Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

121–130 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#121
post #41

Earlier quoted context omitted.

> The threat is not limited to politicians. Anyone (including you and your family members) could be blackmailed or otherwise publicly embarrassed. ... for what they actually did. You think the solution is allowing people to be blackmailed or otherwise publicly embarrassed for things they didn't do, while removing their ability to verify that they didn't do them?

You're misunderstanding how this works. You can't be blackmailed by someone who has no plausible evidence.

They don’t have plausible evidence anyway. Gmail has had bugs before with SPF/DKIM and will have some again for sure.

Some google employees have direct and indirect access to signing keys or writing emails. Not many, and they have good controls, but still many people with the ability to sign messages.

Not to mention a Trojan infiltration or account takeover, of which thousands (if not millions) a day occur.

The DKIM evidence is, for legal purposes, a good hint but far from proof.

Re: Ok Google: please publish your DKIM secret keys

#122

Earlier quoted context omitted.

> So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. I don't think Matthew Green is arguing against transparency. What he's observing is that non-repudiation is a…

Well, by 2030 the non-repudiation will be considered lost if that’s the case. Maybe even 2027. But today, in 2020, a verified DKIM is strong indication about the identity of the writer, or that the keys weren’t safely stored.

> Maybe even 2027. But today, in 2020, a verified DKIM is strong indication about the identity of the writer, or that the keys weren’t safely stored.

Except that we're talking about leaks of emails that date back by years: the earliest Podesta emails are from 2010, back when Google was using 512-bit (!) keys for DKIM. Those were leaked in 2016, at which point 1024-bit keys were already considered crackable by a motivated attacker.

This isn't to say that those emails were faked, only that "an email written in 2020 that's verifiable in 2020" is not the target of interest.

Re: Ok Google: please publish your DKIM secret keys

#123
post #41

Earlier quoted context omitted.

> The threat is not limited to politicians. Anyone (including you and your family members) could be blackmailed or otherwise publicly embarrassed. ... for what they actually did. You think the solution is allowing people to be blackmailed or otherwise publicly embarrassed for things they didn't do, while removing their ability to verify that they didn't do them?

You're misunderstanding how this works. You can't be blackmailed by someone who has no plausible evidence.

You're misunderstanding how destruction of evidence works.

Re: Ok Google: please publish your DKIM secret keys

#124
post #82

I know threads change over time, and it's dangerous to write a comment in response to the perceived gestalt of an HN thread, but, I have to say, it's pretty wild reading a thread on this site arguing so strenuously against the premise of secure messaging. In messaging cryptography, non-repudiability has for almost 2 decades been considered a vulnerability, not a feature. The OTR protocol[1] takes the step of publishi…

Excuse my ignorance but how does someone else signing my message prove that I sent the message? Moreso if the body of the message is not being signed at all?

Re: Ok Google: please publish your DKIM secret keys

#125
post #91

Earlier quoted context omitted.

> that so people can't use email to blackmail politicians? He mentions the politicians because those were high profile cases. This could be used against anybody, not just politicians. > It seems to me that especially when an elected official has something they don't want others to know about that it should be public knowledge. Is this true of everybody else as well? Should anybody be able to deny an email they sent i…

Other than whistleblowers and activists fighting the dictatorships (and they can work-around this), what is the case where not being able to prove who sent the email would be a good thing?

Toward the end of the blog post, the author points out that while it often is nice to have the ability to authenticate who sent an email, nobody asked for this feature to be enabled by default on all their communications. It seems like a matter of preference, and it isn't clear that people thought about it at all.

People change over time and normal human communications have a natural sunset built in as people forget exactly who said what.

Re: Ok Google: please publish your DKIM secret keys

#126
post #91

Earlier quoted context omitted.

> that so people can't use email to blackmail politicians? He mentions the politicians because those were high profile cases. This could be used against anybody, not just politicians. > It seems to me that especially when an elected official has something they don't want others to know about that it should be public knowledge. Is this true of everybody else as well? Should anybody be able to deny an email they sent i…

Other than whistleblowers and activists fighting the dictatorships (and they can work-around this), what is the case where not being able to prove who sent the email would be a good thing?

It could (at least according to the author) reduce the incentive to steal people's emails for blackmail purpose to begin with. The target of blackmail can simply deny they are authentic and it would be extremely hard for the blackmailer to provide evidence of their authenticity without revealing their own identity.

