[DNSOP] Re: QName Minimization vs Aggressive NSEC vs Encrypt ed and Authenticated DNS vs Serve Stale vs DNSSEC vs LocalRoot
Ondřej Surý <[email protected]>
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <[email protected]> |
Philip, [replying with no hat at all] that was exactly my thought when I skimmed through the draft. The draft claims that LocalRoot provided Significant or Complete protection in the case of "a region may become disconnected". I think this is simply not true. Root Zone is only a small but significant part of the DNS and saying that everything will be peachy because ccTLD might be available doesn't match my experience when I worked for ccTLD. Additionally, I think this document misses only class of "mitigations" and that would be "RSS improvements". I find it wrong that this document is being done without a cooperation from Root Server Operators. There's RSSAC - what does RSSAC think about the document and LocalRoot? Just recently I've seen a complaint that IETF is not talking to the operators and this is causing IETF to become irrelevant, and this is operational change so I think operators should be involved. Ondrej -- Ondřej Surý (He/Him) [email protected] A gentle nudge is always appreciated if I take a little longer to reply. > On 2. 6. 2026, at 16:25, Philip Homburg <[email protected]> wrote: > >> Having analysed root-server >> traffic via DITL data, I am acutely aware about the need for >> *complete* privacy protection. Since the best way to keep things >> secret is not to tell anyone, I see that LocalRoot fulfills that >> promise. The other methods go a long way, but do not stop your >> queries from ending up in, say, DITL data. > > What I find problematic is that only a small part of query traffic is > considered. > > Most DNS queries do not just go to the root and stop there. Queries continue > TLDs, SLDs, etc. > > For an on path attacker, does a local root provide much protection? Not > really, the attacker will see the query go to the TLD. > > With local root, root operators will not see the query but operators of > TLDs will. Are root operators less trustworthy than TLDs operators. It seems > that the answer is yes because root operators participate in DITL. So > may be a local root is a good idea. > > When considering all upstream traffic of a resolver to answer a query, > is the improvement provided by a local root significant? > > _______________________________________________ > DNSOP mailing list -- [email protected] > To unsubscribe send an email to [email protected] _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]