So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. It seems to me that especially when an elected official has something they don't want others to know about that…
> that so people can't use email to blackmail politicians? He mentions the politicians because those were high profile cases. This could be used against anybody, not just politicians. > It seems to me that especially when an elected official has something they don't want others to know about that it should be public knowledge. Is this true of everybody else as well? Should anybody be able to deny an email they sent i…
Ok Google: please publish your DKIM secret keys
91–100 of 492 posts
Re: Ok Google: please publish your DKIM secret keys
#92I know threads change over time, and it's dangerous to write a comment in response to the perceived gestalt of an HN thread, but, I have to say, it's pretty wild reading a thread on this site arguing so strenuously against the premise of secure messaging. In messaging cryptography, non-repudiability has for almost 2 decades been considered a vulnerability, not a feature. The OTR protocol[1] takes the step of publishi…
Re: Ok Google: please publish your DKIM secret keys
#93A novel type of cryptographic attack "Begging Google to release their secret keys on HN"[2020]
What about a public plea for justice? Accountability?
Re: Ok Google: please publish your DKIM secret keys
#94Earlier quoted context omitted.
Doesn't DKIM make it harder to blackmail or destroy someone with fake emails because they can show their lack of authenticity? Shouldn't we privilege protecting people from lies vs protecting people from the truth?
No because it's not on us to make moral distinctions between someone who is gay and doesn't want to make that information public, and someone who isn't gay and is being falsly blackmailed. Publishing the DKIM keys makes both cases harder because you no longer have authenticity claims. Neither claim has authenticity value and instead is just a "their word versus yours" situation. Humans are terrible moral adjudicators…
Re: Ok Google: please publish your DKIM secret keys
#95Earlier quoted context omitted.
> The threat is not limited to politicians. Anyone (including you and your family members) could be blackmailed or otherwise publicly embarrassed. ... for what they actually did. You think the solution is allowing people to be blackmailed or otherwise publicly embarrassed for things they didn't do, while removing their ability to verify that they didn't do them?
> ... for what they actually did. Being gay is not a crime, and yet people can be blackmailed with it. It is very easy to open yourself up to blackmail by perfectly legitimate activities.
Re: Ok Google: please publish your DKIM secret keys
#96Earlier quoted context omitted.
> The thing that protects you from blackmail is not getting involved in things you can be blackmailed for. This is incorrect, because the things that someone can be blackmailed for is not the same as the set of immoral or unethical acts. You can be blackmailed for being gay, or for having a serious medical condition that's undisclosed. Neither of those situations is a "well just don't do that" kind of thing. The defe…
Doesn't DKIM make it harder to blackmail or destroy someone with fake emails because they can show their lack of authenticity? Shouldn't we privilege protecting people from lies vs protecting people from the truth?
Indeed! I couldn't have put it better myself.
Re: Ok Google: please publish your DKIM secret keys
#97Earlier quoted context omitted.
> The thing that protects you from blackmail is not getting involved in things you can be blackmailed for. This is incorrect, because the things that someone can be blackmailed for is not the same as the set of immoral or unethical acts. You can be blackmailed for being gay, or for having a serious medical condition that's undisclosed. Neither of those situations is a "well just don't do that" kind of thing. The defe…
Nobody is telling you to not be gay. If you being gay is a secret, then don't send that secret over _plain fucking text email_. Do you send your social security number to people in emails? Email has never been privileged communication and the problem isn't one of validation but one of not understanding one's level of privacy and risk. It uses relays without end-to-end encryption and there's no guarantee that what you…
If your doctor slips up and emails you about your AZT prescription, it doesn't matter how careful you were about not disclosing your HIV status over email you sent.
Re: Ok Google: please publish your DKIM secret keys
#98I think there's an angle to the plausible deniability that many people are missing. Email servers get hacked all the time, right? A disgusting amount. Its almost like security is really difficult; in fact, its difficult to secure both the emails and the DKIM private keys . They're usually on the same server, after all. If a DKIM private key gets hacked, and the world relies on DKIM to provide non-repudiation in the v…
Sadly that's not the case.
Re: Ok Google: please publish your DKIM secret keys
#99https://www.onebigfluke.com/2013/06/bootstrapping-webfinger-...
(I suppose you could just re-opt into webfistbump every time your email provider is about to publish their DKIM key)
Re: Ok Google: please publish your DKIM secret keys
#100To make this work you need to claim a forgery when you know that no such forgery occurred. So you explicitly or implicitly have to accuse someone of a serious crime/offence they did not commit. Most people have a greater sense of honour than that. Those that don't would still have to fear getting caught.
If someone actually does forge a message using the old private keys provided by Google then you would have to fight the assumption that you were using the system as it was designed. Everyone would just assume you said it and are now using the possibility of forgery to lie about having said it.
You can always claim a forgery anyway should you decide to do that. Perhaps someone got access to Google's relatively poorly guarded DKIM private key. How would you know? You are probably not making a specific claim anyway.