Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

191–200 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#191

Earlier quoted context omitted.

> ... for what they actually did. Being gay is not a crime, and yet people can be blackmailed with it. It is very easy to open yourself up to blackmail by perfectly legitimate activities.

> Being gay is not a crime, and yet people can be blackmailed with it. It is very easy to open yourself up to blackmail by perfectly legitimate activities. Option 1: DKIM keys stay private... "That email was just a joke, I'm not really gay" Option 2: DKIM keys go public... "That email was just someone else's joke, I'm not really gay" Not really a difference, and with option 2 you can't prove you didn't send it (as fa…

> Being able to prove a fascist dictator who was killing people for being gay, was secretly engaging in gay acts themselves, might help your cause of protecting gay people.

How?

Re: Ok Google: please publish your DKIM secret keys

#192
post #119
post #91

Earlier quoted context omitted.

Other than whistleblowers and activists fighting the dictatorships (and they can work-around this), what is the case where not being able to prove who sent the email would be a good thing?

-- Example -- Dear Ivanhoe, I regret to inform you that your HIV test came back positive. Please contact my office at your earliest convenience to arrange a follow up. Sincerely, Your doctor

No doctor should be writing that email in the first place; it would be an example of such a flagrantly negligent treatment of PHI that cryptographic signatures and reputability are kind of irrelevant.

Re: Ok Google: please publish your DKIM secret keys

#193
post #45

Meanwhile, the IETF is speccing more messaging protocols with non-repudiation and HN users seem to be cheering that shortcoming along: https://news.ycombinator.com/item?id=25100316 I think it's kind of unfortunate that there are many people that suddenly care when its powerful people or their families that are getting caught out by DKIM, these aren't the people who need protection from it the most. No one would even…

> No one would even care if the Hunter Biden related emails passed DKIM except for the widespread allegation that they were fake, and no one still cares because conversation about them passing DKIM is widely suppressed (including on HN, unfortunately, where a post about it was immediately flagged). Uh... no RFC822 headers from the Hunter Biden emails were ever released, certainly none with a passing DKIM signature. I…

https://github.com/robertdavidgraham/hunter-dkim/blob/main/M...

Re: Ok Google: please publish your DKIM secret keys

#194

Earlier quoted context omitted.

> Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Exactly. If one enters into an contract using an e-mail, then DKIM can be used as a proof to the court of law that the contract was accepted by both sides.

If non-repudiation is important to you, then both parties should consent to it and use a platform that explicitly supports it. It shouldn’t be sprung on people without consent. It would be like saying it’s fine to keep a recording from someone else’s webcam because it might prove a crime later. There’s a reason why justice systems have statues of limitations. People should need to look over their shoulders for the re…

It is not really being sprung on them with how long it has existed. Not at all like continuing recording on a webcam where you might say things never intended for the party receiving it.

Are ppl who don't even know DKIM exists but know they have shady emails saved in the cloud or on their personal really just banking on repudiation and thats why they take no other action like deleting the email or putting more thought into emails they send? Seriously doubt it.

Exactly bc of statute of limitations, they would not have to look over their shoulders for the rest of their lives because of one poorly written email.

Re: Ok Google: please publish your DKIM secret keys

#195

Earlier quoted context omitted.

The word "appalling" describes something that creates surprising distress or dismay (itself implying surprise). To be surprised at a cryptographer advocating for deniable messaging is to suggest that you're unacquainted with the field of messaging cryptography, in which deniable messaging has been a foundational goal for almost 2 decades, going back to Ian Goldberg and Nikita Borisov, who once yelled at me on Twitter…

In the quote I presented above, the author wasn't making a technical argument, but a moral one. If you or the author are presenting an argument why repudiation is necessary on technical grounds , I will admit ignorance and defer to the experts. But my reading of the blog post was that it is not a technical argument. It's an argument about morality, and specifically the author used political examples. If the author di…

I don't know how fair this is but will just say that the first thought that jumps to my mind here is that being surprised at a cryptographer advocating for deniable messages is a little bit like being surprised at a medical researcher advocating for effective antibiotics. It probably never occurs to either of them to question the legitimacy of their moral stance.

Re: Ok Google: please publish your DKIM secret keys

#196
post #55
post #25

I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?

