Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

51–60 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#51
post #18

So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. It seems to me that especially when an elected official has something they don't want others to know about that…

Correct me if I'm wrong but elsewhere you to claim to be a conservative who has at least some mistrust in the recent election results. This seems like a paradox. Do you trust the government and its systems or not? Because the "I've got nothing to hide" [0] argument doesn't work if you recognize that governments can and do go bad. Once that happens, they can retroactively change what is acceptable thought.

https://en.wikipedia.org/wiki/Nothing_to_hide_argument

Edit: Already at -1 votes with no explanation. To be clear I don't want to bring the election/politics into this. I only want to point out that "I've got nothing to hide" is a strange argument if you explicitly distrust the democratic systems in place around you.

Re: Ok Google: please publish your DKIM secret keys

#52
post #23

Earlier quoted context omitted.

The threat is not limited to politicians. Anyone (including you and your family members) could be blackmailed or otherwise publicly embarrassed.

> The threat is not limited to politicians. Anyone (including you and your family members) could be blackmailed or otherwise publicly embarrassed. ... for what they actually did. You think the solution is allowing people to be blackmailed or otherwise publicly embarrassed for things they didn't do, while removing their ability to verify that they didn't do them?

> ... for what they actually did.

Being gay is not a crime, and yet people can be blackmailed with it. It is very easy to open yourself up to blackmail by perfectly legitimate activities.

Re: Ok Google: please publish your DKIM secret keys

#53
post #25

I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?

Except, as pointed out in the article, over time the ability to crack the underlying key and thus forge such emails becomes very practical. By disavowing the keys it prevents someone from taking a cracked key, forging an email and then "discovering it" for nefarious purposes.

Re: Ok Google: please publish your DKIM secret keys

#54
post #18

So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. It seems to me that especially when an elected official has something they don't want others to know about that…

> As a follow up, several people point out that it could happen to me or a family member, but this seems even further reason to have DKIM so that if someone attempts to blackmail me based on the contents of my email, checking the DKIM signature makes it even easier to disprove a bad blackmail attempt.

I think his point is that the DKIM signatures could be used to verify that you did, in fact, send something worth being blackmailed over, rather than having the plausable deniability of saying that your DKIM private key from that period is already public and thus could be forged.

Which, to me, sounds similar to the classic XKCD "Theoretically, I use 2048bit RSA encryption and the hackers can't get my data. In Reality, they just beat me with a hammer until I give up the password." Maybe a public DKIM argument would hold up in court, but if we're just talking reputation blackmail among family and friends, it aint it chief.

Re: Ok Google: please publish your DKIM secret keys

#55
post #25

I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?

Among messaging cryptographers, it's not even an argument. Serious secure messengers have been designed to avoid non-repudiation since OTR. Non-repudiation is a vulnerability: once counterparties have authenticated each other's messages, the legitimate need for authentication is gone; allowing random strangers to authenticate messages concedes information to them.

Here, have a link, from 2004:

https://otr.cypherpunks.ca/otr-wpes.pdf

Re: Ok Google: please publish your DKIM secret keys

#56
post #25

I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?

> Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail.

This. Publishing the DKIM keys would be a huge loss for email archivists and historians in general. E.g. a couple weeks ago Donald Knuth published all of the emails he's sent and received over the last 20+ years of his career[1], without DKIM how would we know that they are authentic?

[1] https://library.stanford.edu/blogs/special-collections-unbou...

Re: Ok Google: please publish your DKIM secret keys

#58
post #25

I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?

Except, as pointed out in the article, over time the ability to crack the underlying key and thus forge such emails becomes very practical. By disavowing the keys it prevents someone from taking a cracked key, forging an email and then "discovering it" for nefarious purposes.

Disavowing also protects against key theft or leaks. I'd guess that theft or leaks are probably more likely than cracking, now that the major providers are using long keys.

Re: Ok Google: please publish your DKIM secret keys

#59

Earlier quoted context omitted.

> The thing that protects you from blackmail is not getting involved in things you can be blackmailed for. This is incorrect, because the things that someone can be blackmailed for is not the same as the set of immoral or unethical acts. You can be blackmailed for being gay, or for having a serious medical condition that's undisclosed. Neither of those situations is a "well just don't do that" kind of thing. The defe…

Doesn't DKIM make it harder to blackmail or destroy someone with fake emails because they can show their lack of authenticity? Shouldn't we privilege protecting people from lies vs protecting people from the truth?

No because it's not on us to make moral distinctions between someone who is gay and doesn't want to make that information public, and someone who isn't gay and is being falsly blackmailed.

Publishing the DKIM keys makes both cases harder because you no longer have authenticity claims. Neither claim has authenticity value and instead is just a "their word versus yours" situation.

Humans are terrible moral adjudicators, and acting off of universals leads to repugnant ends. The truth can absolutely do terrible damage and still be the truth, but being the truth doesn't remove value from privacy. Put another way - would it be moral to publish your full medical records in the public? After all, they are the truth...

Re: Ok Google: please publish your DKIM secret keys

#60
post #25

I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?

> Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. This. Publishing the DKIM keys would be a huge loss for email archivists and historians in general. E.g. a couple weeks ago Donald Knuth published all of the emails he's sent and received over the last 20+ years of his career[1], without DKIM how would we know that they are authentic? [1] https://libra…

You can say the exact same thing about all secure messaging, which, after all, has the essential function of keeping documents out of the hands of third parties, including activists and historians. If DKIM upsets you, how do you get your head around disappearing messages?
Post reply on HN