Re: New I-D:draft-kaplan-enum-source-uri-00.txt

Duane <[email protected]>
Newsgroups gmane.ietf.enum
Message-ID <[email protected]>
Hadriel Kaplan wrote:
> Yup, you're right, I should make that issue very explicit in the
> draft.  The purpose of this draft's extension is strictly for
> non-public ENUM use, and I should have said that (d'oh).

I acknowledged this was the case, however even for non-public only enum
use I feel privacy issues should still be mentioned, as I can almost
garentee some peers somewhere at some point in time will end up, for
what ever reasons, using the public internet to locate routing
information. Perhaps you could go so far as forbidding this explicitly
and suggesting VPN or private links or what not.

> The requester can decide if it wants to include the extension or not,
> and whether to provide an anonymous URI or not.  If a device "in the
> network" wants to issue such a request, and has the source URI info
> with which to do so, then I'm afraid the government can already get
> that information - directly from that device.  In fact, without this
> extension, to perform routing for certain types of application
> messages, such as SIP, would instead require using SIP and sending
> the entire SIP request (bodies and all) to the routing service and it
> would get far more information than just the source URI.

Actually the implications aren't limited to your own government now, all
it takes is a few misconfigurations and suddenly DNS requests are
hitting root and other name servers and sending all kinds of call meta
information to any number of providers, countries, who knows.

In any case, my primary concern is that this subject wasn't mentioned or
was brushed over as being "There are no specific security issues for
this mechanism, beyond those already applicable to DNS and ENUM." which
isn't accurate and extra care should be taken if/when using lookups and
sending more information then current/most NAPTR requests contain.

-- 

Best regards,
 Duane
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.