Re: [Doh] WGLC #2

Patrick McManus <pmcmanus@mozilla.com> Wed, 23 May 2018 21:54 UTC

Return-Path: <pmcmanus@mozilla.com>
X-Original-To: doh@ietfa.amsl.com
Delivered-To: doh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8AFE5127010 for <doh@ietfa.amsl.com>; Wed, 23 May 2018 14:54:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.234
X-Spam-Level:
X-Spam-Status: No, score=-1.234 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, SPF_SOFTFAIL=0.665] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zdwCXikIrKXh for <doh@ietfa.amsl.com>; Wed, 23 May 2018 14:54:02 -0700 (PDT)
Received: from linode64.ducksong.com (www.ducksong.com [192.155.95.102]) by ietfa.amsl.com (Postfix) with ESMTP id BD25A1201F8 for <doh@ietf.org>; Wed, 23 May 2018 14:54:02 -0700 (PDT)
Received: from mail-ot0-f177.google.com (mail-ot0-f177.google.com [74.125.82.177]) by linode64.ducksong.com (Postfix) with ESMTPSA id 6F5CC3A069 for <doh@ietf.org>; Wed, 23 May 2018 17:54:02 -0400 (EDT)
Received: by mail-ot0-f177.google.com with SMTP id h8-v6so27041969otb.2 for <doh@ietf.org>; Wed, 23 May 2018 14:54:02 -0700 (PDT)
X-Gm-Message-State: ALKqPwd7iX08fERw0VY+q2gB7Byg71rVqGYuee0ahv7jNN+7UmtpkxyA qs2mAxiqZFhnMu2SSZaRS1AlkyEC909iqjmj7DU=
X-Google-Smtp-Source: AB8JxZreEOWAEankpNAEIaJiKOIQHmrGSVT1yFGXS+8j+V3u6Wvo4t2jxvmZvTsC1rIYOtPGB1iCeEkIm+JXSyQwqSs=
X-Received: by 2002:a9d:1ba8:: with SMTP id z37-v6mr3120352otd.85.1527112442124; Wed, 23 May 2018 14:54:02 -0700 (PDT)
MIME-Version: 1.0
Received: by 2002:a4a:8a24:0:0:0:0:0 with HTTP; Wed, 23 May 2018 14:54:01 -0700 (PDT)
In-Reply-To: <603D7553-D1A9-4DCC-9E74-199059C56A9F@sinodun.com>
References: <CAHbrMsCxkogJ-fzubf7cPgvbeGAhWUFKV3crrmn4ee6=fDnqwQ@mail.gmail.com> <382ba525100a4561b086fe8b8b6527be@ustx2ex-dag1mb3.msg.corp.akamai.com> <603D7553-D1A9-4DCC-9E74-199059C56A9F@sinodun.com>
From: Patrick McManus <pmcmanus@mozilla.com>
Date: Wed, 23 May 2018 17:54:01 -0400
X-Gmail-Original-Message-ID: <CAOdDvNrrSVV7Ni-rM19GrX5Xcv7B+9OQmzRiLjQuyk0OXkvJjA@mail.gmail.com>
Message-ID: <CAOdDvNrrSVV7Ni-rM19GrX5Xcv7B+9OQmzRiLjQuyk0OXkvJjA@mail.gmail.com>
To: Sara Dickinson <sara@sinodun.com>
Cc: "Hewitt, Rory" <rhewitt=40akamai.com@dmarc.ietf.org>, DoH WG <doh@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000a51f08056ce692de"
Archived-At: <https://mailarchive.ietf.org/arch/msg/doh/vDk0QtZsvB6KIXcvrjWmLSQqN7s>
Subject: Re: [Doh] WGLC #2
X-BeenThere: doh@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: DNS Over HTTPS <doh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/doh>, <mailto:doh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/doh/>
List-Post: <mailto:doh@ietf.org>
List-Help: <mailto:doh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/doh>, <mailto:doh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 May 2018 21:54:05 -0000

On Tue, May 22, 2018 at 11:37 AM, Sara Dickinson <sara@sinodun.com> wrote:

>
> 2) “If a client of this protocol encounters an HTTP
>    error after sending a DNS query, and then falls back to a different
>    DNS retrieval mechanism, doing so can weaken the privacy and
>    authenticity expected by the user of the client.”
>
> What does authenticity mean here - data integrity or DNSSEC
> authentication? If it is the latter I would argue to remove it because
> DNSSEC and transport choice are orthogonal.
>
>
I'm not a big fan of that text. What it says is true (essentially - if you
don't use HTTPS you don't get the properties of HTTPS), but that's not
really much of a security consideration of this protocol.

I'm going to propose removing the paragraph. thoughts?