Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

131–140 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#131
post #82

I know threads change over time, and it's dangerous to write a comment in response to the perceived gestalt of an HN thread, but, I have to say, it's pretty wild reading a thread on this site arguing so strenuously against the premise of secure messaging. In messaging cryptography, non-repudiability has for almost 2 decades been considered a vulnerability, not a feature. The OTR protocol[1] takes the step of publishi…

Has this kind of repudiation ever been tested in the real world? It's hard to imagine a court throwing out email evidence because it lacked a DKIM signature. And on a personal level seeing a chat transcript that had cryptographic non-repudiation would make me likely to believe it, but seeing one that lacked it would probably not weigh heavily in how I came to that determination.

Re: Ok Google: please publish your DKIM secret keys

#132
post #10

> Google could launch the process right now by releasing its ancient 2016-era private keys. Since the secrecy of these serves literally no security purpose at this point, except for allowing third parties to verify email leaks, there’s no case for keeping these values secret at all. I've used Google's DKIM signatures to timestamp call recordings for years by putting a sha256 of the attached recording in the subject,…

If you have a specific use case where you need non-repudiation then there are numerous other tools you can accomplish that with. I think the author is arguing that it shouldn't be on by default.

Re: Ok Google: please publish your DKIM secret keys

#133

Earlier quoted context omitted.

> once counterparties have authenticated each other's messages, the legitimate need for authentication is gone; allowing random strangers to authenticate messages concedes information to them. As you know, there are many legitimate needs to authenticate messages of strangers. For example, when you order products over the internet, an e-mail of your purchase is often the only proof of what was agreed in the purchase.…

> As you know, there are many legitimate needs to authenticate messages of strangers. I agree with you here. However, EMail was never designed to do this. Eg if you order products over the internet, how do you know that your opposing party keeps their DKIM key safe?

> I agree with you here. However, EMail was never designed to do this. Eg if you order products over the internet, how do you know that your opposing party keeps their DKIM key safe?

I get that email and DKIM was never designed for this, it's a side effect. Fingers were not designed for finger print evidence, but it's still nice to have evidence from finger prints, as a side effect from touching things. And the problem of key storage / keys leaking will not disappear even if you change to some different protocol.

Re: Ok Google: please publish your DKIM secret keys

#134
post #23

Earlier quoted context omitted.

The threat is not limited to politicians. Anyone (including you and your family members) could be blackmailed or otherwise publicly embarrassed.

> The threat is not limited to politicians. Anyone (including you and your family members) could be blackmailed or otherwise publicly embarrassed. ... for what they actually did. You think the solution is allowing people to be blackmailed or otherwise publicly embarrassed for things they didn't do, while removing their ability to verify that they didn't do them?

People change over time, and normal human communications have a natural sunset as most people don't remember every conversation in exacting detail. It is worth at least considering the fact that we've signed up to have basically all our communications preserved and cryptographically signed in perpetuity. Most people using these services didn't fully weigh the options.

Re: Ok Google: please publish your DKIM secret keys

#135
post #102

Earlier quoted context omitted.

See response here: https://news.ycombinator.com/item?id=25114692

Okay, but what about a topic that is legal and acceptable in today's society but not in the society 20, 30 or 40 years down the line? What if being gay becomes socially unacceptable again? Or supporting the second amendment? Or [literally anything]? The problem is that what is socially and legally acceptable changes over time . Just 30 years ago, the standard for social acceptable commentary was wildly different in t…

Yes, you should absolutely think about everything that you commit to public record.

Yes, you might be totally fine now. You might be hanging out and get photographed with this creepy billionaire named Jeffrey Epstein who is just another creepy billionaire at your creepy billionaire parties. Then 20 years from now we find out he's running pedophile island and people start looking into your associations.

We are not teaching people to be cautious about their public data and in fact there's an entire industry out there encouraging everyone to detail their whole lives in public record.

Get off of social media _today_. Yes, it's probably too late. The other option is to be such a big celebrity that your entire life is public and you have the defense of scrutiny.

Side note: Somebody from my high school class is a famous criminal. I regularly receive requests for interviews on the basis of that association alone despite having nothing to do with the person for decades.

