Re: [dns-privacy] Privacy for engineers

2014-10-27 Thread Bob Harold
admits that there are tradeoffs. The law (or a typical organization's policy) does not seem to understand that. Disclaimer: definitely not speaking for my employer. -- Bob Harold On Mon, Oct 27, 2014 at 3:46 AM, Stephane Bortzmeyer bortzme...@nic.fr wrote: Good reading about the blind spots

Re: [dns-privacy] I-D Action: draft-ietf-dprive-start-tls-for-dns-00.txt

2015-05-05 Thread Bob Harold
One minor concern: Page 8, section 4, point 4 Use of a local DNS forwarder allows a single active DNS-over-TLS connection allows a single active TCP connection for DNS per client computer. -- That sentence does not read correctly to me. -- Bob Harold

Re: [dns-privacy] Start of WGLC for draft-ietf-dprive-dns-over-tls-01

2015-10-22 Thread Bob Harold
On Thu, Oct 22, 2015 at 2:05 PM, Wessels, Duane <dwess...@verisign.com> wrote: > > > On Oct 22, 2015, at 6:59 PM, Bob Harold <rharo...@umich.edu> wrote: > > > > The URL is not working for me, and I cannot find a working URL. Is it > just me? > > > T

Re: [dns-privacy] Non-zero padding (was EDNS0 padding with non-0 MUST respond with FORMERR?)

2015-11-16 Thread Bob Harold
asons. > > > > > I think the WG should consider if the current text of saying use 0x00 is > not good enough, > > there are 3 options, use: > > - 0x00 > > - cheap randomness > > - real randomness source > > > > I think the m

Re: [dns-privacy] draft-am-dprive-eval-02

2015-11-02 Thread Bob Harold
. pg 17, sec 7.4 I am not familiar with the details of IPSEC, but from the text it appears to hide the port number. But does it hide the destination IP? If not, and if most DNS resolvers have a separate IP from other services, then "undetectability" is very low,

Re: [dns-privacy] Start of WGLC for draft-ietf-dprive-dnsodtls.

2016-08-17 Thread Bob Harold
; This sentence does not read well to me: "TLS False Start [I-D.ietf-tls-falsestart] which reduces round-trips by allowing the TLS second flight of messages (ChangeCipherSpec) to also contain the (encrypted) DNS query. " -- Bob Harold ___ dns-privacy mailing list dns-privacy@ietf.org https://www.ietf.org/mailman/listinfo/dns-privacy

Re: [dns-privacy] Start of WGLC for draft-ietf-dprive-dnsodtls.

2016-08-18 Thread Bob Harold
On Thu, Aug 18, 2016 at 1:14 AM, Tirumaleswar Reddy (tireddy) < tire...@cisco.com> wrote: > *From:* Bob Harold [mailto:rharo...@umich.edu] > *Sent:* Wednesday, August 17, 2016 9:13 PM > *To:* Warren Kumari <war...@kumari.net> > *Cc:* dns-privacy@ietf.org; draft-ietf-

Re: [dns-privacy] Call for Adoption: draft-mayrhofer-dprive-padding-profile

2016-11-28 Thread Bob Harold
implementors (based on pending research and > > analysis). > > > > If we really only want one document, then probably it should start with > > recommendations and then include the review of techniques as an > > appendix. > > I happen to favour this second approach

Re: [dns-privacy] ENDS0 Padding Profile: Rough first draft

2016-11-01 Thread Bob Harold
es"), discusses the > >implications of each of these options, and provides implementation > >guidance. > > > > > > The IETF datatracker status page for this draft is: > > https://datatracker.ietf.org/doc/draft-mayrhofer-dprive-padding-profi > > le/

Re: [dns-privacy] I-D Action: draft-ietf-dprive-padding-policy-05.txt

2018-07-25 Thread Bob Harold
queries are typically much smaller. So an attacker could use small padding to a server that used "maximum-ish" padding and get amplification. I don't think we want to pad queries to more than 288? -- Bob Harold > Of course, it doesn't defeat > > anonymizing attacks, it j

Re: [dns-privacy] I-D Action: draft-ietf-dprive-bcp-op-01.txt

2018-12-18 Thread Bob Harold
ve-bcp-op-01 > > > > A diff from the previous version is available at: > > https://www.ietf.org/rfcdiff?url2=draft-ietf-dprive-bcp-op-01 > > Minor nits: 5.1.5. Service options DNS Privacy Threats: o Unfairly disadvantaging users of the privacy service with respect to

Re: [dns-privacy] New Version Notification for draft-bretelle-dprive-dot-spki-in-ns-name-00.txt

