Re: [Doh] New Version Notification for draft-dickinson-doh-dohpe-00.txt

Sara Dickinson <sara@sinodun.com> Thu, 19 July 2018 14:52 UTC

Return-Path: <sara@sinodun.com>
X-Original-To: doh@ietfa.amsl.com
Delivered-To: doh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 25A991310E1 for <doh@ietfa.amsl.com>; Thu, 19 Jul 2018 07:52:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.199
X-Spam-Level:
X-Spam-Status: No, score=-4.199 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id O14kalbO1xIV for <doh@ietfa.amsl.com>; Thu, 19 Jul 2018 07:52:29 -0700 (PDT)
Received: from balrog.mythic-beasts.com (balrog.mythic-beasts.com [IPv6:2a00:1098:0:82:1000:0:2:1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8B4DC130EBF for <doh@ietf.org>; Thu, 19 Jul 2018 07:52:29 -0700 (PDT)
Received: from [2001:67c:1232:144:d42:eb7c:2d4a:e5b3] (port=51574) by balrog.mythic-beasts.com with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <sara@sinodun.com>) id 1fgAI3-0002Ma-S8; Thu, 19 Jul 2018 15:52:28 +0100
From: Sara Dickinson <sara@sinodun.com>
Message-Id: <81486098-95E9-49BE-9C04-F0EBEC2A2085@sinodun.com>
Content-Type: multipart/signed; boundary="Apple-Mail=_2442AD86-833C-4B75-B865-98D49BE7F114"; protocol="application/pgp-signature"; micalg="pgp-sha256"
Mime-Version: 1.0 (Mac OS X Mail 11.5 \(3445.9.1\))
Date: Thu, 19 Jul 2018 10:52:20 -0400
In-Reply-To: <CAHbrMsDc1TV=HHmzPWqkd5-i6ObuMD6gGXD_NkL_m3cgvN37EA@mail.gmail.com>
Cc: DoH WG <doh@ietf.org>
To: Ben Schwartz <bemasc@google.com>
References: <153192232867.2882.433616342941784102.idtracker@ietfa.amsl.com> <F3B9C552-D38B-48E2-B592-E817ECFD6DF4@sinodun.com> <CAHbrMsDc1TV=HHmzPWqkd5-i6ObuMD6gGXD_NkL_m3cgvN37EA@mail.gmail.com>
X-Mailer: Apple Mail (2.3445.9.1)
X-BlackCat-Spam-Score: -16
Archived-At: <https://mailarchive.ietf.org/arch/msg/doh/v1BJpqsseMYYMJGi5wmVAtL5DOU>
Subject: Re: [Doh] New Version Notification for draft-dickinson-doh-dohpe-00.txt
X-BeenThere: doh@ietf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: DNS Over HTTPS <doh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/doh>, <mailto:doh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/doh/>
List-Post: <mailto:doh@ietf.org>
List-Help: <mailto:doh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/doh>, <mailto:doh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 19 Jul 2018 14:52:44 -0000


> On 18 Jul 2018, at 16:22, Ben Schwartz <bemasc@google.com> wrote:
> 
> I think this draft could use review from readers familiar with HTTP.  I hope that people with knowledge of HTTP will help us to understand whether this draft's recommendations would result in a significant increase in user privacy.

Completely agree.

> 
> For the draft's authors, I have a question: does this draft's "privacy threat model" include a DOH server that uses active measures to differentiate clients?  Or is it scoped only to passive discrimination between different client implementations?

Both of these.

> 
> As for other issues, I think the draft might need to consider header order.

Yes - a couple of other folks have mentioned that too.

>   I also couldn't find an easy list of mandatory headers in RFC 7540, so that list might be worth repeating.

There doesn’t seem to be a simple example in any draft I found so the current text is a bit of a cop-out. I was wondering if it would make more sense to have the list in draft-ietf-httpbis-bcp56bis-06 as a general clarification and then this document could reference that?

Or Stephane suggested pointing to RFC 7230 (plus a bit of RFC 7231) instead. But actually I now think example messages would be the most explicit way to show what DoHPE messages should look like.

Sara.


> 
> On Wed, Jul 18, 2018 at 10:03 AM Sara Dickinson <sara@sinodun.com <mailto:sara@sinodun.com>> wrote:
> Hi All,
> 
> We’ve just submitted a very short draft outlining a privacy profile for DoH called DoHPE.
> 
> It is very basic at the moment but it would be great to get some feedback on the idea here and to see if the WG sees this as something that should go through this group or head somewhere else. Since the guidelines are purely HTTP related, this does feel like the right audience to review the document at least in the first instance.
> 
> Sara.
> 
> 
>> Begin forwarded message:
>> 
>> From: internet-drafts@ietf.org <mailto:internet-drafts@ietf.org>
>> Subject: New Version Notification for draft-dickinson-doh-dohpe-00.txt
>> Date: 18 July 2018 at 09:58:48 GMT-4
>> To: "Sara Dickinson" <sara@sinodun.com <mailto:sara@sinodun.com>>, "Willem Toorop" <willem@nlnetlabs.nl <mailto:willem@nlnetlabs.nl>>
>> 
>> 
>> A new version of I-D, draft-dickinson-doh-dohpe-00.txt
>> has been successfully submitted by Sara Dickinson and posted to the
>> IETF repository.
>> 
>> Name:		draft-dickinson-doh-dohpe
>> Revision:	00
>> Title:		DoHPE: DoH with Privacy Enhancements
>> Document date:	2018-07-18
>> Group:		Individual Submission
>> Pages:		8
>> URL:            https://www.ietf.org/internet-drafts/draft-dickinson-doh-dohpe-00.txt <https://www.ietf.org/internet-drafts/draft-dickinson-doh-dohpe-00.txt>
>> Status:         https://datatracker.ietf.org/doc/draft-dickinson-doh-dohpe/ <https://datatracker.ietf.org/doc/draft-dickinson-doh-dohpe/>
>> Htmlized:       https://tools.ietf.org/html/draft-dickinson-doh-dohpe-00 <https://tools.ietf.org/html/draft-dickinson-doh-dohpe-00>
>> Htmlized:       https://datatracker.ietf.org/doc/html/draft-dickinson-doh-dohpe <https://datatracker.ietf.org/doc/html/draft-dickinson-doh-dohpe>
>> 
>> 
>> Abstract:
>>   This document describes DoHPE (DoH with Privacy Enhancements) - a
>>   privacy and anonymity profile for DoH [I-D.ietf-doh-dns-over-https]
>>   clients.  The profile provides guidelines on the composition of DoH
>>   messages, designed to minimize disclosure of identifying information.
>> 
>> 
>> 
>> 
>> Please note that it may take a couple of minutes from the time of submission
>> until the htmlized version and diff are available at tools.ietf.org <http://tools.ietf.org/>.
>> 
>> The IETF Secretariat
>> 
> 
> _______________________________________________
> Doh mailing list
> Doh@ietf.org <mailto:Doh@ietf.org>
> https://www.ietf.org/mailman/listinfo/doh <https://www.ietf.org/mailman/listinfo/doh>