ietf dns privacy
play

IETF DNS Privacy A short introduction and update on DPRIVE Warren - PowerPoint PPT Presentation

IETF DNS Privacy A short introduction and update on DPRIVE Warren Kumari 1 ICANN-TechDay / Dublin, .IE - 10/2015 - Ver:01 Whats the problem? 2 Whats the problem? I hate doing expense reports 2 Whats the problem? I hate doing


  1. IETF DNS Privacy A short introduction and update on DPRIVE Warren Kumari 1 ICANN-TechDay / Dublin, .IE - 10/2015 - Ver:01

  2. What’s the problem? 2

  3. What’s the problem? I hate doing expense reports… 2

  4. What’s the problem? I hate doing expense reports… so I procrastinate… 2

  5. What’s the problem? I hate doing expense reports… so I procrastinate… … and tidy up my desk 2

  6. What’s the problem? I hate doing expense reports… so I procrastinate… … and tidy up my desk … and clean all the crumbs out of my keyboard 2

  7. What’s the problem? I hate doing expense reports… so I procrastinate… … and tidy up my desk … and clean all the crumbs out of my keyboard … and do the laundry 2

  8. What’s the problem? I hate doing expense reports… so I procrastinate… … and tidy up my desk … and clean all the crumbs out of my keyboard … and do the laundry … and then start reading Wikipedia…. 2

  9. What’s the problem? (cont) Attribution: xkcd is licensed by Randall Munroe under a Creative Commons Attribution-NonCommercial 2.5 3 License - XKCD from http://imgs.xkcd.com/comics/the_problem_with_wikipedia.png

  10. What’s the problem? (cont) “99 Luftballons” Attribution: xkcd is licensed by Randall Munroe under a Creative Commons Attribution-NonCommercial 2.5 3 License - XKCD from http://imgs.xkcd.com/comics/the_problem_with_wikipedia.png

  11. What’s the problem? (cont) “99 Luftballons” → “99 Red Balloons” Attribution: xkcd is licensed by Randall Munroe under a Creative Commons Attribution-NonCommercial 2.5 3 License - XKCD from http://imgs.xkcd.com/comics/the_problem_with_wikipedia.png

  12. What’s the problem? (cont) “99 Luftballons” → “99 Red Balloons” → Nuclear accidents Attribution: xkcd is licensed by Randall Munroe under a Creative Commons Attribution-NonCommercial 2.5 3 License - XKCD from http://imgs.xkcd.com/comics/the_problem_with_wikipedia.png

  13. What’s the problem? (cont) “99 Luftballons” → “99 Red Balloons” → Nuclear accidents → [ Three hours of fascinated clicking ] Attribution: xkcd is licensed by Randall Munroe under a Creative Commons Attribution-NonCommercial 2.5 3 License - XKCD from http://imgs.xkcd.com/comics/the_problem_with_wikipedia.png

  14. What’s the problem? (cont) “99 Luftballons” → “99 Red Balloons” → Nuclear accidents → [ Three hours of fascinated clicking ] → websites on the efficiency of centrifugal enrichment of uranium-235 Attribution: xkcd is licensed by Randall Munroe under a Creative Commons Attribution-NonCommercial 2.5 3 License - XKCD from http://imgs.xkcd.com/comics/the_problem_with_wikipedia.png

  15. So what? 4

  16. So what? All of the URLs I went to were https:// , so the content is protected, no-one is likely to get the wrong idea… 4

  17. So what? All of the URLs I went to were https:// , so the content is protected, no-one is likely to get the wrong idea… …but many of the domain names that my machine looked up were, um, suspicious, especially if taken out of context. 4

  18. So what? All of the URLs I went to were https:// , so the content is protected, no-one is likely to get the wrong idea… …but many of the domain names that my machine looked up were, um, suspicious, especially if taken out of context. ... and it has become clear that governments and pervasive monitors are using actively exploiting metadata for targeting. 4

  19. So what? All of the URLs I went to were https:// , so the content is protected, no-one is likely to get the wrong idea… …but many of the domain names that my machine looked up were, um, suspicious, especially if taken out of context. ... and it has become clear that governments and pervasive monitors are using actively exploiting metadata for targeting. Am I really concerned about this particular case? Nah, I’m not that paranoid, but it makes a good example :-) 4

  20. RFC 7258 - Pervasive Monitoring Is an Attack The IETF community's technical assessment is that PM is an attack on the privacy of Internet users and organisations. The IETF community has expressed strong agreement that PM is an attack that needs to be mitigated where possible, via the design of protocols that make PM significantly more expensive or infeasible. 5

