Earlier quoted context omitted.
> ..... so? That means in 2016, the DKIM was already deniable. And it made no difference whatsoever. Both journalists and investigative groups (and conspiracy theorists) treat DKIM as a sign of authenticity, even when the key material is long past its prime. Wikileaks still prominently displays a "verified" marker next to their archives. > Did DKIM change anything about the podesta emails? Or were they basically ackn…
I don’t understand the fascination with DKIM on this thread. Yes, journalists verified it. But they consider it supporting data, just as they wouldn’t automatically ignore any email that had no DKIM signature. Phone calls are never authenticated. Does anyone automatically believe or disbelieve recorded phone calls? I mean, “conspiracy theorists” (in the common usage of that terms) already believe only what they want…
I think the point boils down to expectation management: journalists (and ...) barely understand non-repudiation, much less why each of the following scenarios pans out:
* 2006 email + 512-bit RSA, leaked in 2006: probably authentic
* 2008 email + 512-bit RSA, leaked in 2012: potentially inauthentic
* 2008 email + 1024-bit RSA, leaked in 2008: probably authentic
* 2008 email + 1024-bit RSA, leaked in 2016: potentially inauthentic
...and so on. In sum: we're making life harder for the people doing real investigative work (since they're not technical), and we're giving fodder to the people who want to conspiracize. All because we're using a spam mitigation technique to provide properties that it was never intended to provide.