Re: same-origin assertions in the DNS (Fwd: [apps-discuss] draft-sullivan-domain-origin-assert-00)

On May 9, 2012, at 11:25 PM, Andrew Sullivan <ajs@anvilwalrusden.com> wrote:

> Hi,
> 
> I'm responding to two messages at once because I didn't receive the
> earlier of these.  I should note that I'm not actually a subscriber to
> any w3c list, and so if one wants me to address a particular objection
> one needs to cc: me for the time being.  I appreciate the comments,
> however!
> 
> On Thu, May 10, 2012 at 07:17:40AM +0200, Henrik Nordström wrote:
>> ons 2012-05-09 klockan 22:10 -0700 skrev Maciej Stachowiak:
>> 
>>> Treating separate domains as same-origin based on DNS records seems
>>> extremely dangerous
> 
> I'm not sure how I can respond to this objection, given that the
> entire idea of "same origin" without DNS is hard for me to understand.
> What do you mean by it?  I think the draft actually points out that,
> if both sides don't agree or you're not using DNSSEC (or both), there
> are problems.  Is that not clear enough?

The draft doesn't clearly state what to do with the information in BOUND records, so it's not clear enough. Does the spec require supporting the cases where "there are problems"? Does it require not doing so? It's impossible to tell. 

Regards,
Maciej

Received on Sunday, 13 May 2012 10:44:43 UTC