  21. QNAME Minimization draft-ietf-dnsop-qname-minimisation * [*]:Submitted to IESG for Publication 6

  22. How DNS works Root DNS .com http://www.example.com example.com 7

  23. How DNS works Root www.example.com? DNS .com http://www.example.com example.com 7

  24. How DNS works ? m Root o c . s i e r e h w www.example.com? DNS .com http://www.example.com example.com 7

  25. How DNS works ? m Root o c . s i e r e .com is at 1.2.3.4 h w www.example.com? DNS .com http://www.example.com example.com 7

  26. How DNS works ? m Root o c . s i e r e .com is at 1.2.3.4 h w where is .example.com? www.example.com? DNS .com http://www.example.com example.com 7

  27. How DNS works ? m Root o c . s i e r e .com is at 1.2.3.4 h w where is .example.com? www.example.com? DNS .com example.com is at 2.3.4.5 http://www.example.com example.com 7

  28. How DNS works ? m Root o c . s i e r e .com is at 1.2.3.4 h w where is .example.com? www.example.com? DNS .com example.com is at 2.3.4.5 http://www.example.com w h e r e i s w w w . e x a m p l e . c o m ? example.com 7

  29. How DNS works ? m Root o c . s i e r e .com is at 1.2.3.4 h w where is .example.com? www.example.com? DNS .com example.com is at 2.3.4.5 http://www.example.com w h e r e i s w w w . e x a m p l e . c o m ? example.com www.example.com is at 3.4.5.6 7

  30. How DNS works ? m Root o c . s i e r e .com is at 1.2.3.4 h w where is .example.com? www.example.com? DNS .com 3.4.5.6 example.com is at 2.3.4.5 http://www.example.com w h e r e i s w w w . e x a m p l e . c o m ? example.com www.example.com is at 3.4.5.6 7

  31. How DNS actually works Root DNS .com http://www.example.com example.com 8

  32. How DNS actually works Root www.example.com? DNS .com http://www.example.com example.com 8

  33. How DNS actually works ? m o c . e l p Root m a x e . w w w s i e r e h w www.example.com? DNS .com http://www.example.com example.com 8

  34. How DNS actually works ? m o c . e l p Root m a x e . w w .com is at 1.2.3.4 w s i e r e h w www.example.com? DNS .com http://www.example.com example.com 8

  35. How DNS actually works ? m o c . e l p Root m a x e . w w .com is at 1.2.3.4 w s i e r e h w where is www.example.com? www.example.com? DNS .com http://www.example.com example.com 8

  36. How DNS actually works ? m o c . e l p Root m a x e . w w .com is at 1.2.3.4 w s i e r e h w where is www.example.com? www.example.com? DNS .com example.com is at 2.3.4.5 http://www.example.com example.com 8

  37. How DNS actually works ? m o c . e l p Root m a x e . w w .com is at 1.2.3.4 w s i e r e h w where is www.example.com? www.example.com? DNS .com example.com is at 2.3.4.5 http://www.example.com w h e r e i s w w w . e x a m p l e . c o m ? example.com 8

  38. How DNS actually works ? m o c . e l p Root m a x e . w w .com is at 1.2.3.4 w s i e r e h w where is www.example.com? www.example.com? DNS .com example.com is at 2.3.4.5 http://www.example.com w h e r e i s w w w . e x a m p l e . c o m ? example.com www.example.com is at 3.4.5.6 8

  39. How DNS actually works ? m o c . e l p Root m a x e . w w .com is at 1.2.3.4 w s i e r e h w where is www.example.com? www.example.com? DNS .com 3.4.5.6 example.com is at 2.3.4.5 http://www.example.com w h e r e i s w w w . e x a m p l e . c o m ? example.com www.example.com is at 3.4.5.6 8

  40. QNAME attack surface ? m o c . e l p Root m a x e . w w .com is at 1.2.3.4 w s i e r e h w where is www.example.com? www.example.com? DNS .com 3.4.5.6 example.com is at 2.3.4.5 http://www.example.com w h e r e i s w w w . e x a m p l e . c o m ? example.com www.example.com is at 3.4.5.6 9

  41. QNAME attack surface ? m o c . e l p Root m a x e . w w .com is at 1.2.3.4 w s i e r e h w where is www.example.com? www.example.com? DNS .com 3.4.5.6 example.com is at 2.3.4.5 http://www.example.com w h e r e i s w w w . e x a m p l e . c o m ? example.com www.example.com is at 3.4.5.6 9

  42. QNAME attack surface ? m o c . e l p Root m a x e . w w .com is at 1.2.3.4 w s i e r e h w where is www.example.com? www.example.com? DNS .com 3.4.5.6 example.com is at 2.3.4.5 http://www.example.com w h e r e i s w w w . e x a m p l e . c o m ? example.com www.example.com is at 3.4.5.6 9

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend