Live data from Hacker News

Verifying Wikileaks DKIM-Signatures

solsticlipse.com

31–38 of 38 posts

Re: Verifying Wikileaks DKIM-Signatures

#31
I think the major problem of this election is deciding on what the truth is but since everything can be rewritten, links broken, and data lost there is too much noise to get a clear signal. We need a trust/identity protocol that allows us to take history in account I wrote a draft of a whitepaper on a possible way to implement this with blockchains and cross-signing https://hashd.in/hashd-in-draft0/

Re: Verifying Wikileaks DKIM-Signatures

#32

Earlier quoted context omitted.

Well, with you putting it that way, I can't say too much against the tactic. :) It's actually quite similar to what I wanted to convince courts to allow as a default in the event that they don't already. That is to let me withhold a smoking gun on a case where they might get low charges or punishment due to technicalities. Let them argue their case with lies to the court. Then, show the smoking gun with a follow-up o…

As far as I know, only the prosecution has an obligation to provide exculpatory evidence. That said, if you wait to half way through your murder trial to produce the video of the one armed man stuffing the body in your trunk, that probably sets you up for interfering with a police investigation, or aiding and abetting, etc.

(Sighs) That's a good point. They mighy try to score an extra conviction on their record in same trial.

Re: Verifying Wikileaks DKIM-Signatures

#33
post #9
post #8

Very cool research! Is there any proof-of-existence archive of DKIM keys or DNS record changes in general? Seems like a perfect use case for blockchain[1]. If the DKIM keys were rolled over or replaced since they were originally sent out, there wouldn't be anything to compare them against. Having a record that can show proof-of-existence (at a min point in time) would cover that. [1]: Ha! I knew there would eventuall…

This just requires the inability-to-rewind property of the blockchain, doesn't require there to be one centralized log of events and doesn't require protections against flooding with data (if we verify that the DNS records are correct at the point of inserting). This makes a certificate-transparency-like solution just as good and much less complicated (one can arguably call that blockchain, but usually people mean by…

Well, we've been making validated structures where a checksum (essentially a pre-cryptographic hash) of the last data-block is included in the next since the sixties. (And I suspect much further back in an accounting context.)

The difference these days is a protection, via proof-of-work, against just creating a new, valid, chain by editing the old one.

That proof of work, to be translatable into a dollar value, requires a market for the proofs and that's the currency part. (Without that you don't know the true market value of the energy required for the PoW.)

Re: Verifying Wikileaks DKIM-Signatures

#34
post #30

Earlier quoted context omitted.

I'm pretty sure a Bernie Sanders supporter would say this goes way beyond that. Leaking plans from one candidate to another is beyond best for the party.

IDK, as a bernie voter in the primary, I don't see this as surprising or problematic, at least not if I'm reading these correctly.

Ok, nothing will shock you then. If you don't believe the head of the party giving insider information from people who were supposed to be working for Sen. Sanders campaign feeding his opponent doesn't cause you fits, then all is fair game.

anyway search #PodestaEmails14 on twitter for the rest

Re: Verifying Wikileaks DKIM-Signatures

#35
post #13

Earlier quoted context omitted.

Specific examples that are in your opinion most worthy of authentication?

I'm at work so, and I'll get the rest later tonight (Twitter won't load for me now anyway): https://wikileaks.org/podesta-emails/emailid/3023 https://wikileaks.org/dnc-emails/emailid/4776 https://wikileaks.org/dnc-emails/emailid/10808 wow, what the heck, I'll get more later but a lot of sites just aren't loading [edit: guess its not just me https://news.ycombinator.com/item?id=12762397 ]

That third email looks like they were asking the DNC for comment on a planned article, which is a standard reporting practice.

Edit: researched more, and while asking for comment is standard practice, sharing a full article pre-edit is not.

Re: Verifying Wikileaks DKIM-Signatures

#36
post #7
post #3

Yes, the interesting thing would be if any emails with controversial content can be verified. I don't think there were any real bombshells in the wikileaks emails, but still...

Most of the things i've came across that are being brought up as bombshells are actually incoming mails from outside the campaign. Plus there is a number of things that are being put out of context like the Hillary hates Everyday Americans thing, where it's clear from the context that it is just about the phrasing

There are a lot of things that are horrible in these leaks. For example, here are four: http://www.usatoday.com/story/news/politics/onpolitics/2016/...

From those four, the following are "verified" by the OP of this thread.

    - 5205: The Clinton's seem to have had access to the questions to a debate.
    - 4178: The Clinton's seem to have been advised about the investigation into their emails from someone in the DOJ. 
These are two out of 4. I'll edit this if someone links other articles and I'll check them across this link.

Re: Verifying Wikileaks DKIM-Signatures

#37
post #7

Earlier quoted context omitted.

Most of the things i've came across that are being brought up as bombshells are actually incoming mails from outside the campaign. Plus there is a number of things that are being put out of context like the Hillary hates Everyday Americans thing, where it's clear from the context that it is just about the phrasing

There are a lot of things that are horrible in these leaks. For example, here are four: http://www.usatoday.com/story/news/politics/onpolitics/2016/... From those four, the following are "verified" by the OP of this thread. - 5205: The Clinton's seem to have had access to the questions to a debate. - 4178: The Clinton's seem to have been advised about the investigation into their emails from someone in the DOJ. These…

The DOJ status hearing is one of the perfect examples of something out of WikiLeaks that was way blown out of proportion by tweeting first, ask questions later.

http://mediamatters.org/research/2016/10/11/nbc-reporter-sug...

http://www.politico.com/blogs/under-the-radar/2016/10/trump-...

On the debate thing, a Bernie senior aide came out and said that she gave guidance to Sanders campaign too. The most nefarious scenario would be that Brazile gave questions to Clinton to prop her up. The less nefarious scenario would be that Brazile from her DNC position tried to get the best out of both candidates to not embarrass the DNC.

Note that Brazile and CNN are still denying she could have gotten access to the townhall questions. I agree though that networks should not put themselves in these kind of conflict of interests, by hiring a political commentator that is paid by the DNC at the same time, or a former campaign manager that is still on the payroll of said campaign like Corey Lewandowski.

http://www.latimes.com/nation/politics/trailguide/la-na-trai...

Re: Verifying Wikileaks DKIM-Signatures

#38
post #12

There has been no evidence yet that the emails were doctored. What there has been, as one journalist put it, was efforts to conflate "wikileaks emails" with "unsourced shit I saw on Twitter".

No evidence that they were doctored, but there are still plenty of complete fakes that were tweeted out by others, which were taken serious by way too many people including FOX news.

http://www.snopes.com/hillary-calls-voters-bucket-of-losers/

Post reply on HN