Re: [Doh] [Ext] Re: Use cases and URLs

Andrew Sullivan <> Wed, 07 March 2018 22:20 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id AE39612D95A for <>; Wed, 7 Mar 2018 14:20:42 -0800 (PST)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (1024-bit key) header.b=KnKdixtQ; dkim=pass (1024-bit key) header.b=fqoEmVeh
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id ku8iWJV1CWML for <>; Wed, 7 Mar 2018 14:20:41 -0800 (PST)
Received: from ( []) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 375E412D959 for <>; Wed, 7 Mar 2018 14:20:40 -0800 (PST)
Received: from localhost (localhost []) by (Postfix) with ESMTP id 9A2F0BE780 for <>; Wed, 7 Mar 2018 22:20:39 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=default; t=1520461239; bh=/pzd0u6EmxPiC2I+x4cBoY7FQgCuXDtsPektHyV80KA=; h=Date:From:To:Subject:References:In-Reply-To:From; b=KnKdixtQre5EMe7EOQaEtqM0PqIFSrcOgS9uxaeNvgRYlIk4QdeyxopMEwxRAmgiG qZiiMgGCkyUkWiXbVsafO9wcxhv/kwr3Ks7XqhB2YEsyAN6FLu/MvBAEmOniMto/v9 TaAbrWhIY0v8dWc0T1i49IH7aWu+UA/WybKwPots=
X-Virus-Scanned: Debian amavisd-new at
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id XlgOhTuBR-iC for <>; Wed, 7 Mar 2018 22:20:38 +0000 (UTC)
Date: Wed, 7 Mar 2018 17:20:35 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=default; t=1520461238; bh=/pzd0u6EmxPiC2I+x4cBoY7FQgCuXDtsPektHyV80KA=; h=Date:From:To:Subject:References:In-Reply-To:From; b=fqoEmVehSm9+xLr8YRAKM0gy8xbk9PHma7dnmsKu93zCHxgJjg/qNMjRE9H0vgAeU pkMsGPu6xPH0LfxKnmVgFzaOkoVbE5qGYGBDD/8FNeqkJ0/TBzXpRvnU1uJ7h1PSdy 4opjotP7x4liMb0G5STNdw/klwSnnfYrCsELMwwM=
From: Andrew Sullivan <>
Message-ID: <>
References: <> <> <> <> <>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <>
Archived-At: <>
Subject: Re: [Doh] [Ext] Re: Use cases and URLs
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: DNS Over HTTPS <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Wed, 07 Mar 2018 22:20:43 -0000


On Wed, Mar 07, 2018 at 09:30:06PM +0000, Paul Hoffman wrote:
> On Mar 7, 2018, at 1:41 AM, Mark Nottingham <> wrote:
> > 
> > Is making it super-easy for non-technical end users to configure a new DNS server a feature or a bug?
> It has been considered a feature for as long as there has been an Internet. That is, every operating system allows users to do this in the operating system. Why should browsers be different?

I think I agree with Paul's sentiment there, but I am pretty sure I
disagree with his glib description of the history.  As a percentage of
Internet users, the group of people who understood what it meant to
reconfigure one's DNS resolution path has been in decline for rather a
long time, and it is often quite clear to me that even developers
working on things that might touch on the DNS have only the dimmest
grasp of how it works or what the consequences will be in fooling with
it.  Nobody has any reason to imagine that changes to their search
engine will have wide effects throughout the automatic portions of
their Internet experience, but changing your resolver certainly will
have that sort of effect in at least some cases.  I think this is an
area that needs some care, even if I agree that users need to be able
to do it.

Best regards,


Andrew Sullivan