Re: [DNSOP] DNS privacy : now at least two drafts

2014-03-16 Thread Florian Weimer
* Mark Andrews: >>>Another note is that the answer to the NS query, unlike the referral >>>sent when the question is a full qname, is in the Answer section, not >>>in the Authoritative section. It has probably no practical >>>consequences. >> >> Most resolvers do not make NS quer

Re: [DNSOP] An approach to DNS privacy

2014-03-16 Thread Florian Weimer
* Phillip Hallam-Baker: >> If your ordinary resolver operator is a "carrier" is somewhat >> questionable, but resolver operators generally comply with requests >> for cleartext copies of traffic transitioning through their networks. >> >> I have no doubts that these operators will ask implementors

Re: [DNSOP] DNS privacy : now at least two drafts

2014-03-16 Thread Florian Weimer
* Florian Weimer: > There is another privacy-enhancing approach that is not mentioned in > the draft: defensive delegations. For example, with current resolver > behavior, the lack of a delegation for 1.E164.ARPA means that queries > under that tree are sent to the E164.ARPA servers, which are sc