[DNSOP] Re: Language negotiation in draft-ietf-dnsop-structu red-dns-error

Mukund Sivaraman <[email protected]>
Newsgroups gmane.ietf.dnsop
Message-ID <ahcaBaXsE86TIx81@p5>
On Thu, May 28, 2026 at 12:17:51AM +0800, Mukund Sivaraman wrote:
> On Wed, May 27, 2026 at 09:04:21AM -0400, Paul Wouters wrote:
> > 
> > 
> > > On May 27, 2026, at 03:09, Lars Eggert <[email protected]> wrote:
> > > 
> > > Hi,
> > > 
> > >> On May 26, 2026, at 20:00, Mukund Sivaraman <[email protected]> wrote:
> > >> It is a textual message for users to consume and for clients to display
> > >> to users. Web browsers may have strict policies on what they display in
> > >> some contexts, but that doesn't mean that DNS should not distribute this
> > >> textual information.
> > > 
> > > IMO there is zero chance browsers will show this text to users in *any* context. What other clients do you envision to be different?
> > 
> > And it’s not because they are just stubborn. Any free flow text that an attacker can populate will be abused by attackers for malicious messages.
> > 
> > I already have to support some non-technical people inundated with “your phone is infected, click here” messages. Free form fields are dangerous.
> > 
> > If this is not an “enduser” free form field, but a debugging thing, language tags seem overkill and are rarely used by implementations to customize the error message for specific languages 
> > 
> > That llms say to use nslookup, a tool that has been obsoleted longer than the age of half the people on this list is perhaps an indication that these are not strong arguments to use for implementation decisions at the protocol level.
> 
> nslookup was deprecated in the BIND tree for a period of time for having
> a history of inconsistent behavior and a confusing interface. nslookup
> was undeprecated in the BIND tree around the 9.3 timeframe - see change
> 1700 in the bind9 CHANGES file, but I don't have the exact version tag
> handy. It is available in the Debian bind9-utils package, the Fedora
> bind-utils package, etc. and its manpage does not have any notices about
> obsoletion or deprecation. (I'm not recommending that nslookup be used
> over dig.)

I forgot to mention - I'm not speaking for the BIND project in
anyway. Just noting what I remember from developing a fork of it, what's
in the CHANGES file, and what's in the nslookup manpage. I definitely do
not want to cause any ill will by commenting about BIND history.

And dig being better than nslookup is not contested.

		Mukund

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 1.5 KB)
-----BEGIN PGP SIGNATURE-----

iQQzBAABCgAdFiEExrdyGG6c4NA+XvCrfNjWvMM1gqEFAmoXGgIACgkQfNjWvMM1
gqFntx//SzM1hEeLm11+UmxOb1oMD5Jy3Xt3eTQBLSm440PTe0kd4J7h/jQpq8Iy
WSaQo0KfYml9jEynnIVyz3yXLc3iZaMP/68Gpk/QY96evOpz+B04J44Us90DYaeM
7wG5UFsOhFtE2955xLdIUC+xA/i4ETgbyMJqGorCqE4N7SiCZZuNmlLysXZ2Xdb4
AMienydz4oGbEKSVi3ZclgKxR3o+cxqNt8LqXa9tqaHxzH1UjvIA8JxQs/BNulRU
MxYguTvRw4FgMecTXhS4HNLW29H7gMTGv86pyua5aK8/v4NbNnKo78gJo68pIM1Q
zyKYfnrCRrt583OSTYfT/A6h9N8060ncrLuCiditt8d2kXWXs9KGjHOKBgE+CCJv
BzFPjpkF9+L5NlxdBg8fB07NakXc7v/hP8o74TnBghZ2kwC53qay4r6VtdlnZMCS
+VLhJ+p8ppU/B83KMK5cfqlujZKuHDfEpyzOjztqlvHTgHZy9pRhARn0XKea1R0b
FnIEQkH3yPPR8R4xcukb99vqNueXDhdv0c9WW23soLYLb4QpJgzKxJ71Jv4O7nH9
CsqQLqMdP+pxYBLlrOCcjsXzWL6q0BgSSJbyTXFAWXcw/dGDxX7dxFGFnqQ9+nfX
K6dPlQv5T5qtHK/G4Opmd2i+8o/XiDvwI0dNVqAtmt264ZMeCvbOmWHea1A/e/wM
nvehJeQdhLHnTIfHNqOpvEM0E7vG51qYsdqnAXCxd+G/UCPYZXUccEM70tjo5Eb2
AWDScrpfGmwN0jYutuCaEc0FcTGvoKNV087Jjpb6M9dxj4O78sT1rQK6iNoxTMO/
gjdcQ/CleGF/rlNvcGt52ppPXTmWxTrwydiKmKjYOVzPkHFOHAC1SUrvh2zky+9g
ZdkpcoUJemw3HEr6FJCellhwsjS97T0ll/zuEoB4Dk+kAI6x4kMIF4yw+DNkce0R
7wE/I03F0r8vFPBlWOq+0bc82JZeU8UVEOEKP/0xpQOY/oUSBqdiQNXhyKbi5ijj
kzfXWk9xUdZ4Zue+FGIATmio/MMGLvKcJFomvG1FPvPWtbJJdRx0EinhH2+6bezY
p37Wx0gE+xsU8e+OD973gMWHbReyEaGbyzaNAF02Q7lNDiplq7t7yjRmYJJKdOaF
eihgP4KgueQMXIMrE0oM+sWs6Q1QtcGtpJdBeVSEDMcIgYKoCBWaoMN0JAoO2Hcb
Cuf6O/sDrf46/d96wt6jX1EcQdprASPiD3/aCV47pGl7RZJkOuq7CJYM4644isUb
ZDh30cZXJqbw4nfv+e6uM+OJZFQO7zgw4lzMet9uHquw2JRmWKLbYliXLUjGmmmD
5PP8ngcbrM4csekzmP+l//keTH/FgA==
=Us++
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.