> <765e9e5a-9b8c-fa1c-85b5-da824807e609@o2.pl> <CAOdDvNrC6VGQtCYgLOoRvwCGn0kRJuchncFj4m5r_KZ-ig7=NA@mail.gmail.com> <28678acd-f67d-7f95-273f-26ed1115d3ee@o2.pl> <75B0BB57-A222-4328-A155-E5C351DEB7CC@icann.org> <3457562c-5576-18ea-a764-d485d870b5ea@o2.pl> <CAOdDvNqft5RwHcf1Ds-nzCZ=ha1weBTwbP4KzMLoHHwJQt0bVQ@mail.gmail.com> <46145a1e-99a9-405f-9f5c-4b85005feaf9@o2.pl> <BFBE3B13-15DF-45D5-8E8A-A4DC5B476357@icann.org> <CAHbrMsBHV5z5oNJrTvmvAPO79PRSufgGSY_NFePz34xNX4R+vQ@mail.gmail.com> <BF72EBFC-ACFB-49BE-BE7F-5F1AA81E73B0@bangj.com> <302013A3-DA11-4398-A226-64939FC4DA46@icann.org> <978B235F-9700-43DB-833B-C1AA02438E52@bangj.com> <5B2F997F-E5DF-4A97-B73B-2EC699113898@fugue.com> <AD8D65FE-E2AE-4922-B6E0-98BC0C295C2D@icann.org>
To: Paul Hoffman <paul.hoffman@icann.org>
X-Mailer: Apple Mail (2.3445.6.18)
Archived-At: <https://mailarchive.ietf.org/arch/msg/doh/4MKh1vcCWOAEVpGWXbBsACXWmbc>
Subject: Re: [Doh] Goals of DOH
X-BeenThere: doh@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: DNS Over HTTPS <doh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/doh>, <mailto:doh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/doh/>
List-Post: <mailto:doh@ietf.org>
List-Help: <mailto:doh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/doh>, <mailto:doh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 24 Apr 2018 00:27:12 -0000

On Apr 23, 2018, at 6:06 PM, Paul Hoffman <paul.hoffman@icann.org> wrote:
> Can you point to the part of the draft (which is in WG Last Call) where it says that? If so, I promise to fix it because that is not an intended goal.

From the WG Charter:

The primary focus of this working group is to develop a mechanism that
provides confidentiality and connectivity between DNS clients (e.g., operating
system stub resolvers) and recursive resolvers. 

From the document's introduction:

   Two primary uses cases were considered during this protocol's
   development.  They included preventing on-path devices from
   interfering with DNS operations and allowing web applications to
   access DNS information via existing browser APIs in a safe way
   consistent with Cross Origin Resource Sharing (CORS) [CORS].  There
   are certainly other uses for this work.

The first of these two use cases is to subvert the intentions of the network operator. Providing confidentiality and connectivity is as well.   Of course, a less provoking way of saying what I said might be "to prevent abuse by network operators," but it's kind of a toss-up.

Anyway, if you think this is not the goal of the document, there may be some kind of communication problem here to resolve... :)