Re: [Driu] Resolverless DNS Side Meeting in Montreal
Patrick McManus <pmcmanus@mozilla.com> Sat, 28 July 2018 16:32 UTC
Return-Path: <pmcmanus@mozilla.com>
X-Original-To: driu@ietfa.amsl.com
Delivered-To: driu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7A48313112F; Sat, 28 Jul 2018 09:32:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.233
X-Spam-Level:
X-Spam-Status: No, score=-1.233 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, SPF_SOFTFAIL=0.665, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1LHR9oc1sEUa; Sat, 28 Jul 2018 09:32:06 -0700 (PDT)
Received: from linode64.ducksong.com (www.ducksong.com [192.155.95.102]) by ietfa.amsl.com (Postfix) with ESMTP id C8006131058; Sat, 28 Jul 2018 09:32:05 -0700 (PDT)
Received: from mail-oi0-f48.google.com (mail-oi0-f48.google.com [209.85.218.48]) by linode64.ducksong.com (Postfix) with ESMTPSA id 3E0353A01E; Sat, 28 Jul 2018 12:32:04 -0400 (EDT)
Received: by mail-oi0-f48.google.com with SMTP id 13-v6so14401967ois.1; Sat, 28 Jul 2018 09:32:04 -0700 (PDT)
X-Gm-Message-State: AOUpUlEgs9tLYUFMInrRu5Ed1/r6qRSyB9pQWcfS2V6E6xBmqwyb/Ddh h/hGbAcvoEI/gIA442lIIaxCH5f9LC0tBR7Wkhk=
X-Google-Smtp-Source: AAOMgpe3GfMsU8IPLMBVMGcTYzO5YR2A132mu6+fScl/bN/My52Qoncd98FN47XywI0p+XDbx93EUAyTeO21dD3DrRA=
X-Received: by 2002:aca:31c6:: with SMTP id x189-v6mr11878333oix.213.1532795523956; Sat, 28 Jul 2018 09:32:03 -0700 (PDT)
MIME-Version: 1.0
Received: by 2002:a4a:8a22:0:0:0:0:0 with HTTP; Sat, 28 Jul 2018 09:32:02 -0700 (PDT)
In-Reply-To: <CAOdDvNp0S5-aEzy4ziqVvL1Kd+V79nD49_Zuo1dLoThXYP7nFg@mail.gmail.com>
References: <CAOdDvNp0S5-aEzy4ziqVvL1Kd+V79nD49_Zuo1dLoThXYP7nFg@mail.gmail.com>
From: Patrick McManus <pmcmanus@mozilla.com>
Date: Sat, 28 Jul 2018 12:32:02 -0400
X-Gmail-Original-Message-ID: <CAOdDvNrJWBnWevj4cTmi+0D0JL1vzYcgb5QtMhe4fivkaQoPrA@mail.gmail.com>
Message-ID: <CAOdDvNrJWBnWevj4cTmi+0D0JL1vzYcgb5QtMhe4fivkaQoPrA@mail.gmail.com>
To: Patrick McManus <pmcmanus@mozilla.com>, DNS Privacy Working Group <dns-privacy@ietf.org>
Cc: Ben Schwartz <bemasc@google.com>, Daniel Kahn Gillmor <dkg@aclu.org>, DoH WG <doh@ietf.org>, driu@ietf.org, HTTP Working Group <ietf-http-wg@w3.org>, dnsop <dnsop@ietf.org>
Content-Type: multipart/mixed; boundary="000000000000b82213057211c474"
Archived-At: <https://mailarchive.ietf.org/arch/msg/driu/a_fCtN6S8ygxXpILW--lRkDGRXg>
Subject: Re: [Driu] Resolverless DNS Side Meeting in Montreal
X-BeenThere: driu@ietf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: "DNS Resolver Identification and Use \(DRIU\)." <driu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/driu>, <mailto:driu-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/driu/>
List-Post: <mailto:driu@ietf.org>
List-Help: <mailto:driu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/driu>, <mailto:driu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 28 Jul 2018 16:32:16 -0000
