[hrpc] DoH and its deployment

Stephane Bortzmeyer <bortzmeyer@nic.fr> Sun, 10 March 2019 10:12 UTC

Return-Path: <stephane@laperouse.bortzmeyer.org>
X-Original-To: hrpc@ietfa.amsl.com
Delivered-To: hrpc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 421AE126C01 for <hrpc@ietfa.amsl.com>; Sun, 10 Mar 2019 03:12:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HEADER_FROM_DIFFERENT_DOMAINS=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6Ml8TzC0x0FL for <hrpc@ietfa.amsl.com>; Sun, 10 Mar 2019 03:12:23 -0700 (PDT)
Received: from ayla.bortzmeyer.org (ayla.bortzmeyer.org [92.243.4.211]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DD357124D68 for <hrpc@irtf.org>; Sun, 10 Mar 2019 03:12:22 -0700 (PDT)
Received: by ayla.bortzmeyer.org (Postfix, from userid 10) id 72CF5A052E; Sun, 10 Mar 2019 11:12:20 +0100 (CET)
Received: by godin (Postfix, from userid 1000) id 2FECEEC0B0D; Sun, 10 Mar 2019 11:11:28 +0100 (CET)
Date: Sun, 10 Mar 2019 11:11:28 +0100
From: Stephane Bortzmeyer <bortzmeyer@nic.fr>
To: hrpc@irtf.org
Message-ID: <20190310101128.GA15061@laperouse.bortzmeyer.org>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
X-Transport: UUCP rules
X-Operating-System: Ubuntu 18.04 (bionic)
X-Charlie: Je suis Charlie
User-Agent: Mutt/1.9.4 (2018-02-28)
Archived-At: <https://mailarchive.ietf.org/arch/msg/hrpc/Iyg-Wdx5Rk2MFdl0rKfW84YLruQ>
Subject: [hrpc] DoH and its deployment
X-BeenThere: hrpc@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "mail@nielstenoever.net" <hrpc.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/hrpc>, <mailto:hrpc-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/hrpc/>
List-Post: <mailto:hrpc@irtf.org>
List-Help: <mailto:hrpc-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/hrpc>, <mailto:hrpc-request@irtf.org?subject=subscribe>
X-List-Received-Date: Sun, 10 Mar 2019 10:12:25 -0000

Two Internet-Drafts have been recently published about DoH
(DNS-over-HTTPS) deployment, draft-reid-doh-operator and
draft-livingood-doh-implementation-risks-issues. They criticize DoH as
allowing a power shift from ISPs and corporate networks to users,
browser makers and US cloud services such as Google's and
Cloudflare's.

This has obvious HR consequences (privacy, control of browsing). Note
that draft-reid-doh-operator even has a "Human rights considerations"
section.

I won't give my opinion here right now but you can follow the discussion here:

https://mailarchive.ietf.org/arch/msg/doh/_J-lTbQB5GUdAuCDucUaTkLwmM8

https://mailarchive.ietf.org/arch/msg/doh/p0q7lWHRuXp-Tzv9Lyiza_OpdTY