Re: Last Call: <draft-ietf-dnsop-onion-tld-00.txt> (The .onion Special-Use Domain Name) to Proposed Standard

"John R Levine" <johnl@taugh.com> Wed, 15 July 2015 23:42 UTC

Return-Path: <johnl@taugh.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E0A5F1B2F23 for <ietf@ietfa.amsl.com>; Wed, 15 Jul 2015 16:42:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.137
X-Spam-Level:
X-Spam-Status: No, score=-1.137 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HELO_MISMATCH_COM=0.553, HOST_MISMATCH_NET=0.311, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NYsbOEWsxJtu for <ietf@ietfa.amsl.com>; Wed, 15 Jul 2015 16:42:37 -0700 (PDT)
Received: from miucha.iecc.com (abusenet-1-pt.tunnel.tserv4.nyc4.ipv6.he.net [IPv6:2001:470:1f06:1126::2]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EDFEA1B2F20 for <ietf@ietf.org>; Wed, 15 Jul 2015 16:42:36 -0700 (PDT)
Received: (qmail 24221 invoked from network); 15 Jul 2015 23:42:51 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=iecc.com; h=date:message-id:from:to:cc:subject:in-reply-to:references:mime-version:content-type:user-agent; s=5e9c.55a6effb.k1507; bh=5RP9tRvJ7yPfLPam6kroQwxYrb/9izi8mjCzhhEsn/4=; b=vJo1UsyixViivJln9HbgjWgsk9/z2ccvsVItkHuCfrxBa1ygCa6AwvjvJC2AmqBudLg601s4M7MxoKcMmHf/hy7pogUt2WBM4al1jLpPBJqfU3OVJpeibr9wDKkSZYR3CT4lvaNPSgxwuoP4Eo+A3vZYd8pAKR6lXHw+/YUdgs68YGDnSU34lcB/gm5A3QL/HwpB+mTFu8BhYxBsFyKhxHva/SlSgVjtaiYXS/14mC2CwwSvaObgwT8WXmVBfjTV
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=taugh.com; h=date:message-id:from:to:cc:subject:in-reply-to:references:mime-version:content-type:user-agent; s=5e9c.55a6effb.k1507; bh=5RP9tRvJ7yPfLPam6kroQwxYrb/9izi8mjCzhhEsn/4=; b=btRg2hut/7ET3EzTroYo6LuiYmSKj1u3madvqRcQxz3OU6q3xrla7nq9G7gkvMiM0en82ufPK4mfwt0klsG8jh6n/K+g1/NMEQtgNw/5pPf2pczRN4TdwxaEIvp5bPhr+51cppdcBgSMPEc9ybjd3UEXV8b/6AERsgKlNI/pwVkSG2jFLNdbTq5GS/Z8FQi0zrRX5XXo8VK++UUSnMa5Xi2RmJQaOVI2GwiHvazAx2HH6gX1BmN2M9ksxttZPs9S
Received: from localhost ([IPv6:2001:470:1f07:1126::78:696d:6170]) by imap.iecc.com ([IPv6:2001:470:1f07:1126::78:696d:6170]) with ESMTPS (TLS1.0/X.509/SHA1) via TCP6; 15 Jul 2015 23:42:51 -0000
Date: Wed, 15 Jul 2015 19:42:34 -0400
Message-ID: <alpine.OSX.2.11.1507151938070.45296@ary.lan>
From: John R Levine <johnl@taugh.com>
To: Mark Andrews <marka@isc.org>
Subject: Re: Last Call: <draft-ietf-dnsop-onion-tld-00.txt> (The .onion Special-Use Domain Name) to Proposed Standard
In-Reply-To: <20150715232306.0D8B833329A4@rock.dv.isc.org>
References: <20150715225944.27605.qmail@ary.lan> <20150715232306.0D8B833329A4@rock.dv.isc.org>
User-Agent: Alpine 2.11 (OSX 23 2013-08-11)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"; format="flowed"
Archived-At: <http://mailarchive.ietf.org/arch/msg/ietf/NBI2iFImPaGvypxNfAdqInELssE>
Cc: IETF general list <ietf@ietf.org>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Jul 2015 23:42:38 -0000

> Also what I haven't seen explored but is actually a logical extension
> of using socks to make ordinary browsers talk to .onion sites is
> extending the local recursive server to do the TOR lookup rather
> than a traditional DNS lookup and return the results in a DNS
> message.  With dprive this should end up being secure.

Doesn't work because the underlying protocol isn't TCP.  It can work in 
SOCKS because that's an application layer gateway which can recognize 
.onion as special and set up a TOR session rather than a TCP session.

I suppose the recursive server could return an address in 169.254.0.0/16 
and run a proxy between a link-local TCP session and TOR, but ugh.

Regards,
John Levine, johnl@taugh.com, Taughannock Networks, Trumansburg NY
Please consider the environment before reading this e-mail.