On Tue, Oct 21, 2014 at 02:14:49PM +0900,
 Masataka Ohta <[email protected]> wrote 
 a message of 27 lines which said:

> As the choice between privacy and latency is on resolver side,
> moderate latency is not harmful.

I fully agree. Qname minimisation is an _unilateral_ decision. Any
resolver can make its own trade-off, depending on its administrator's
choices.

dataminimisation: on|off (programmers, pick the best default value)

> Right, NXDOMAIN returned by some broken implementation to
> empty non-terminals MUST NOT be interpreted that the
> terminals does not exist.

Full agreement again and I suggest everyone to consider
draft-vixie-dnsext-resimprove-00, section 3 (an useful thing for qname
minimisation but also against current "random qnames" attacks
<https://indico.dns-oarc.net//contributionDisplay.py?contribId=37&sessionId=3&confId=20>).



_______________________________________________
DNSOP mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to