Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

21–30 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#21
I like the idea of non-repudiation, let the chips fall where they may when such authentic email is maliciously dumped.

Perhaps a simple timestamped based appendage can be added for the sake of email client authentication. In other words reject the email if the signature is older than a few hours/minutes.

Re: Ok Google: please publish your DKIM secret keys

#23
post #18

So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. It seems to me that especially when an elected official has something they don't want others to know about that…

The threat is not limited to politicians. Anyone (including you and your family members) could be blackmailed or otherwise publicly embarrassed.

Re: Ok Google: please publish your DKIM secret keys

#25
I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail.

Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?

Re: Ok Google: please publish your DKIM secret keys

#26
post #10

> Google could launch the process right now by releasing its ancient 2016-era private keys. Since the secrecy of these serves literally no security purpose at this point, except for allowing third parties to verify email leaks, there’s no case for keeping these values secret at all. I've used Google's DKIM signatures to timestamp call recordings for years by putting a sha256 of the attached recording in the subject,…

The answer to every problem: blockchain!

Re: Ok Google: please publish your DKIM secret keys

#27
post #20

I find it pretty funny that the author wrote this because they are salty that the leaked hunter Biden emails could be verified with DKIM

This is false. The article pointed to DKIM being used for journalistic verification for multiple parties (persons and organizations) across the political spectrum. It's not salty or overtly political.

Their lack of addressing Hunter's emails says the most.

Re: Ok Google: please publish your DKIM secret keys

#28
post #23
post #18

So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. It seems to me that especially when an elected official has something they don't want others to know about that…

The threat is not limited to politicians. Anyone (including you and your family members) could be blackmailed or otherwise publicly embarrassed.

> The threat is not limited to politicians. Anyone (including you and your family members) could be blackmailed or otherwise publicly embarrassed.

... for what they actually did.

You think the solution is allowing people to be blackmailed or otherwise publicly embarrassed for things they didn't do, while removing their ability to verify that they didn't do them?

Re: Ok Google: please publish your DKIM secret keys

#29
Perversely, this solution could result in MORE emails being hacked MORE OFTEN. Allow me to explain.

If a hacker were to retrieve some emails before the DKIM key was made public, they could then sign their hacked emails with their own timestamped signature, proving that they are in fact authentic (since the signed timestamp shows that they were retrieved before the DKIM key was released).

Therefore, by rotating the DKIM keys "every few weeks" you are giving the would-be hackers a deadline to retrieve the target emails - a few weeks - which could lead to hackers preemptively hacking as many possibly useful accounts as possible (not just the ones they know they want at a given moment), every few weeks.

(The merits of OP's argument notwithstanding)

Re: Ok Google: please publish your DKIM secret keys

#30
post #18

So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. It seems to me that especially when an elected official has something they don't want others to know about that…

> that so people can't use email to blackmail politicians?

He mentions the politicians because those were high profile cases. This could be used against anybody, not just politicians.

> It seems to me that especially when an elected official has something they don't want others to know about that it should be public knowledge.

Is this true of everybody else as well? Should anybody be able to deny an email they sent in the past? If so, we have to take this step.

Post reply on HN