netsec-sig - Re: [Security-WG] DNS Location record question
Subject: Internet2 Network Security SIG
List archive
- From: Jeff Bartig <>
- To:
- Subject: Re: [Security-WG] DNS Location record question
- Date: Tue, 05 Sep 2017 09:40:36 -0500
- Authentication-results: internet2.edu; dkim=none (message not signed) header.d=none;internet2.edu; dmarc=none action=none header.from=internet2.edu;
- Ironport-phdr: 9a23:KSNVOxTxQLjBGyeby0c2Y4p2C9psv+yvbD5Q0YIujvd0So/mwa6ybRGN2/xhgRfzUJnB7Loc0qyN4vCmATRIyK3CmUhKSIZLWR4BhJdetC0bK+nBN3fGKuX3ZTcxBsVIWQwt1Xi6NU9IBJS2PAWK8TW94jEIBxrwKxd+KPjrFY7OlcS30P2594HObwlSijewZbB/IA+qoQnNq8IbnZZsJqEtxxXTv3BGYf5WxWRmJVKSmxbz+MK994N9/ipTpvws6ddOXb31cKokQ7NYCi8mM30u683wqRbDVwqP6WACXWgQjxFFHhLK7BD+Xpf2ryv6qu9w0zSUMMHqUbw5Xymp4qF2QxHqlSgHLSY0/mLZhMJwgq1UrwyvqQFxw4HWfI6VNeFzcbnBcdwAX2VNQtxcWzFHD4ihb4UPFe0BPeNAoof5uVQOoxW+DhSxCez10D9Imn723aIn2OkmEwHJxxYvH8gSsHTVo9X4L6YSUeapzKbW1zXDae1Z2Svj5ITSbB8uvOyMUKt2fMHMx0cvEAbFgU+RqYzjJz6VzvoCvHaB7+phU+KvhHMopBprrjezwccsj5HFhoQLxVHK9SR0zpg5Kse/SEFhe9KkFoVftz2CO4t3XMwiX29otDw9yr0ctp62ejUBxpc/xxPHdfCLbomF7gjtWeqPOzt0mXFodK6lixqv8kWtxfXwWtSo3FtFtCZJjNbBu34X2xDO5cWKSOFx8lm81TuA0Q3Y9/tKLloulaXBLp4s2r4wmYQXsUTEBiL4gFn7gqiKekk54+Sl9vzpb7v/qp+bLIB7lBvyMqMzmsyjGus4NRUOX26G9uimzL3j50r5QKlUgfIqjqnZsZfaJcIBqq6+Hg9VzoIj6xG4DzelytgXgX4HLFdddBKGiYjmJU3OLejmAfuiglmgijlmy+7cMrH8AZjBMmLPnKricLty80JczRA8zdFb55JaELEBJ/fzV1fztNPDFBA5KRC0w+foCNhm14MeX36PDbGDMKPUr1CI+vwjL/OSa4AIpTbxM+Il6OL2jX8lhV8derGk3YAJZ3+kA/RmOUSZYWbsg9sYH2YKsREzTOjriF2ZTT5TfGi+U7g95jE9FIKpE53DRoazj7ydwiu3BINZaX1bCgPELXC9bIiPRu0NdDPXPcBJkzoYWKKnRpN7kxyiqVzU0b1ie8jZ9CNQn5v5yNl6r7nRnxgo6T17J8Wbz2yXSWxoxCUFSyJgj/M3mlB01lrWifswuPdfD9EGv/4=
- Spamdiagnosticoutput: 1:0
On 9/5/17, 9:28
AM, Michael H Lambert wrote:
On 5 Sep 2017, at 10:19, Matthew J Zekauskas wrote: FWIW, I think the accuracy/precision values in the records are all defaults (which would lead me to believe they were not explicitly set). I could be wrong; I just glanced at the RFC <https://tools.ietf.org/html/rfc1876>.I concur that that's the likeliest possibility. Again, I'll reiterate that I don't think it's worth the effort to change them. I agree. I don't see the value of devoting the software development effort to reducing the precision. As was pointed out, even without the LOC records, it is easy to guess our PoP locations, even with more precision than the LOC coordinates provide. There are many public sources of PoP locations and fiber paths that could easily be used to locate Internet2's physical infrastructure. For the particular example that was given, rtsw.newy32aoa.net.internet2.edu, I can even guess the address is 32 Avenue of the Americas by just seeing the A record and knowing a little bit about colo space in New York. Maybe we should get rid of the A, AAAA, and PTR records too? (I unfortunately feel the need to point out that was engineering sarcasm, not a security recommendation). Jeff |
- Re: [Security-WG] DNS Location record question, (continued)
- Re: [Security-WG] DNS Location record question, Steven Wallace, 09/05/2017
- Re: [Security-WG] DNS Location record question, Jason Zurawski, 09/05/2017
- Re: [Security-WG] DNS Location record question, James Deaton, 09/05/2017
- Re: [Security-WG] DNS Location record question, Chris Wilkinson, 09/05/2017
- Re: [Security-WG] DNS Location record question, Michael H Lambert, 09/05/2017
- Re: [Security-WG] DNS Location record question, Steven Wallace, 09/05/2017
- Re: [Security-WG] DNS Location record question, Matthew J Zekauskas, 09/05/2017
- Re: [Security-WG] DNS Location record question, Michael H Lambert, 09/05/2017
- Re: [Security-WG] DNS Location record question, Steven Wallace, 09/05/2017
- Re: [Security-WG] DNS Location record question, Chris Wilkinson, 09/05/2017
- Re: [Security-WG] DNS Location record question, Jeff Bartig, 09/05/2017
- Re: [Security-WG] DNS Location record question, Michael H Lambert, 09/05/2017
- Re: [Security-WG] DNS Location record question, Matthew J Zekauskas, 09/05/2017
- Re: [Security-WG] DNS Location record question, Steven Wallace, 09/05/2017
- Re: [Security-WG] DNS Location record question, Michael H Lambert, 09/05/2017
- Re: [Security-WG] DNS Location record question, David Farmer, 09/05/2017
- Re: [Security-WG] DNS Location record question, Paul Howell, 09/05/2017
Archive powered by MHonArc 2.6.19.