[DNSOP] Re: QName Minimization vs Aggressive NSEC vs Encrypt ed and Authenticated DNS vs Serve Stale vs DNSSEC vs LocalRoot

Ondřej Surý <[email protected]>
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
Philip,

[replying with no hat at all]

that was exactly my thought when I skimmed through the draft.

The draft claims that LocalRoot provided Significant or Complete
protection in the case of "a region may become disconnected".
I think this is simply not true. Root Zone is only a small but significant
part of the DNS and saying that everything will be peachy because
ccTLD might be available doesn't match my experience when I worked
for ccTLD.

Additionally, I think this document misses only class of "mitigations"
and that would be "RSS improvements". I find it wrong that this document
is being done without a cooperation from Root Server Operators.

There's RSSAC - what does RSSAC think about the document and LocalRoot?
Just recently I've seen a complaint that IETF is not talking to the operators
and this is causing IETF to become irrelevant, and this is operational change
so I think operators should be involved.

Ondrej
--
Ondřej Surý (He/Him)
[email protected]

A gentle nudge is always appreciated if I take a little longer to reply.

> On 2. 6. 2026, at 16:25, Philip Homburg <[email protected]> wrote:
> 
>> Having analysed root-server
>> traffic via DITL data, I am acutely aware about the need for
>> *complete* privacy protection. Since the best way to keep things
>> secret is not to tell anyone, I see that LocalRoot fulfills that
>> promise. The other methods go a long way, but do not stop your
>> queries from ending up in, say, DITL data.
> 
> What I find problematic is that only a small part of query traffic is
> considered.
> 
> Most DNS queries do not just go to the root and stop there. Queries continue
> TLDs, SLDs, etc.
> 
> For an on path attacker, does a local root provide much protection? Not 
> really, the attacker will see the query go to the TLD.
> 
> With local root, root operators will not see the query but operators of
> TLDs will. Are root operators less trustworthy than TLDs operators. It seems
> that the answer is yes because root operators participate in DITL. So
> may be a local root is a good idea.
> 
> When considering all upstream traffic of a resolver to answer a query,
> is the improvement provided by a local root significant?
> 
> _______________________________________________
> DNSOP mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.