Earlier quoted context omitted.
You can say the exact same thing about all secure messaging, which, after all, has the essential function of keeping documents out of the hands of third parties, including activists and historians. If DKIM upsets you, how do you get your head around disappearing messages?
>how do you get your head around disappearing messages? I get my head around them by thinking they are bad? As in, not good. An undesirable property.
Ok Google: please publish your DKIM secret keys
151–160 of 492 posts
Re: Ok Google: please publish your DKIM secret keys
#152Earlier quoted context omitted.
You're misunderstanding how destruction of evidence works.
Huh? No one (including yourself), have mentioned anything about "destruction of evidence" so far. If you care to enlighten me about how it's relevant I'm happy to listen.
Evidence was destroyed.
Re: Ok Google: please publish your DKIM secret keys
#153Earlier quoted context omitted.
They don’t have plausible evidence anyway. Gmail has had bugs before with SPF/DKIM and will have some again for sure. Some google employees have direct and indirect access to signing keys or writing emails. Not many, and they have good controls, but still many people with the ability to sign messages. Not to mention a Trojan infiltration or account takeover, of which thousands (if not millions) a day occur. The DKIM…
In the court of public opinion, the standard is not "100% proven beyond any reasonable doubt" . Hence, blackmail can still be very effective if an accusation is highly plausible.
Re: Ok Google: please publish your DKIM secret keys
#154Wow. This blog post is appalling. I completely disagree with it. Consider this excerpt from the blog post: > But DKIM authenticity is great! Don’t we want to be able to authenticate politicians’ leaked emails? > Modern DKIM deployments are problematic because they incentivize a specific kind of crime: theft of private emails for use in public blackmail and extortion campaigns. An accident of the past few years is tha…
Because this isn't just about politicians, or holding politicians accountable. It affects the rest of us too!
Instead, imagine what would happen if a hacker accessed the email of a closeted LGBTQIA+ person living in a country where being outed is practically a death sentence, and the DKIM signatures were sufficient proof of guilt.
Re: Ok Google: please publish your DKIM secret keys
#155Wow. This blog post is appalling. I completely disagree with it. Consider this excerpt from the blog post: > But DKIM authenticity is great! Don’t we want to be able to authenticate politicians’ leaked emails? > Modern DKIM deployments are problematic because they incentivize a specific kind of crime: theft of private emails for use in public blackmail and extortion campaigns. An accident of the past few years is tha…
In the particular case of Google releasing its DKIM keys, I think I would need more context. What kind of repudiation property do users expect when sending emails over GMail? Is non-repudiability currently used by users for legal or business purposes? Probably the way to do it would be to announce a particular date maybe a year into the future that the private keys would be released.
Re: Ok Google: please publish your DKIM secret keys
#156Earlier quoted context omitted.
..... so? That means in 2016, the DKIM was already deniable. And it made no difference whatsoever. The DKIM signature is proof only that whoever signed the email possessed the key, nothing more, nothing less. This, in turn, is a suggestion about the identity of the signer and possibly the author - but not proof. Did DKIM change anything about the podesta emails? Or were they basically acknowledged as authentic regard…
> ..... so? That means in 2016, the DKIM was already deniable. And it made no difference whatsoever. Both journalists and investigative groups (and conspiracy theorists) treat DKIM as a sign of authenticity, even when the key material is long past its prime. Wikileaks still prominently displays a "verified" marker next to their archives. > Did DKIM change anything about the podesta emails? Or were they basically ackn…
Yes, journalists verified it. But they consider it supporting data, just as they wouldn’t automatically ignore any email that had no DKIM signature.
Phone calls are never authenticated. Does anyone automatically believe or disbelieve recorded phone calls?
I mean, “conspiracy theorists” (in the common usage of that terms) already believe only what they want to believe.
Re: Ok Google: please publish your DKIM secret keys
#157Earlier quoted context omitted.
Then why don't we design such a system first with a higher level of guarantee first and inform users that this the goal.
We did, it's called email. The phrase "like a postcard" is how email has been described for decades -- by our school systems and the media when educating the general public, in corporate training, and in the court system.
There is not a popular email system in existence that says
"To: myfriend@mailserver.com CC: Everyone [NON-EDITABLE]"
Quite the opposite is true. Gmail, for example, says "Google.com Mail protects your message during delivery As you add people to this message, this icon will let you know your message is secure."
Re: Ok Google: please publish your DKIM secret keys
#158Meanwhile, the IETF is speccing more messaging protocols with non-repudiation and HN users seem to be cheering that shortcoming along: https://news.ycombinator.com/item?id=25100316 I think it's kind of unfortunate that there are many people that suddenly care when its powerful people or their families that are getting caught out by DKIM, these aren't the people who need protection from it the most. No one would even…
Uh... no RFC822 headers from the Hunter Biden emails were ever released, certainly none with a passing DKIM signature. I read that Post article with a microscope. This never happened.
And in fact, the transparent truth that these appeared to LACK the trivially producible authentication layer is one of the big reasons that the more right-leaning entities among the tech community stayed far away from this subject.
Re: Ok Google: please publish your DKIM secret keys
#159I know threads change over time, and it's dangerous to write a comment in response to the perceived gestalt of an HN thread, but, I have to say, it's pretty wild reading a thread on this site arguing so strenuously against the premise of secure messaging. In messaging cryptography, non-repudiability has for almost 2 decades been considered a vulnerability, not a feature. The OTR protocol[1] takes the step of publishi…
Re: Ok Google: please publish your DKIM secret keys
#160Earlier quoted context omitted.
Has this kind of repudiation ever been tested in the real world? It's hard to imagine a court throwing out email evidence because it lacked a DKIM signature. And on a personal level seeing a chat transcript that had cryptographic non-repudiation would make me likely to believe it, but seeing one that lacked it would probably not weigh heavily in how I came to that determination.
> Has this kind of repudiation ever been tested in the real world? It's hard to imagine a court throwing out email evidence because it lacked a DKIM signature. They're more likely to ask their expert witness to testify about the evidence, and the deniability of the DKIM signature could be brought up by the expert witness as a reason to distrust the evidence. I wouldn't expect lawyers to discover this argument from fi…
https://en.wikipedia.org/wiki/Trojan_horse_defense#Cases_inv...
I'm sure defense lawyers would love it :)