Hi All - This is a wrap-up email for the Resolverless DNS meeting held on July 16 in Montreal. We had, by my rough count, about 50 people and two sets of minutes are attached. If you attended, contributed, or took minutes (Thanks Shane and Ben!) thank you - it was, imo, a productive, professional, and even pretty focused discussion. We identified a next step: using an AD sponsored list (See Below!), identify one minimal context or use case that provides value for using DNS information without direct recursive resolver contact, and enumerate the concerns and potential mitigations for those concerns. If we can focus on that and make some progress then we might have a proposal for a future BoF - if we cannot make progress then that is also telling. Adam and Warren have setup a list for us to use. I apologize to the various working group's cc'd on this so far (and thank them for their indulgence) - future communications should move to the new list. New List Info ------------------- https://www.ietf.org/mailman/listinfo/resolverless-dns -Patrick On Mon, Jul 9, 2018 at 10:49 PM, Patrick McManus <pmcmanus@mozilla.com> wrote: > Hi All, > > I am organizing an ad-hoc Side Meeting regarding 'Resolverless DNS' in > Montreal. > > We have often talked about the benefits and concerns of DNS information > obtained from sources that are, shall we say, less globally trusted than a > recursive a resolver. The central use case is DoH when pushed from an > endpoint that isn't a recursive resolver but there have been other > proposals. > > For example www.example.com pushes you a AAAA record for img1.example.com. > Should you use it? What if it is for img1.img-example.com ? Do the > relationship between these domains matter? What kind of relationship (i.e. > it could be a domain relationship, or in the context of a browser it might > be a first-party tab like relationship, etc..)? What are the implications > of poison? Trackers? Privacy of requests never made? Speed? Competitive > shenanigans or DoS attacks? > > This was out of scope for DoH. > > *We'll do the meeting over 1 hour in the Dorchester room from 16:30 to > 17:30 on Monday July 16th.* > > This is a meeting of interested folks looking to see if we can agree on > next steps - we're not going to work out the details (nor should a side > meeting try and do so). so we'll have a tight agenda that I suggest > organizaing as follows: > > 1] What forms of transport could be in scope? HTTP/2 push is one such > vector, but I've heard others. Spray paint for example. > > 2] What needs to be considered when using such data? (signatures? scope? > etc?) > > 3] Who are the stakeholders for 1 + 2? > > 4] Is there enough interest to explore further? Next steps as output > > I hope you can come! > > -Patrick > >
- Re: [Driu] [DNSOP] Resolverless DNS Side Meeting … Patrick McManus
- Re: [Driu] [Doh] Resolverless DNS Side Meeting in… manu tman
- Re: [Driu] [DNSOP] Resolverless DNS Side Meeting … Philip Homburg
- Re: [Driu] [DNSOP] Resolverless DNS Side Meeting … Paul Vixie
- Re: [Driu] [Doh] [DNSOP] Resolverless DNS Side Me… Tim Wicinski
- Re: [Driu] [Doh] Resolverless DNS Side Meeting in… Patrick McManus
- Re: [Driu] [DNSOP] Resolverless DNS Side Meeting … Paul Wouters
- Re: [Driu] [Doh] [DNSOP] Resolverless DNS Side Me… Adam Roach
- Re: [Driu] [DNSOP] [Doh] Resolverless DNS Side Me… Paul Wouters
- Re: [Driu] Resolverless DNS Side Meeting in Montr… Patrick McManus
