Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

211–220 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#211

Earlier quoted context omitted.

In the quote I presented above, the author wasn't making a technical argument, but a moral one. If you or the author are presenting an argument why repudiation is necessary on technical grounds , I will admit ignorance and defer to the experts. But my reading of the blog post was that it is not a technical argument. It's an argument about morality, and specifically the author used political examples. If the author di…

I don't know how fair this is but will just say that the first thought that jumps to my mind here is that being surprised at a cryptographer advocating for deniable messages is a little bit like being surprised at a medical researcher advocating for effective antibiotics. It probably never occurs to either of them to question the legitimacy of their moral stance.

I certainly could be wrong. What’s the case for repudiation? Is making blackmail harder really the cryptographer’s mail argument for why repudiation is a benefit?

I didn’t see a more convincing argument in the blog post. If there is a technical reason why repudiation is beneficial, I would be grateful for an explanation.

Re: Ok Google: please publish your DKIM secret keys

#212
post #119

Earlier quoted context omitted.

-- Example -- Dear Ivanhoe, I regret to inform you that your HIV test came back positive. Please contact my office at your earliest convenience to arrange a follow up. Sincerely, Your doctor

No doctor should be writing that email in the first place; it would be an example of such a flagrantly negligent treatment of PHI that cryptographic signatures and reputability are kind of irrelevant.

Email is used outside of countries with these kinds of protections. For example, I know someone who had an STI test in Thailand and the results did indeed come via email.

Even if this example is imperfect, it's really not that hard to imagine a scenario where some type of compromising information is sent to you. Perhaps even accidentally.

Re: Ok Google: please publish your DKIM secret keys

#213

Earlier quoted context omitted.

> No one would even care if the Hunter Biden related emails passed DKIM except for the widespread allegation that they were fake, and no one still cares because conversation about them passing DKIM is widely suppressed (including on HN, unfortunately, where a post about it was immediately flagged). Uh... no RFC822 headers from the Hunter Biden emails were ever released, certainly none with a passing DKIM signature. I…

https://github.com/robertdavidgraham/hunter-dkim/blob/main/M...

Interesting, thanks. Odd that this data was never part of the published record from the Post, and that Graham's source is apparently secret? Curious what you make of that? If the Post had it, they'd surely have released it. I guess it's sort of academic at this point, but it does point to a few different actors pushing this story in different directions.

Re: Ok Google: please publish your DKIM secret keys

#214

The piece seems to be arguing from a general principle. Repudiation is a feature of most secure messaging applications and it is a feature that should be introduced to GMail. This argument doesn't fully address how technologies are actually used today. As far as I can tell, people who need repudiation are already using apps that have repudiation (eg Signal), because they know they are in a vulnerable position. The pe…

> The people who need non-repudiation already have it.

Can you really not think of a scenario where non-repudiation could be important even to people "not in power"?

Re: Ok Google: please publish your DKIM secret keys

#215
post #165

Earlier quoted context omitted.

Yes, you should absolutely think about everything that you commit to public record. Yes, you might be totally fine now. You might be hanging out and get photographed with this creepy billionaire named Jeffrey Epstein who is just another creepy billionaire at your creepy billionaire parties. Then 20 years from now we find out he's running pedophile island and people start looking into your associations. We are not tea…

Using the billionaire pedophile example is a disgusting trick. You're trying to set me up for appearing to support that. Why not use more neutral examples? Like being gay or supporting certain political causes? What if those later become controversial or illegal? What then? Do you want to live in a world where you have to guard everything you say in semi-private conversations, just in case it one day becomes controve…

I'm not setting you up as supporting anything.

I'm illustrating the severity of the identifiable public record. When the Nazis started rounding up people to put in camps, they looked at the _extremely detailed_ Christian Parish records saying who was what and where they lived.

They were thought to be innocuous and important records to keep at the time. Actually I think in the Scandinavian countries the state Church is still responsible for recording all marriage & death records. They stopped tracking births for the previously mentioned reasons. (Hey, we just learned the importance of separation of Church and State, too!)

Nobody knows how important privacy is. Until they do.

Re: Ok Google: please publish your DKIM secret keys

#216

Earlier quoted context omitted.

I don't know how fair this is but will just say that the first thought that jumps to my mind here is that being surprised at a cryptographer advocating for deniable messages is a little bit like being surprised at a medical researcher advocating for effective antibiotics. It probably never occurs to either of them to question the legitimacy of their moral stance.

I certainly could be wrong. What’s the case for repudiation? Is making blackmail harder really the cryptographer’s mail argument for why repudiation is a benefit? I didn’t see a more convincing argument in the blog post. If there is a technical reason why repudiation is beneficial, I would be grateful for an explanation.

Read Goldberg, Brewer, and Borisov:

https://otr.cypherpunks.ca/otr-wpes.pdf

Re: Ok Google: please publish your DKIM secret keys

#217

Earlier quoted context omitted.

I'm not going to present a moral argument (what is a moral argument in this context?), only two direct rebuttals of your objections: 1. DKIM provides neither truthfulness nor objectivity. It's a signature mechanism used between mail servers to reduce spam. For implementation reasons, most DKIM users sign with RSA keys that are either currently crackable or will be crackable in a matter of years. Consequently, "signed…

If right now DKIM doesn’t provide truthfulness or objectivity, then the author’s blackmail example already doesn’t apply. DKIM signatures, by your argument, are useless in blackmail, since they don’t verify the message. So why did the author resort to that as an example?

The problem is that it's not clear about it. It looks like it does quite a bit, and the counter-argument boils down to "someone could have cracked the secret key", which everyone always is told is the thing that is impossible. So you get plenty people believing and claiming DKIM can do that. This would be fixed by obviously breaking it.

Re: Ok Google: please publish your DKIM secret keys

#218
post #167
post #142

Earlier quoted context omitted.

A counter to the non-repudiation of old emails is the fact that people who own their own mail servers can rotate their DKIM keys. So it's already possible for e.g politicians to have their email set up in such a way that they're insulated from leaks. The argument here is more that customers of gmail and other email services are not offered repudiation as a feature.

"Rotating keys" isn't the important part. "Publishing keys" is the important part. "Rotating keys" is an implementation requirement of "DKIM with repudiability via eventually-published keys."

OP's argument is if you care about this enough, you can set up your own mail server, rotate and publish your own keys on whatever schedule you like.

Re: Ok Google: please publish your DKIM secret keys

#219

Earlier quoted context omitted.

> You said "there is never a legitimate need to do X". No, he didn't, and to use quotes to claim someone said something that they didn't say is extremely disingenuous.

Here is the actual quote: "once counterparties have authenticated each other's messages, the legitimate need for authentication is gone". Yes I used quotes in the "do X" sentence, but nobody will mistake it for a literal quote, because it contains "X" in place of the actual thing. Anyway, do you think there is something wrong with my characterization of that statement?

Yes, because it ignores the sentence that precedes it.
Post reply on HN