<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.dkgjsal-dprive-unilateral-probing" target="https://datatracker.ietf.org/doc/html/draft-dkgjsal-dprive-unilateral-probing-02">
   <front>
      <title>Unilateral Opportunistic Deployment of Encrypted Recursive-to-Authoritative DNS</title>
      <author initials="D. K." surname="Gillmor" fullname="Daniel Kahn Gillmor">
         <organization>American Civil Liberties Union</organization>
      </author>
      <author initials="J." surname="Salazar" fullname="Joey Salazar">
         <organization>ARTICLE 19</organization>
      </author>
      <date month="January" day="26" year="2022" />
      <abstract>
	 <t>   This draft sets out steps that DNS servers (recursive resolvers and
   authoritative servers) can take unilaterally (without any
   coordination with other peers) to defend DNS query privacy against a
   passive network monitor.  The steps in this draft can be defeated by
   an active attacker, but should be simpler and less risky to deploy
   than more powerful defenses.  The draft also introduces (but does not
   try to specify) the semantics of signalling that would permit defense
   against an active attacker.

   The goal of this draft is to simplify and speed deployment of
   opportunistic encrypted transport in the recursive-to-authoritative
   hop of the DNS ecosystem.  With wider easy deployment of the
   underlying transport on an opportunistic basis, we hope to facilitate
   the future specification of stronger cryptographic protections
   against more powerful attacks.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-dkgjsal-dprive-unilateral-probing-02" />
   
</reference>