Re: Ok Google: please publish your DKIM secret keys

#136

Earlier quoted context omitted.

> The threat is not limited to politicians. Anyone (including you and your family members) could be blackmailed or otherwise publicly embarrassed. ... for what they actually did. You think the solution is allowing people to be blackmailed or otherwise publicly embarrassed for things they didn't do, while removing their ability to verify that they didn't do them?

> ... for what they actually did. Being gay is not a crime, and yet people can be blackmailed with it. It is very easy to open yourself up to blackmail by perfectly legitimate activities.

> Being gay is not a crime, and yet people can be blackmailed with it. It is very easy to open yourself up to blackmail by perfectly legitimate activities.

Option 1: DKIM keys stay private... "That email was just a joke, I'm not really gay" Option 2: DKIM keys go public... "That email was just someone else's joke, I'm not really gay"

Not really a difference, and with option 2 you can't prove you didn't send it (as far as you can prove someone didn't crack 2048 bit RSA and use that power to concern themselves with your sex life).

Being able to prove a fascist dictator who was killing people for being gay, was secretly engaging in gay acts themselves, might help your cause of protecting gay people.

Re: Ok Google: please publish your DKIM secret keys

#137
post #112

Earlier quoted context omitted.

The point was that you pointed out a use case for some sort of cryptographic signing, not for (ab-) using DKIM for this purpose rather than what it was designed for. I don't understand enough about all the issue to really know how I feel about it, but clearly there are trade-offs here that at least argue against expanding the scope.

> His point was that you pointed out a use case for some sort of cryptographic signing, not for (ab-) using DKIM for this purpose rather than what it was designed for. First, thank you for the clarification. Second, to answer tptacek's point, I understand that authenticating emails as a third party is an unintended side effect of the DKIM protocol. I understand that cryptographers would like people to move onto using…

It's just really clear that people in this thread are trying to approach this from first principles without any engagement in the field that they're discussing. That's a fun thing to do as, like, a game or a way to pass the time, and I guess that's what HN is, but it's still crazymaking, because essentially every paper written about messaging cryptography refutes this comment. Cryptographers would like to move people onto GPG? The fact that GPG is non-repudiable and shouldn't be is one of the 2 motivating use cases for OTR, and later Signal. Nobody is trying to get people to use GPG.

Re: Ok Google: please publish your DKIM secret keys

#138

Earlier quoted context omitted.

> Maybe even 2027. But today, in 2020, a verified DKIM is strong indication about the identity of the writer, or that the keys weren’t safely stored. Except that we're talking about leaks of emails that date back by years: the earliest Podesta emails are from 2010, back when Google was using 512-bit (!) keys for DKIM. Those were leaked in 2016, at which point 1024-bit keys were already considered crackable by a motiv…

..... so? That means in 2016, the DKIM was already deniable. And it made no difference whatsoever. The DKIM signature is proof only that whoever signed the email possessed the key, nothing more, nothing less. This, in turn, is a suggestion about the identity of the signer and possibly the author - but not proof. Did DKIM change anything about the podesta emails? Or were they basically acknowledged as authentic regard…

> ..... so? That means in 2016, the DKIM was already deniable. And it made no difference whatsoever.

Both journalists and investigative groups (and conspiracy theorists) treat DKIM as a sign of authenticity, even when the key material is long past its prime. Wikileaks still prominently displays a "verified" marker next to their archives.

> Did DKIM change anything about the podesta emails? Or were they basically acknowledged as authentic regardless, and had a lot of other verifyable info in them?

That's hard to say, but it's also not the point. The point with being able to crack the key is that a motivated party could intersperse false information with otherwise verifiable information. And, well, what's a conspiracy theorist to do? Only believe the non-juicy parts?

Re: Ok Google: please publish your DKIM secret keys

#139
post #41

Earlier quoted context omitted.

You're misunderstanding how this works. You can't be blackmailed by someone who has no plausible evidence.

You're misunderstanding how destruction of evidence works.

Huh? No one (including yourself), have mentioned anything about "destruction of evidence" so far. If you care to enlighten me about how it's relevant I'm happy to listen.
Post reply on HN