nanog mailing list archives
Re: Question about DNS naming conventions
From: Jack Bates <jbates () paradoxnetworks net>
Date: Wed, 12 Feb 2025 11:58:31 -0600
On 2/12/2025 8:15 AM, William Herrin wrote:
The software has no concept of what the data is and must provide the user the desired confidentiality and integrity, which unfortunately means forced deprecation and possible lack of Availability. This also applies to features such as HTTPS RRs in DNS that aren't always configured correctly and ECH prohibits fallback when it breaks; choosing security over availability.And then of course there's the completely fair question of whether it's sensible to forcibly deprecate older security protocols when accessing information that's also offered over fully unencrypted channels. Confidentiality, Integrity AND Availability. Lotta wounds to availability from forced deprecation. Whole lot.
I do wish browsers were better at explaining why something breaks, though. It's especially bad with embedded content where it just doesn't work and even dev tools might show "server disconnected prematurely" or something similar.
Jack
Current thread:
- Question about DNS naming conventions Joel Sommers (Feb 11)
- Re: Question about DNS naming conventions William Herrin (Feb 11)
- Re: Question about DNS naming conventions John Levine (Feb 11)
- Re: Question about DNS naming conventions Steven Champeon (Feb 13)
- Re: Question about DNS naming conventions John Levine (Feb 11)
- Re: Question about DNS naming conventions Thomas Mieslinger via NANOG (Feb 12)
- Re: Question about DNS naming conventions Mark Tinka (Feb 12)
- Re: Question about DNS naming conventions Thomas Mieslinger via NANOG (Feb 12)
- Re: Question about DNS naming conventions Mark Tinka (Feb 12)
- <Possible follow-ups>
- Re: Question about DNS naming conventions nanog--- via NANOG (Feb 12)
- Re: Question about DNS naming conventions William Herrin (Feb 12)
- Re: Question about DNS naming conventions Jack Bates (Feb 12)
- Re: Question about DNS naming conventions William Herrin (Feb 12)
- Re: Question about DNS naming conventions Jack Bates (Feb 12)
- Re: Question about DNS naming conventions William Herrin (Feb 12)
- Re: Question about DNS naming conventions William Herrin (Feb 12)
- Re: Question about DNS naming conventions William Herrin (Feb 11)