- Re: [Driu] Resolverless DNS Side Meeting in Montr… Ted Lemon
- [Driu] Resolverless DNS Side Meeting in Montreal Patrick McManus
- Re: [Driu] [DNSOP] [Doh] Resolverless DNS Side Me… Joe Abley
- Re: [Driu] [Doh] [DNSOP] Resolverless DNS Side Me… Adam Roach
- Re: [Driu] [DNSOP] [Doh] Resolverless DNS Side Me… Joe Abley
- Re: [Driu] [DNSOP] [Doh] Resolverless DNS Side Me… Ted Lemon
- Re: [Driu] [DNSOP] [Doh] Resolverless DNS Side Me… Joe Abley
- Re: [Driu] [DNSOP] [Doh] Resolverless DNS Side Me… Adam Roach
- Re: [Driu] [DNSOP] [Doh] Resolverless DNS Side Me… Adam Roach
- Re: [Driu] [DNSOP] [Doh] Resolverless DNS Side Me… Ted Lemon
- Re: [Driu] [DNSOP] [Doh] Resolverless DNS Side Me… Patrick McManus
- Re: [Driu] [DNSOP] [Doh] Resolverless DNS Side Me… Philip Homburg
- Re: [Driu] [Doh] [DNSOP] Resolverless DNS Side Me… Adam Roach
- Re: [Driu] [DNSOP] [Doh] Resolverless DNS Side Me… Dave Lawrence
- Re: [Driu] [DNSOP] [Doh] Resolverless DNS Side Me… Joe Abley
- Re: [Driu] [DNSOP] [Doh] Resolverless DNS Side Me… Adam Roach
- Re: [Driu] [DNSOP] [Doh] Resolverless DNS Side Me… Paul Wouters
- Re: [Driu] [Doh] [DNSOP] Resolverless DNS Side Me… Dave Lawrence
- Re: [Driu] [DNSOP] [Doh] Resolverless DNS Side Me… Ryan Sleevi
- Re: [Driu] [Doh] [DNSOP] Resolverless DNS Side Me… Dave Lawrence
- Re: [Driu] [Doh] [DNSOP] Resolverless DNS Side Me… Daniel Kahn Gillmor
- Re: [Driu] [Doh] [DNSOP] Resolverless DNS Side Me… Tony Finch
- Re: [Driu] [DNSOP] [Doh] Resolverless DNS Side Me… Mike Bishop
- Re: [Driu] [DNSOP] [Doh] Resolverless DNS Side Me… Ryan Sleevi
- [Driu] SRV and HTTP Mark Nottingham
- Re: [Driu] [DNSOP] SRV and HTTP Ólafur Guðmundsson
- Re: [Driu] [DNSOP] SRV and HTTP Mark Andrews
- Re: [Driu] [DNSOP] SRV and HTTP Mark Nottingham
- Re: [Driu] [DNSOP] SRV and HTTP Mark Andrews
- Re: [Driu] [DNSOP] SRV and HTTP Dave Lawrence
- Re: [Driu] [DNSOP] SRV and HTTP Dave Lawrence
- Re: [Driu] [DNSOP] SRV and HTTP Mark Andrews
- Re: [Driu] SRV and HTTP - 18:30 Tuesday Mark Nottingham
- Re: [Driu] [DNSOP] SRV and HTTP Patrik Fältström
- Re: [Driu] [DNSOP] SRV and HTTP Mark Andrews
- Re: [Driu] [Doh] [DNSOP] Resolverless DNS Side Me… Petr Špaček
- Re: [Driu] SRV and HTTP Leif Hedstrom
- Re: [Driu] [DNSOP] SRV and HTTP Patrik Fältström
- Re: [Driu] [Doh] [DNSOP] Resolverless DNS Side Me… Mike Bishop
- Re: [Driu] [DNSOP] SRV and HTTP Nico Williams
- Re: [Driu] [Doh] [DNSOP] SRV and HTTP Joseph Lorenzo Hall
- Re: [Driu] [DNSOP] SRV and HTTP Mark Andrews
- Re: [Driu] [DNSOP] SRV and HTTP Nico Williams
- Re: [Driu] [DNSOP] SRV and HTTP Mark Andrews
- Re: [Driu] SRV and HTTP - 18:30 Tuesday (room cha… Mark Nottingham
- Re: [Driu] [Doh] SRV and HTTP - 18:30 Tuesday (ro… Shane Kerr
- Re: [Driu] [Doh] SRV and HTTP - 18:30 Tuesday (ro… Jim Reid
- Re: [Driu] [Doh] SRV and HTTP - 18:30 Tuesday (ro… Tim Wicinski
- Re: [Driu] [Doh] SRV and HTTP - 18:30 Tuesday (ro… Ray Bellis
- Re: [Driu] Resolverless DNS Side Meeting in Montr… Patrick McManus
- Re: [Driu] [Doh] SRV and HTTP - 18:30 Tuesday (ro… Sebastiaan Deckers
- Re: [Driu] [Doh] SRV and HTTP - 18:30 Tuesday (ro… Adam Roach
- Re: [Driu] [Doh] SRV and HTTP - 18:30 Tuesday (ro… Adam Roach