2019-03-14 Thread Bob Harold
[RFC7858]) authoritative server by encoding > > it as part of its name. The fingerprint can thereafter be used to > > validate the certificate received from the DoT server as well as > > being able to discover support for DoT on the server. > > 6. IANA Considerations

Re: [dns-privacy] Fwd: New Version Notification for draft-hzpa-dprive-xfr-over-tls-02.txt

2019-07-11 Thread Bob Harold
; 6.2. TLS Not sure that these are the right words. "surveillance" to me implies a passive watching. Which means: "passive surveillance" - is redundant, and "active surveillance" - is a contradiction in terms. I assume that "active" means sending packets to try to confuse the server or client, which I would call an "attack" and not "surveillance". Or am I wrong? -- Bob Harold ___ dns-privacy mailing list dns-privacy@ietf.org https://www.ietf.org/mailman/listinfo/dns-privacy

Re: [dns-privacy] Operating System API support for DNS security policy

2019-08-19 Thread Bob Harold
lf, bypassing the OS (even though I dislike this, unless the user has agreed) - OS supports DoT but cannot reach a DoT server - various choices, we don't need to discuss this now. -- Bob Harold > > > My view is that the OS should be taking the most secure DNS route it has

Re: [dns-privacy] [Ext] Threat Model

2019-11-08 Thread Bob Harold
el of caution/fear/lack-of-backbone (I am sure there are other descriptions people would prefer). -- Bob Harold ___ dns-privacy mailing list dns-privacy@ietf.org https://www.ietf.org/mailman/listinfo/dns-privacy

Re: [dns-privacy] [Ext] Threat Model

2019-11-11 Thread Bob Harold
> outage notification by tools or humans. > > Paul > Thanks to everyone for the info and recommendations. I need to figure out how to alert on validation failures, and then enable validation. -- Bob Harold ___ dns-privacy mailing list dns-privacy@ietf.org https://www.ietf.org/mailman/listinfo/dns-privacy

Re: [dns-privacy] I-D Action: draft-ietf-dprive-xfr-over-tls-00.txt

2019-11-25 Thread Bob Harold
quot; "RR of this" -> "of this RR" 6.4. IP Based ACL on the Primary "This is also possible with XoT but it must be noted that as with TCP the implementation of such and ACL cannot be enforced" "and ACL" -> "an ACL" -- Bob Harold ___ dns-privacy mailing list dns-privacy@ietf.org https://www.ietf.org/mailman/listinfo/dns-privacy

Re: [dns-privacy] Last Call: (DNS Privacy Considerations) to Informational RFC

2020-01-21 Thread Bob Harold
n submitted directly on this I-D. > > Looks good to me. One grammar nit: 3.5.1.4.2. DoH Specific Considerations next to last paragraph "Some implementations have, in fact, chosen restrict the use of" change to: "Some implementations have, in fact, chosen to restrict the use

Re: [dns-privacy] I-D Action: draft-ietf-dprive-early-data-00.txt

2020-04-22 Thread Bob Harold
ttps://tools.ietf.org/html/draft-ietf-dprive-early-data-00 > https://datatracker.ietf.org/doc/html/draft-ietf-dprive-early-data-00 > > Looks good to me, one nit: 1. Introduction "tecniques" -> "techniques" -- Bob Harold ___ dns-privacy mailing list dns-privacy@ietf.org https://www.ietf.org/mailman/listinfo/dns-privacy

Re: [dns-privacy] I-D Action: draft-ietf-dprive-bcp-op-09.txt

2020-05-04 Thread Bob Harold
e Trust model "overtime" > "over time" 7.1.2. Trust Model Bootstrapping The whole first paragraph is difficult to parse - it does not seem like complete sentences. 7.2.2. Automated Trust Anchor Check "to to" > "to" But the sentence does not seem c

Re: [dns-privacy] I-D Action: draft-ietf-dprive-bcp-op-13.txt

2020-07-10 Thread Bob Harold
ions available at: > > https://tools.ietf.org/html/draft-ietf-dprive-bcp-op-13 > > https://datatracker.ietf.org/doc/html/draft-ietf-dprive-bcp-op-13 > > > > A diff from the previous version is available at: > > https://www.ietf.org/rfcdiff?url2=draft-ietf-dprive-bcp-op-13

Re: [dns-privacy] New Version Notification - draft-ietf-dprive-dnsoquic-12.txt

2022-04-28 Thread Bob Harold
om? I was expecting "doq-00". 5.5. Session Resumption and 0-RTT Next to last paragraph, "errros" -> "errors" 6.3. Address Validation The end of the first paragraph "to a factor 3." -> "to a factor of 3." -- Bob Harold _