Perhaps a simple timestamped based appendage can be added for the sake of email client authentication. In other words reject the email if the signature is older than a few hours/minutes.
Ok Google: please publish your DKIM secret keys
21–30 of 492 posts
Re: Ok Google: please publish your DKIM secret keys
#22Re: Ok Google: please publish your DKIM secret keys
#23So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. It seems to me that especially when an elected official has something they don't want others to know about that…
Re: Ok Google: please publish your DKIM secret keys
#24Re: Ok Google: please publish your DKIM secret keys
#25Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?
Re: Ok Google: please publish your DKIM secret keys
#26> Google could launch the process right now by releasing its ancient 2016-era private keys. Since the secrecy of these serves literally no security purpose at this point, except for allowing third parties to verify email leaks, there’s no case for keeping these values secret at all. I've used Google's DKIM signatures to timestamp call recordings for years by putting a sha256 of the attached recording in the subject,…
Re: Ok Google: please publish your DKIM secret keys
#27I find it pretty funny that the author wrote this because they are salty that the leaked hunter Biden emails could be verified with DKIM
This is false. The article pointed to DKIM being used for journalistic verification for multiple parties (persons and organizations) across the political spectrum. It's not salty or overtly political.
Re: Ok Google: please publish your DKIM secret keys
#28So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. It seems to me that especially when an elected official has something they don't want others to know about that…
The threat is not limited to politicians. Anyone (including you and your family members) could be blackmailed or otherwise publicly embarrassed.
... for what they actually did.
You think the solution is allowing people to be blackmailed or otherwise publicly embarrassed for things they didn't do, while removing their ability to verify that they didn't do them?
Re: Ok Google: please publish your DKIM secret keys
#29If a hacker were to retrieve some emails before the DKIM key was made public, they could then sign their hacked emails with their own timestamped signature, proving that they are in fact authentic (since the signed timestamp shows that they were retrieved before the DKIM key was released).
Therefore, by rotating the DKIM keys "every few weeks" you are giving the would-be hackers a deadline to retrieve the target emails - a few weeks - which could lead to hackers preemptively hacking as many possibly useful accounts as possible (not just the ones they know they want at a given moment), every few weeks.
(The merits of OP's argument notwithstanding)
Re: Ok Google: please publish your DKIM secret keys
#30So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. It seems to me that especially when an elected official has something they don't want others to know about that…
He mentions the politicians because those were high profile cases. This could be used against anybody, not just politicians.
> It seems to me that especially when an elected official has something they don't want others to know about that it should be public knowledge.
Is this true of everybody else as well? Should anybody be able to deny an email they sent in the past? If so, we have to take this step.