Re: RFC 9498: The GNU Name System

Maxime Devos <[email protected]> Tue, 21 Nov 2023 18:55:42 +0100
Newsgroups gmane.network.gnunet.devel
Message-ID <[email protected]>
Op 21-11-2023 om 08:34 schreef Schanzenbach, Martin:
> We are happy to announce that our *The GNU Name System* (GNS)
> specification is now published as RFC 9498 [0].

> in order to transparently enable this functionality for migration purposes, a local GNS-aware SOCKS5 proxy [RFC1928] can be configured to resolve domain names

Are you sure this is transparent?  Consider the case where a website has 
a log-in system, and instead of being based on passwords, it is based on 
TLS client certificates (for example, https://ci.guix.gnu.org/ has such 
a system to decide who is allowed to adjust ‘specifications’ and 
‘restart builds’).

Given that the SOCKS5 proxy is technically a MITM attack, and the client 
certificates instead of only server certificates, I would expect (and 
hope) that the SOCKS5 proxy can't convince the server that it is the client.

It's a somewhat niche use case, so mostly transparent, sure.
But transparent, without qualifiers, I don't think so.

Best regards,
Maxime Devos
OpenPGP_0x49E3EE22191725EE.asc (application/pgp-keys, 912 B)
-----BEGIN PGP PUBLIC KEY BLOCK-----

xjMEX4ch6BYJKwYBBAHaRw8BAQdANPb/d6MrGnGi5HyvODCkBUJPRjiFQcRU5V+m
xvMaAa/NL01heGltZSBEZXZvcyA8bWF4aW1lLmRldm9zQHN0dWRlbnQua3VsZXV2
ZW4uYmU+wpAEExYIADgWIQTB8z7iDFKP233XAR9J4+4iGRcl7gUCX4ch6AIbAwUL
CQgHAwUVCgkICwUWAgMBAAIeAQIXgAAKCRBJ4+4iGRcl7japAQC3opZ2KGWzWmRc
/gIWSu0AAcfMwyinFEEPa/QhUt2CogD/e2RdF4CYAgaRHJJmZ9WU7piKbLZ7llB4
LzgezVDHggzNJU1heGltZSBEZXZvcyA8bWF4aW1lZGV2b3NAdGVsZW5ldC5iZT7C
kAQTFggAOBYhBMHzPuIMUo/bfdcBH0nj7iIZFyXuBQJf56ycAhsDBQsJCAcDBRUK
CQgLBRYCAwEAAh4BAheAAAoJEEnj7iIZFyXujpQBAKV1SwDDl4f24rXciDlB9L8W
ycZt30CgbewMSRQk4mvbAP9dFMbVVixYBd6C8cfhR+NsOBGiOJnQABlUmgNuqGFJ
Dc44BF+HIegSCisGAQQBl1UBBQEBB0BOlzIWiJzgobMF6/cqwLaLk7jIcFSZ++c0
k9cCNT6YXwMBCAfCeAQYFggAIBYhBMHzPuIMUo/bfdcBH0nj7iIZFyXuBQJfhyHo
AhsMAAoJEEnj7iIZFyXuMr0BAJc8cl5PGvVmVuSQVKjleNl4DK1/XAaPAYPe34AE
fZJPAP9IqLCQhH/FeJanHqBP8gNdGNI2qn8RnnLVfRJgUjZ1BA==
=OVqp
-----END PGP PUBLIC KEY BLOCK-----
OpenPGP_signature (application/pgp-signature, 236 B) - not displayed