Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

61–70 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#61
post #25

I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?

This fails the role-reversal test. If Donald Trump had his e-mails leaked in 2016, the blackmailer would likely have extorted a ransom payment from then-candidate Trump. He paid off Stormy Daniels, after all. Nobody would have gotten any juicy e-mail dumps, and some criminals would have had actual leverage over politicians. Just because Hillary Clinton was less shrewd than Donald Trump does not mean that blackmail material is good for us as citizens just because some politicians don't pay ransoms on principle.

If you want transparency from your politicians, then you should demand unconditional archival and publication of campaign e-mails. Build transparency into the system. Leakers are not archivists, nor are they journalists. They are leakers, with an entirely different set of motivations and incentives which only sometimes align with journalistic or archival motivations. You as a member of the public will not hear about leaks if the person in possession of those leaked files has successfully extorted or ransomed the politician they came from. In this particular threat model, DKIM does not provide a social benefit to you as a citizen, it provides a monetary benefit to the leaker.

Re: Ok Google: please publish your DKIM secret keys

#62

Earlier quoted context omitted.

You might want to validate your emails more than a few months out. Regardless of if your emails are valid or not, blackmail is still a crime. Not being able to have your emails validated doesn't protect you from blackmail. The power of blackmail is often in the social cost of the accusation itself. The thing that protects you from blackmail is not getting involved in things you can be blackmailed for. This is like sa…

> The thing that protects you from blackmail is not getting involved in things you can be blackmailed for. This is incorrect, because the things that someone can be blackmailed for is not the same as the set of immoral or unethical acts. You can be blackmailed for being gay, or for having a serious medical condition that's undisclosed. Neither of those situations is a "well just don't do that" kind of thing. The defe…

Nobody is telling you to not be gay. If you being gay is a secret, then don't send that secret over _plain fucking text email_.

Do you send your social security number to people in emails?

Email has never been privileged communication and the problem isn't one of validation but one of not understanding one's level of privacy and risk. It uses relays without end-to-end encryption and there's no guarantee that what you sent is not totally out in the open.

Re: Ok Google: please publish your DKIM secret keys

#63
post #60

Earlier quoted context omitted.

> Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. This. Publishing the DKIM keys would be a huge loss for email archivists and historians in general. E.g. a couple weeks ago Donald Knuth published all of the emails he's sent and received over the last 20+ years of his career[1], without DKIM how would we know that they are authentic? [1] https://libra…

You can say the exact same thing about all secure messaging, which, after all, has the essential function of keeping documents out of the hands of third parties, including activists and historians. If DKIM upsets you, how do you get your head around disappearing messages?

> how do you get your head around disappearing messages?

I mean I try to publish most of my interesting email conversations on the web, because every time you have a good email conversation that isn't public it's like taking a $100 bill and lighting it on fire. So I wouldn't ever personally use disappearing messages.

Literally the first rule of email is that if you wouldn't want it on the front page of the NYT then you shouldn't send it. The first national scandal involving email was Iran Contra in 1986. People should know by now not to put anything into an email that they wouldn't be comfortable with the entire world knowing. And while privacy is hugely important to individuals and essential for a healthy society, to me rotating DKIM keys feels like it's incentivizing people to use email incorrectly.

Re: Ok Google: please publish your DKIM secret keys

#64

One thing that Google publishing their DKIM rotated keys is take fake news to a new level. Basically anybody could use those signing keys to fake email from a politician or celebrity. Imagine the headlines “Celebrity X account hacked, here are the emails, cryptographically verified by Google” Of course, informed people will know that anybody could have faked them, but I would guess normal people would be fooled. In a…

> Of course, informed people will know that anybody could have faked them, but I would guess normal people would be fooled. In addition, there is no way to say the emails are definitely fake. At least now, we can tell between actual leaked emails and fake emails.

No, you can't. Google used to use 512- and 1024-bit RSA keys for DKIM signatures, both of which are comfortably within the means of small-to-medium-sized nation states. They currently use 2048-bit keys, which will probably be crackable within the next decade.

DKIM is providing a false sense of non-repudiation here, one that it was never designed (much less correctly implemented) to provide.