Re: Ok Google: please publish your DKIM secret keys

#127

Earlier quoted context omitted.

Well, by 2030 the non-repudiation will be considered lost if that’s the case. Maybe even 2027. But today, in 2020, a verified DKIM is strong indication about the identity of the writer, or that the keys weren’t safely stored.

> Maybe even 2027. But today, in 2020, a verified DKIM is strong indication about the identity of the writer, or that the keys weren’t safely stored. Except that we're talking about leaks of emails that date back by years: the earliest Podesta emails are from 2010, back when Google was using 512-bit (!) keys for DKIM. Those were leaked in 2016, at which point 1024-bit keys were already considered crackable by a motiv…

..... so? That means in 2016, the DKIM was already deniable. And it made no difference whatsoever.

The DKIM signature is proof only that whoever signed the email possessed the key, nothing more, nothing less. This, in turn, is a suggestion about the identity of the signer and possibly the author - but not proof.

Did DKIM change anything about the podesta emails? Or were they basically acknowledged as authentic regardless, and had a lot of other verifyable info in them?

Re: Ok Google: please publish your DKIM secret keys

#128
post #112

Earlier quoted context omitted.

You said "there is never a legitimate need to do X". I gave an example of a legitimate need to do X. Your rebuttal is that... I'm confused? Yeah, you're gonna have to be more specific than that if you want to convince anybody.

The point was that you pointed out a use case for some sort of cryptographic signing, not for (ab-) using DKIM for this purpose rather than what it was designed for. I don't understand enough about all the issue to really know how I feel about it, but clearly there are trade-offs here that at least argue against expanding the scope.

> His point was that you pointed out a use case for some sort of cryptographic signing, not for (ab-) using DKIM for this purpose rather than what it was designed for.

First, thank you for the clarification.

Second, to answer tptacek's point, I understand that authenticating emails as a third party is an unintended side effect of the DKIM protocol. I understand that cryptographers would like people to move onto using other protocols for purposes like this. However, the suggestion that Google should periodically publish and rotate their secret keys, does not achieve this goal in any way. If Google were to do this, the webstore that you purchase items from, would not suddenly start using different protocols to authenticate purchase receipts, they would continue to send regular email... but those emails could no longer be authenticated. Or if we go back to the example in OP, the politician that's admitting to crimes over email, they're certainly not going to switch over to another method of documenting their crimes.

Edit: I was incorrectly using GPG as an example. I removed the incorrect example and let the point stand without it.

Re: Ok Google: please publish your DKIM secret keys

#129

Earlier quoted context omitted.

> Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Exactly. If one enters into an contract using an e-mail, then DKIM can be used as a proof to the court of law that the contract was accepted by both sides.

> Exactly. If one enters into an contract using an e-mail, then DKIM can be used as a proof to the court of law that the contract was accepted by both sides. It would make a good TV drama plot, but courts don't work this way in real life. If that were the case, courts wouldn't be able to enforce contracts with wet signatures (which are straightforward to forge), or verbal contracts (which are valid contracts and regu…

> If that were the case, courts wouldn't be able to enforce contracts with wet signatures (which are straightforward to forge)

I'm pretty confident that I could sign an email with a DKIM key if that were published, however, there's nothing that would give me the confidence that I could forge a pen signature in such a way that not even an expert could detect the forgery.

> or verbal contracts (which are valid contracts and regularly enforced).

I'm not a a lawyer, but according to the first google result "the Uniform Commercial Code [...] requires that contracts for the sale of goods over $500 to be in writing".[1]

> Disputes over whether the text of the executed contract is authentic are rare in real life.

Maybe they are rare precisely because it's hard and risky to forge signatures.

[1] https://www.hg.org/legal-articles/are-verbal-agreements-bind...

Re: Ok Google: please publish your DKIM secret keys

#130
post #41

Earlier quoted context omitted.

You're misunderstanding how this works. You can't be blackmailed by someone who has no plausible evidence.

They don’t have plausible evidence anyway. Gmail has had bugs before with SPF/DKIM and will have some again for sure. Some google employees have direct and indirect access to signing keys or writing emails. Not many, and they have good controls, but still many people with the ability to sign messages. Not to mention a Trojan infiltration or account takeover, of which thousands (if not millions) a day occur. The DKIM…

In the court of public opinion, the standard is not "100% proven beyond any reasonable doubt". Hence, blackmail can still be very effective if an accusation is highly plausible.
Post reply on HN