Re: [dns-privacy] Call for Adoption: draft-hzpa-dprive-xfr-over-tls

2019-11-05 Thread Robert Edmonds
RIVE, and comments to the list, clearly stating your view. > > Please also indicate if you are willing to contribute text, review, etc. I support adoption of draft-hzpa-dprive-xfr-over-tls and am willing to review. -- Robert Edmonds ___ dns-priva

Re: [dns-privacy] Sketchy notes on DNS-over-TLS to authoritative servers

2018-09-14 Thread Robert Edmonds
ervers with a separate NS query to DNSSEC-validate any signals encoded in NSDNAMEs. -- Robert Edmonds ___ dns-privacy mailing list dns-privacy@ietf.org https://www.ietf.org/mailman/listinfo/dns-privacy

Re: [dns-privacy] DNS over TLS for zone transfers?

2017-01-17 Thread Robert Edmonds
to help an inferior format. What does poor message decoding performance from a particular implementation have to do with DNS transaction confidentiality? (There are DNS implementations that advertise high query rates with filtering, so I'm skeptical that backwards inco

Re: [dns-privacy] DNS over TLS for zone transfers?

2017-01-17 Thread Robert Edmonds
the transport. (BTW, one thing I wonder about is, for operators who *don't* use AXFR/IXFR on port 53 to distribute their zones, does the transport they use support confidentiality equivalent to TLS/SSH?) -- Robert Edmonds ___ dns-privacy mailing list dns-privacy@ietf.org https://www.ietf.org/mailman/listinfo/dns-privacy

Re: [dns-privacy] Scope of Privacy considerations

2016-11-28 Thread Robert Edmonds
h the IETF has committed to mitigating (RFC 7258). This is a much broader issue than the existence or disclosure of personally identifiable data. -- Robert Edmonds ___ dns-privacy mailing list dns-privacy@ietf.org https://www.ietf.org/mailman/listinfo/dns-privacy

Re: [dns-privacy] [internet-dra...@ietf.org: I-D Action: draft-bortzmeyer-dprive-step-2-00.txt]

2016-07-19 Thread Robert Edmonds
ster a port for a “private use” protocol. -- Robert Edmonds ___ dns-privacy mailing list dns-privacy@ietf.org https://www.ietf.org/mailman/listinfo/dns-privacy

Re: [dns-privacy] Recharter discussion? (was DPRIVe Agenda requests for Berlin)

2016-06-10 Thread Robert Edmonds
it) may be useful to an attacker. And key distribution between AXFR clients and servers is probably even more well understood than key distribution between resolver and authority. -- Robert Edmonds ___ dns-privacy mailing list dns-privacy@ietf.org

Re: [dns-privacy] Recharter discussion? (was DPRIVe Agenda requests for Berlin)

2016-06-10 Thread Robert Edmonds
89 _53 or _853 ? -- Robert Edmonds ___ dns-privacy mailing list dns-privacy@ietf.org https://www.ietf.org/mailman/listinfo/dns-privacy

Re: [dns-privacy] Deployment issues

2016-06-02 Thread Robert Edmonds
Christian Huitema wrote: > Is this part of DPRIVE's charter? "...but it may also later consider mechanisms that provide confidentiality between Iterative Resolvers and Authoritative Servers, or provide end-to-end confidentiality of DNS transactions."

Re: [dns-privacy] DNS + 0-RTT

2016-04-11 Thread Robert Edmonds
Unbound is fixed (PowerDNS has a feature request for round-robin, but > is currently also fixed (*)). Unbound actually does support both fixed and randomized, and the entropy is taken from an interesting place: the ID field from the query. -- Robert Edmonds

Re: [dns-privacy] DNS PRIVate Exchange

2016-01-15 Thread Robert Edmonds
til the mid-1960s and was the first machine capable of supporting large networks that was considered secure against known plaintext attack. The KL-7 was also used by several NATO countries until 1983. -- Robert Edmonds ___ dns-privacy mailin