Among messaging cryptographers, it's not even an argument. Serious secure messengers have been designed to avoid non-repudiation since OTR. Non-repudiation is a vulnerability: once counterparties have authenticated each other's messages, the legitimate need for authentication is gone; allowing random strangers to authenticate messages concedes information to them. Here, have a link, from 2004: https://otr.cypherpunks…

I do have a question though, as a relative amateur. It’s more on a sociological level.

Suppose you are in an organization, and it needs to figure our whether an employee was saying a Bad Thing such as giving out company secrets or cursing people out “off the record”.

Yes, even with end to end encryption, Facebook and others can still let you prove the other person sent the messages when you need. The question is whether that is a good thing:

https://facebook.com/help/messenger-app/1165699260192280

My personal feeling is yes, yes it is. I make a more extensive analysis here:

https://news.ycombinator.com/item?id=25030085

Re: Ok Google: please publish your DKIM secret keys

#197

Wow. This blog post is appalling. I completely disagree with it. Consider this excerpt from the blog post: > But DKIM authenticity is great! Don’t we want to be able to authenticate politicians’ leaked emails? > Modern DKIM deployments are problematic because they incentivize a specific kind of crime: theft of private emails for use in public blackmail and extortion campaigns. An accident of the past few years is tha…

I'm not going to present a moral argument (what is a moral argument in this context?), only two direct rebuttals of your objections: 1. DKIM provides neither truthfulness nor objectivity. It's a signature mechanism used between mail servers to reduce spam. For implementation reasons, most DKIM users sign with RSA keys that are either currently crackable or will be crackable in a matter of years. Consequently, "signed…

If right now DKIM doesn’t provide truthfulness or objectivity, then the author’s blackmail example already doesn’t apply.

DKIM signatures, by your argument, are useless in blackmail, since they don’t verify the message. So why did the author resort to that as an example?

Re: Ok Google: please publish your DKIM secret keys

#198
post #55

Earlier quoted context omitted.

Among messaging cryptographers, it's not even an argument. Serious secure messengers have been designed to avoid non-repudiation since OTR. Non-repudiation is a vulnerability: once counterparties have authenticated each other's messages, the legitimate need for authentication is gone; allowing random strangers to authenticate messages concedes information to them. Here, have a link, from 2004: https://otr.cypherpunks…

> once counterparties have authenticated each other's messages, the legitimate need for authentication is gone; allowing random strangers to authenticate messages concedes information to them. As you know, there are many legitimate needs to authenticate messages of strangers. For example, when you order products over the internet, an e-mail of your purchase is often the only proof of what was agreed in the purchase.…

As you know, there are many legitimate needs to publish naked pictures of your body to the entire internet, but most people want to keep them private. Defaults matter.

What makes this hard is that email is responsible for too much crap. No single user interface should carry:

1. Party invites

2. Private messages to your spouse, therapist, pastor, etc.

3. Marketing messages

4. Password recovery requests

5. Financial transactions

We've just shoved them all into email because it's there.

Re: Ok Google: please publish your DKIM secret keys

#199
post #189
post #55

Earlier quoted context omitted.

Among messaging cryptographers, it's not even an argument. Serious secure messengers have been designed to avoid non-repudiation since OTR. Non-repudiation is a vulnerability: once counterparties have authenticated each other's messages, the legitimate need for authentication is gone; allowing random strangers to authenticate messages concedes information to them. Here, have a link, from 2004: https://otr.cypherpunks…

FWIW, I am pretty sure I agree with you/OTR, but the IETF Messaging Layer Security (MLS) people disagree for not-always-trivially-dismissible reasons (indirect link because I am lazy). https://news.ycombinator.com/item?id=25101825

(a) I wasn't aware of this.

(b) Thanks for the link!

(c) The IETF is such a shitshow for cryptography.

Re: Ok Google: please publish your DKIM secret keys

#200

Earlier quoted context omitted.

> Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Exactly. If one enters into an contract using an e-mail, then DKIM can be used as a proof to the court of law that the contract was accepted by both sides.

Entering an contract via an email is a ridiculous idea from the start.

Would you prefer we use fax machines instead?
Post reply on HN