Re: Ok Google: please publish your DKIM secret keys

#65

Earlier quoted context omitted.

You can authenticate messages in a way that only the recipient can verify (Diffie-Hellman plus MAC).

If you had access to a public key for every email address then why stop at authentication - you could encrypt all email on the web. But we don't, so we can't.

Maybe we should.

Re: Ok Google: please publish your DKIM secret keys

#66
post #29

Perversely, this solution could result in MORE emails being hacked MORE OFTEN. Allow me to explain. If a hacker were to retrieve some emails before the DKIM key was made public, they could then sign their hacked emails with their own timestamped signature, proving that they are in fact authentic (since the signed timestamp shows that they were retrieved before the DKIM key was released). Therefore, by rotating the DK…

If crackers could justify the resources, they would already now be doing more cracking. It's not like they can just scale their operations ten times all else staying equal. The proposed change in key rotation and publication makes fresh mails only more valuable relative to old messages, not more valuable in general.

If we're looking at cracking-activities from an economic point of view, publishing DKIM keys makes the cracking harder:

1. More accounts need to be cracked fast

2. Timestamped signatures must be published in a timely way

3. Results must be stored until they become useful

These things not only increase cracking expenses, they also increase the threat of detection.

Re: Ok Google: please publish your DKIM secret keys

#67
post #25

I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?

"An accident of the past few years is that this feature has been used primarily by political actors working in a manner that many people find agreeable — either because it suits a partisan preference, or because the people who got “caught” sort of deserved it. But bad things happen to good people too. If you build a mechanism that incentivizes crime, sooner or later you will get crimed on."

People who are protected from blackmail by email repudiation are by definition people who have incriminating emails. Maybe everyone had skeletons in their closet, but if you have email proof of skeletons I'm starting to wonder if you're such a good person.

Also there's an argument that "good people" can be blackmailed for INVENTED misconduct, but wouldn't such fake emails be more convincing without the ability to verify their origins? Making real emails and fake emails more similar protects people who have their incriminating emails leaked, but it also harms the defence of people who have fake emails targeting them "leaked".

There's a high bar for obfuscating truth and I don't believe this argument meets it.

Re: Ok Google: please publish your DKIM secret keys

#68
post #34

Earlier quoted context omitted.

You might want to validate your emails more than a few months out. Regardless of if your emails are valid or not, blackmail is still a crime. Not being able to have your emails validated doesn't protect you from blackmail. The power of blackmail is often in the social cost of the accusation itself. The thing that protects you from blackmail is not getting involved in things you can be blackmailed for. This is like sa…

Sounds like the "If you've got nothing to hide, you've got nothing to fear" argument. Not very compelling. https://en.wikipedia.org/wiki/Nothing_to_hide_argument

See response here: https://news.ycombinator.com/item?id=25114692

Re: Ok Google: please publish your DKIM secret keys

#69

Earlier quoted context omitted.

You might want to validate your emails more than a few months out. Regardless of if your emails are valid or not, blackmail is still a crime. Not being able to have your emails validated doesn't protect you from blackmail. The power of blackmail is often in the social cost of the accusation itself. The thing that protects you from blackmail is not getting involved in things you can be blackmailed for. This is like sa…

> The thing that protects you from blackmail is not getting involved in things you can be blackmailed for. This is incorrect, because the things that someone can be blackmailed for is not the same as the set of immoral or unethical acts. You can be blackmailed for being gay, or for having a serious medical condition that's undisclosed. Neither of those situations is a "well just don't do that" kind of thing. The defe…

Blackmail existed long before DKIM was a thing.

Being able to say "no I didn't say that" is far more powerful than the reverse because the reverse has existed for thousands of years.

But being able to definitively prove that you did not say something is brand new and very powerful.

Re: Ok Google: please publish your DKIM secret keys

#70
post #25

I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?

Please read the whole article before jumping into a conclusion about the author, Matthew Green. He sighted two examples where incorrect crypto science affected both a Democrat and a Republican. He is not trying to protect any particular side. He is simply articulating a method by which the key can be invalidated after its intended life time. If you have a technical argument, please explain that.
Post reply on HN