Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

101–110 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#101
post #25

I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?

I think he's referring to this?

https://www.trumpaccountability.net/

Re: Ok Google: please publish your DKIM secret keys

#102
post #34

Earlier quoted context omitted.

Sounds like the "If you've got nothing to hide, you've got nothing to fear" argument. Not very compelling. https://en.wikipedia.org/wiki/Nothing_to_hide_argument

See response here: https://news.ycombinator.com/item?id=25114692

Okay, but what about a topic that is legal and acceptable in today's society but not in the society 20, 30 or 40 years down the line? What if being gay becomes socially unacceptable again? Or supporting the second amendment? Or [literally anything]?

The problem is that what is socially and legally acceptable changes over time. Just 30 years ago, the standard for social acceptable commentary was wildly different in the areas of gender identity, sexuality, and race for instance.

Re: Ok Google: please publish your DKIM secret keys

#103

Earlier quoted context omitted.

"An accident of the past few years is that this feature has been used primarily by political actors working in a manner that many people find agreeable — either because it suits a partisan preference, or because the people who got “caught” sort of deserved it. But bad things happen to good people too. If you build a mechanism that incentivizes crime, sooner or later you will get crimed on."

People who are protected from blackmail by email repudiation are by definition people who have incriminating emails. Maybe everyone had skeletons in their closet, but if you have email proof of skeletons I'm starting to wonder if you're such a good person. Also there's an argument that "good people" can be blackmailed for INVENTED misconduct, but wouldn't such fake emails be more convincing without the ability to ver…

Ah yes, the good old, “If you haven’t done anything wrong, you’ve got nothing to hide” argument. The authoritarians favourite argument for a police state.

I guess you’re the type of person that would happily hand over all your personal files to the police on a regular basis as you have nothing to hide.

Re: Ok Google: please publish your DKIM secret keys

#104
post #89

Hey Google. Please never do this. This would throw thousands of evidence about how Erdogan regime worked with terror organisations, including the e-mails that tried to ban social media to stop these evidences be available to public. And also how they declared innocent people as terror organisations with some companies that offered law support. For example, this one https://wikileaks.org/berats-box/emailid/35540 espec…

In reality, that would throw forgery of such evidence in the hands of regular people, as opposed to those politically connected, the secret services, and nation-state hacker squads. While I sympathize with your political plight, I don't really understand why you would think that is a good thing in general. For all intents and purposes, it seems even worse, leaving the ability to weaponize public opinion in the hands…

Except if you are the actual victim of these e-mails and the politicans who control 95% of the media are able to trick people either making them belive it was fake or it had "national interests" and they did it because of "country".

At least these e-mails are believed to be true in other countries. So does Authenticity of thes e-mails can easily help you when you seek asylum in country from a country where they declared you as a terrorist - internationally.

Re: Ok Google: please publish your DKIM secret keys

#105

Earlier quoted context omitted.

Nobody is telling you to not be gay. If you being gay is a secret, then don't send that secret over _plain fucking text email_. Do you send your social security number to people in emails? Email has never been privileged communication and the problem isn't one of validation but one of not understanding one's level of privacy and risk. It uses relays without end-to-end encryption and there's no guarantee that what you…

This is every bit as much about email you receive as email you send , and you are not in control of email you receive. If your doctor slips up and emails you about your AZT prescription, it doesn't matter how careful you were about not disclosing your HIV status over email you sent.

yes, my point is that we should make sure that _no one_ is stupid enough to secrets in plain text.

with criminal repercussions

Or better: don't use email and don't give an email address out to people who hold your secrets.

Re: Ok Google: please publish your DKIM secret keys

#107
post #18

So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. It seems to me that especially when an elected official has something they don't want others to know about that…

> So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. I don't think Matthew Green is arguing against transparency. What he's observing is that non-repudiation is a…

Well, by 2030 the non-repudiation will be considered lost if that’s the case. Maybe even 2027. But today, in 2020, a verified DKIM is strong indication about the identity of the writer, or that the keys weren’t safely stored.

Re: Ok Google: please publish your DKIM secret keys

#108
post #87

Earlier quoted context omitted.

> once counterparties have authenticated each other's messages, the legitimate need for authentication is gone; allowing random strangers to authenticate messages concedes information to them. As you know, there are many legitimate needs to authenticate messages of strangers. For example, when you order products over the internet, an e-mail of your purchase is often the only proof of what was agreed in the purchase.…

No, you have confused messaging cryptography with "all of cryptography".

You said "there is never a legitimate need to do X".

I gave an example of a legitimate need to do X.

Your rebuttal is that... I'm confused? Yeah, you're gonna have to be more specific than that if you want to convince anybody.

Re: Ok Google: please publish your DKIM secret keys

#109

This relies on the problematic approach to deniability of making forgeries possible. To make this work you need to claim a forgery when you know that no such forgery occurred. So you explicitly or implicitly have to accuse someone of a serious crime/offence they did not commit. Most people have a greater sense of honour than that. Those that don't would still have to fear getting caught. If someone actually does forg…

There should be no need to make claims of forgery. The mere fact that an email can be forged will substantially reduce the likelihood of email being used, unless clear providence can be provided.

At the moment that providence can be proved with DKIM. Remove DKIM and now bad actors need to prove that they actually broke into someone’s emails and stole them. A much high bar to pass, especially as it may mean incriminating yourself of a crime.

Emails become just as useful as find a pile of top secret papers on the floor. Unless you can prove the source of those papers everyone is going to ignore you.

Re: Ok Google: please publish your DKIM secret keys

#110
post #25

I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?

> Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Exactly. If one enters into an contract using an e-mail, then DKIM can be used as a proof to the court of law that the contract was accepted by both sides.

[deleted]
Post reply on HN