Re: [DNSOP] DNS privacy : now at least two drafts

2014-03-16 Thread Florian Weimer
* Florian Weimer: There is another privacy-enhancing approach that is not mentioned in the draft: defensive delegations. For example, with current resolver behavior, the lack of a delegation for 1.E164.ARPA means that queries under that tree are sent to the E164.ARPA servers, which are

Re: [DNSOP] An approach to DNS privacy

2014-03-16 Thread Florian Weimer
* Phillip Hallam-Baker: If your ordinary resolver operator is a carrier is somewhat questionable, but resolver operators generally comply with requests for cleartext copies of traffic transitioning through their networks. I have no doubts that these operators will ask implementors to add the

Re: [DNSOP] DNS privacy : now at least two drafts

2014-03-16 Thread Florian Weimer
* Mark Andrews: Another note is that the answer to the NS query, unlike the referral sent when the question is a full qname, is in the Answer section, not in the Authoritative section. It has probably no practical consequences. Most resolvers do not make NS queries, and some