Skip to Content.
Sympa Menu

netsec-sig - Re: [Security-WG] DNS Location record question

Subject: Internet2 Network Security SIG

List archive

Re: [Security-WG] DNS Location record question


Chronological Thread 
  • From: Jeff Bartig <>
  • To:
  • Subject: Re: [Security-WG] DNS Location record question
  • Date: Tue, 05 Sep 2017 09:40:36 -0500
  • Authentication-results: internet2.edu; dkim=none (message not signed) header.d=none;internet2.edu; dmarc=none action=none header.from=internet2.edu;
  • Ironport-phdr: 9a23:KSNVOxTxQLjBGyeby0c2Y4p2C9psv+yvbD5Q0YIujvd0So/mwa6ybRGN2/xhgRfzUJnB7Loc0qyN4vCmATRIyK3CmUhKSIZLWR4BhJdetC0bK+nBN3fGKuX3ZTcxBsVIWQwt1Xi6NU9IBJS2PAWK8TW94jEIBxrwKxd+KPjrFY7OlcS30P2594HObwlSijewZbB/IA+qoQnNq8IbnZZsJqEtxxXTv3BGYf5WxWRmJVKSmxbz+MK994N9/ipTpvws6ddOXb31cKokQ7NYCi8mM30u683wqRbDVwqP6WACXWgQjxFFHhLK7BD+Xpf2ryv6qu9w0zSUMMHqUbw5Xymp4qF2QxHqlSgHLSY0/mLZhMJwgq1UrwyvqQFxw4HWfI6VNeFzcbnBcdwAX2VNQtxcWzFHD4ihb4UPFe0BPeNAoof5uVQOoxW+DhSxCez10D9Imn723aIn2OkmEwHJxxYvH8gSsHTVo9X4L6YSUeapzKbW1zXDae1Z2Svj5ITSbB8uvOyMUKt2fMHMx0cvEAbFgU+RqYzjJz6VzvoCvHaB7+phU+KvhHMopBprrjezwccsj5HFhoQLxVHK9SR0zpg5Kse/SEFhe9KkFoVftz2CO4t3XMwiX29otDw9yr0ctp62ejUBxpc/xxPHdfCLbomF7gjtWeqPOzt0mXFodK6lixqv8kWtxfXwWtSo3FtFtCZJjNbBu34X2xDO5cWKSOFx8lm81TuA0Q3Y9/tKLloulaXBLp4s2r4wmYQXsUTEBiL4gFn7gqiKekk54+Sl9vzpb7v/qp+bLIB7lBvyMqMzmsyjGus4NRUOX26G9uimzL3j50r5QKlUgfIqjqnZsZfaJcIBqq6+Hg9VzoIj6xG4DzelytgXgX4HLFdddBKGiYjmJU3OLejmAfuiglmgijlmy+7cMrH8AZjBMmLPnKricLty80JczRA8zdFb55JaELEBJ/fzV1fztNPDFBA5KRC0w+foCNhm14MeX36PDbGDMKPUr1CI+vwjL/OSa4AIpTbxM+Il6OL2jX8lhV8derGk3YAJZ3+kA/RmOUSZYWbsg9sYH2YKsREzTOjriF2ZTT5TfGi+U7g95jE9FIKpE53DRoazj7ydwiu3BINZaX1bCgPELXC9bIiPRu0NdDPXPcBJkzoYWKKnRpN7kxyiqVzU0b1ie8jZ9CNQn5v5yNl6r7nRnxgo6T17J8Wbz2yXSWxoxCUFSyJgj/M3mlB01lrWifswuPdfD9EGv/4=
  • Spamdiagnosticoutput: 1:0

On 9/5/17, 9:28 AM, Michael H Lambert wrote:
On 5 Sep 2017, at 10:19, Matthew J Zekauskas  wrote:

FWIW, I think the accuracy/precision values in the records are all defaults (which would lead me to believe they were not explicitly set).    I could be wrong; I just glanced at the RFC <https://tools.ietf.org/html/rfc1876>.
I concur that that's the likeliest possibility.  Again, I'll reiterate that I don't think it's worth the effort to change them.

I agree.  I don't see the value of devoting the software development effort to reducing the precision.  As was pointed out, even without the LOC records, it is easy to guess our PoP locations, even with more precision than the LOC coordinates provide.  There are many public sources of PoP locations and fiber paths that could easily be used to locate Internet2's physical infrastructure.

For the particular example that was given, rtsw.newy32aoa.net.internet2.edu, I can even guess the address is 32 Avenue of the Americas by just seeing the A record and knowing a little bit about colo space in New York.  Maybe we should get rid of the A, AAAA, and PTR records too?  (I unfortunately feel the need to point out that was engineering sarcasm, not a security recommendation).

Jeff

--
Jeff Bartig
Interconnection Architect
Internet2  AS11164 / AS11537
+1-608-616-9908



Archive powered by MHonArc 2.6.19.

Top of Page