Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

171–180 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#172

Earlier quoted context omitted.

> As you know, there are many legitimate needs to authenticate messages of strangers. I agree with you here. However, EMail was never designed to do this. Eg if you order products over the internet, how do you know that your opposing party keeps their DKIM key safe?

> I agree with you here. However, EMail was never designed to do this. Eg if you order products over the internet, how do you know that your opposing party keeps their DKIM key safe? I get that email and DKIM was never designed for this, it's a side effect. Fingers were not designed for finger print evidence, but it's still nice to have evidence from finger prints, as a side effect from touching things. And the probl…

This sounds like a Law&Order mindset. No, its generally not a great idea to get fingerprints of everything.

Re: Ok Google: please publish your DKIM secret keys

#173
post #159
post #82

I know threads change over time, and it's dangerous to write a comment in response to the perceived gestalt of an HN thread, but, I have to say, it's pretty wild reading a thread on this site arguing so strenuously against the premise of secure messaging. In messaging cryptography, non-repudiability has for almost 2 decades been considered a vulnerability, not a feature. The OTR protocol[1] takes the step of publishi…

It's easy to see why there are divided opinions on this. When someone sends an email, the recipient often wants to be able to prove that they did so. We think of email as something capable of leaving a paper trail, proof that certain people sent certain emails. It's reasonable for secure messaging to want to fill a different niche, more like private conversation. I've seen messaging apps advertised on the basis that…

My problem isn't that people have divided opinions on this. My problem is that people who oppose it write as if they're just now discovering that the opposite opinion exists --- in one case on this thread, someone suggested that the only reason Matthew Green held this opinion at all was political.

A serious argument against deniable messaging would start by acknowledging deniability as one of the shibboleths of the field of messaging cryptography, and then tackle the idea. Nobody on this thread has done that, and I think the reason why is that they're simply not aware that there is such a field.

Re: Ok Google: please publish your DKIM secret keys

#174
post #29

Perversely, this solution could result in MORE emails being hacked MORE OFTEN. Allow me to explain. If a hacker were to retrieve some emails before the DKIM key was made public, they could then sign their hacked emails with their own timestamped signature, proving that they are in fact authentic (since the signed timestamp shows that they were retrieved before the DKIM key was released). Therefore, by rotating the DK…

Your threat model appears to be that most email providers are hacked a substantial percent of the time, right? What defenses of anything are going to work with that threat model?

You don't necessarily have to hack the provider. You can hack the user's laptop and siphon the data out of their email client. If they use a web client, you can read the files it caches. Or maybe you can set up IMAP and have your malware read a copy of everything. To the email provider, all of this just looks like the user is reading their email.

Re: Ok Google: please publish your DKIM secret keys

#175
post #25

I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?

I think he's referring to this? https://www.trumpaccountability.net/

That website's owners already abandoned the project under suspicious pretenses of "unity".

Re: Ok Google: please publish your DKIM secret keys

#176
post #130

Earlier quoted context omitted.

In the court of public opinion, the standard is not "100% proven beyond any reasonable doubt" . Hence, blackmail can still be very effective if an accusation is highly plausible.

Yes, but it’s not DKIM or not DKIM that will make it plausible in the court of public opinion.

Current events prove otherwise. See Hunter Biden.

Re: Ok Google: please publish your DKIM secret keys

#177
post #25

I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?

> Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Exactly. If one enters into an contract using an e-mail, then DKIM can be used as a proof to the court of law that the contract was accepted by both sides.

Yes. I have seen first hand where it was used to help accelerate out of court agreement without needing a lawsuit. Basically a 3rd party had one of their outlook user accounts compromised by a bad actor who used it to tell another company new instructions for something.

The 3rd party tried to say other company fell for a phishing email and it was their fault but because of DKIM it was immediately provable that instead 3rd party was compromised and email legit sent from their o365 and they were pretending like they didn't know this. This all got disputed maybe a year after email sent.

Love Matthew Green but I personally am not a fan of this proposal. It doesn't fully achieve what he wants bc its only gmail and timing of compromise would be key. Most of the email hacks have actually been very much in the public interest despite being unethical. Breaches also lead to more productive work by companies in better securing accounts and better protecting sensitive information which google has been doing with account security and adding expiring messages.

Like do we really want companies to just continue sloppily sending customer info in email bc they can deny its legit or should they focus on not getting this info compromised to begin with?

Also, for ransomeware groups that now post data when not paid, it is not really seeming like too big of a disincentive that there is repudiation regarding the files they post.

Re: Ok Google: please publish your DKIM secret keys

#178

Earlier quoted context omitted.

It's just really clear that people in this thread are trying to approach this from first principles without any engagement in the field that they're discussing. That's a fun thing to do as, like, a game or a way to pass the time, and I guess that's what HN is, but it's still crazymaking, because essentially every paper written about messaging cryptography refutes this comment. Cryptographers would like to move people…

Ok, my GPG example was wrong. And yes, you got me, I'm not a professional cryptographer. But can you address the point? You said "once counterparties have authenticated each other's messages, the legitimate need for authentication is gone". I provided a counter-example to demonstrate that your statement was an exaggeration. You clearly dispute some part of this, but it's unclear to me what the disputed part is. Edit:…

Start by reading the first sentence of my comment.

Re: Ok Google: please publish your DKIM secret keys

#179
post #82

I know threads change over time, and it's dangerous to write a comment in response to the perceived gestalt of an HN thread, but, I have to say, it's pretty wild reading a thread on this site arguing so strenuously against the premise of secure messaging. In messaging cryptography, non-repudiability has for almost 2 decades been considered a vulnerability, not a feature. The OTR protocol[1] takes the step of publishi…

Excuse my ignorance but how does someone else signing my message prove that I sent the message? Moreso if the body of the message is not being signed at all?

Good luck arguing that Gmail forged and signed an email from you.

Re: Ok Google: please publish your DKIM secret keys

#180

Earlier quoted context omitted.

People who are protected from blackmail by email repudiation are by definition people who have incriminating emails. Maybe everyone had skeletons in their closet, but if you have email proof of skeletons I'm starting to wonder if you're such a good person. Also there's an argument that "good people" can be blackmailed for INVENTED misconduct, but wouldn't such fake emails be more convincing without the ability to ver…

Ah yes, the good old, “If you haven’t done anything wrong, you’ve got nothing to hide” argument. The authoritarians favourite argument for a police state. I guess you’re the type of person that would happily hand over all your personal files to the police on a regular basis as you have nothing to hide.

Not OP. But I would give all my data to the police/government... in an encrypted manner that has guarantees in place that only valid criminal investigations can decrypt. Heck, we do it on some level all the time anyways when it comes to things such as filing taxes, getting married, running companies, enforcing contracts and various other day-to-day benign interactions.

At this point, I'm more inclined to believe that "democratic" and "noble" governments and agents are the ones maliciously pushing for "privacy" because it suits their power-maintaining agenda. I'm struggling to find compelling and valid reasons why we can't pursue a general solution that involves us giving all this "private" data to a government entity for legitimate investigations, fraud prevention and crime-solving whilst keeping that data free from abuse.

Post reply on HN