Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

71–80 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#71
I think there's an angle to the plausible deniability that many people are missing.

Email servers get hacked all the time, right? A disgusting amount. Its almost like security is really difficult; in fact, its difficult to secure both the emails and the DKIM private keys. They're usually on the same server, after all.

If a DKIM private key gets hacked, and the world relies on DKIM to provide non-repudiation in the verification of email leaks, then a hacker who obtains someone's DKIM private key could forge an email to contain any content they want, sign it with that private key, then leak that. The world says "its DKIM validated, Trump really did kill a litter of puppies twelve years ago", Trump tries to say "no, my email server was hacked, i never did that but they got my DKIM key" and who the hell would believe him? The headlines have already been written, and the argument against it is some crazy technical terminology a hundredth a percent of the population actually understands?

Ok, well, maybe you should rotate DKIM keys. Not necessarily make the private portion public, but at least rotate them and totally destroy the old private keys. But, again, if an email server is misconfigured enough to leak data, then its likely the admin is incompetent enough to also not be rotating keys. Moreover, unauthorized access to a server could happen over a period of years, during which hackers collect the rotated DKIM private keys while letting the admins think they're being deleted correctly.

The problem here isn't really DKIM; its the public's perception of what it was designed for. Technologists invented something, journalists discovered it, read a wikipedia article, and thought "woah we could use X for Y". So, I think it makes sense that we need a big name like Google to come out and say "Stop, this is not what this was designed for, it has major limitations in being used for that, and we're talking about real-world consequences like ruining potentially innocent peoples' lives."

Re: Ok Google: please publish your DKIM secret keys

#72
post #9

Can't you just set up your mailserver so that it drops all the crypto headers (DKIM-Signature, ...) after verifying them and storing the result in Authentication-Results? Only your server's Authentication-Results header is really relevant to spam filtering, anyway. Unless you're debugging something those headers seem irrelevant anyway, and they bloat the messages very much. (often times they are 3-4x the size of actu…

That only protects the people who send email to you. It does nothing to protect you.

Hmm. Right. So the only option on sender side is to not use DKIM at all, or rotate the keys as suggested.

Re: Ok Google: please publish your DKIM secret keys

#73
post #25

I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?

> Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail.

Exactly. If one enters into an contract using an e-mail, then DKIM can be used as a proof to the court of law that the contract was accepted by both sides.

Re: Ok Google: please publish your DKIM secret keys

#74

Earlier quoted context omitted.

"An accident of the past few years is that this feature has been used primarily by political actors working in a manner that many people find agreeable — either because it suits a partisan preference, or because the people who got “caught” sort of deserved it. But bad things happen to good people too. If you build a mechanism that incentivizes crime, sooner or later you will get crimed on."

People who are protected from blackmail by email repudiation are by definition people who have incriminating emails. Maybe everyone had skeletons in their closet, but if you have email proof of skeletons I'm starting to wonder if you're such a good person. Also there's an argument that "good people" can be blackmailed for INVENTED misconduct, but wouldn't such fake emails be more convincing without the ability to ver…

Please read the whole article. If it only takes a "few hours" to create incriminating "evidence" (read, something that didn't exist) - it must be clearly proclaimed as such to the world.

Re: Ok Google: please publish your DKIM secret keys

#75
post #55
post #25

I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?

Among messaging cryptographers, it's not even an argument. Serious secure messengers have been designed to avoid non-repudiation since OTR. Non-repudiation is a vulnerability: once counterparties have authenticated each other's messages, the legitimate need for authentication is gone; allowing random strangers to authenticate messages concedes information to them. Here, have a link, from 2004: https://otr.cypherpunks…

> once counterparties have authenticated each other's messages, the legitimate need for authentication is gone; allowing random strangers to authenticate messages concedes information to them.

As you know, there are many legitimate needs to authenticate messages of strangers.

For example, when you order products over the internet, an e-mail of your purchase is often the only proof of what was agreed in the purchase. If there is later a dispute between the buyer and the seller, the email can be used to repudiate lies. In particular, if a third party (like a court) can authenticate the message, the honest party can convince the third party that the dishonest party is being fraudulent.

You are exaggerating when you claim that there is no legitimate need to authenticate messages as a third party.

Re: Ok Google: please publish your DKIM secret keys

#76
post #25

I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?

> Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. This. Publishing the DKIM keys would be a huge loss for email archivists and historians in general. E.g. a couple weeks ago Donald Knuth published all of the emails he's sent and received over the last 20+ years of his career[1], without DKIM how would we know that they are authentic? [1] https://libra…

Do you mistrust the unsigned emails from 10+ years ago because they were sent prior to DKIM?

As for authenticity, you could contact him, or his correspondents?

Re: Ok Google: please publish your DKIM secret keys

#77
As we head into the post-truth era, we already know videos are going to become far less trusted due to deep fake tech. Finding grains of truth through cryptography, like DKIM, is so refreshing that it hurts to think some people want to cripple it.

The Hunter Biden email is a good example.

I initially thought it was a garbage tabloid drop, but once I read Rob Graham's analysis, it felt very refreshing to have a real nugget of truth based on math. While the context of that content is up for debate, the truth was essentially undeniable (unless you subscribe to the 2016 private key being stolen).

We need nuggets of truth.

Re: Ok Google: please publish your DKIM secret keys

#78
Hey Google. Please never do this. This would throw thousands of evidence about how Erdogan regime worked with terror organisations, including the e-mails that tried to ban social media to stop these evidences be available to public. And also how they declared innocent people as terror organisations with some companies that offered law support. For example, this one https://wikileaks.org/berats-box/emailid/35540 especially verifies a crime - Turkish Airlines Nigeria Weapon transfer as it marks the event as "Government Secret"; The evidence that they talk on this e-mail involves a call where the ministers talk "I don't know if they will use it to kill Muslims or Christians".

That specific e-mail does not have DKIM signature (maybe because it was sent his own gmail address? or to an gmail address in general?).

I am aware that even if they publish the DKIM secrets, these e-mail will not lose any value since these e-mails was posted before the secrets.

But I think using e-mails as evidence should be a thing in general. As you could receive them to your personal e-mail server and want to authenticate and use it on a court, even years after. If they publish the keys, it would not be possible as you could be the one who forged the e-mail as it were received from somebody else and has been put to your IMAP server manually.

Re: Ok Google: please publish your DKIM secret keys

#79
post #60

Earlier quoted context omitted.

You can say the exact same thing about all secure messaging, which, after all, has the essential function of keeping documents out of the hands of third parties, including activists and historians. If DKIM upsets you, how do you get your head around disappearing messages?

> how do you get your head around disappearing messages? I mean I try to publish most of my interesting email conversations on the web, because every time you have a good email conversation that isn't public it's like taking a $100 bill and lighting it on fire. So I wouldn't ever personally use disappearing messages. Literally the first rule of email is that if you wouldn't want it on the front page of the NYT then y…

Then why don't we design such a system first with a higher level of guarantee first and inform users that this the goal.

Re: Ok Google: please publish your DKIM secret keys

#80
post #45

Meanwhile, the IETF is speccing more messaging protocols with non-repudiation and HN users seem to be cheering that shortcoming along: https://news.ycombinator.com/item?id=25100316 I think it's kind of unfortunate that there are many people that suddenly care when its powerful people or their families that are getting caught out by DKIM, these aren't the people who need protection from it the most. No one would even…

I think you are missing part of the irony here. A good number of those Hillary emails should have been on a government server in the first place, signed for entirety by the government for archival. Non-repudiation is an explicit design goal for the communication of public officials.
Post reply on HN