Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

221–230 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#221

Earlier quoted context omitted.

It's just really clear that people in this thread are trying to approach this from first principles without any engagement in the field that they're discussing. That's a fun thing to do as, like, a game or a way to pass the time, and I guess that's what HN is, but it's still crazymaking, because essentially every paper written about messaging cryptography refutes this comment. Cryptographers would like to move people…

Ok, my GPG example was wrong. And yes, you got me, I'm not a professional cryptographer. But can you address the point? You said "once counterparties have authenticated each other's messages, the legitimate need for authentication is gone". I provided a counter-example to demonstrate that your statement was an exaggeration. You clearly dispute some part of this, but it's unclear to me what the disputed part is. Edit:…

> Ok, my GPG example was wrong. And yes, you got me, I'm not a professional cryptographer. But can you address the point? You said "once counterparties have authenticated each other's messages, the legitimate need for authentication is gone". I provided a counter-example ...

I think the person you're talking to thinks this is very obvious and thus isn't stating it explicitly, but in the special case where you want an email to include non-repudiation, such as for a purchase receipt, the sender should just add non-repudiation to it in the form of a signature that's intended for that. Simple.

Re: Ok Google: please publish your DKIM secret keys

#222

Earlier quoted context omitted.

> Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Exactly. If one enters into an contract using an e-mail, then DKIM can be used as a proof to the court of law that the contract was accepted by both sides.

Entering an contract via an email is a ridiculous idea from the start.

That's right, we need more travel and in-person meetings now.

Re: Ok Google: please publish your DKIM secret keys

#223

Earlier quoted context omitted.

"An accident of the past few years is that this feature has been used primarily by political actors working in a manner that many people find agreeable — either because it suits a partisan preference, or because the people who got “caught” sort of deserved it. But bad things happen to good people too. If you build a mechanism that incentivizes crime, sooner or later you will get crimed on."

People who are protected from blackmail by email repudiation are by definition people who have incriminating emails. Maybe everyone had skeletons in their closet, but if you have email proof of skeletons I'm starting to wonder if you're such a good person. Also there's an argument that "good people" can be blackmailed for INVENTED misconduct, but wouldn't such fake emails be more convincing without the ability to ver…

I don't think the implication that only "bad" people can be blackmailed is valid. You could be blackmailed for being a homosexual in many parts of the US still or doubting the existence of god or having unacceptably conservative political views. We do all sorts of things that are not at all wrong but may carry a significant social or economic cost if they were to be exposed publicly.

Re: Ok Google: please publish your DKIM secret keys

#224

Earlier quoted context omitted.

> Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Exactly. If one enters into an contract using an e-mail, then DKIM can be used as a proof to the court of law that the contract was accepted by both sides.

Entering an contract via an email is a ridiculous idea from the start.

I don't know about your country, but in mine (The Netherlands), it is a completely and utterly valid way to enter a contract.

Actually, you are free to enter a contract in any way possible. It is vormvrij (translated: form-free). Excluded is the purchase of a house, as far as I know. But for the rest, you are free to come to an agreement via WhatsApp, Facebook, email, or a scrawl on a piece of paper.

Re: Ok Google: please publish your DKIM secret keys

#225
post #180

Earlier quoted context omitted.

Ah yes, the good old, “If you haven’t done anything wrong, you’ve got nothing to hide” argument. The authoritarians favourite argument for a police state. I guess you’re the type of person that would happily hand over all your personal files to the police on a regular basis as you have nothing to hide.

Not OP. But I would give all my data to the police/government... in an encrypted manner that has guarantees in place that only valid criminal investigations can decrypt. Heck, we do it on some level all the time anyways when it comes to things such as filing taxes, getting married, running companies, enforcing contracts and various other day-to-day benign interactions. At this point, I'm more inclined to believe that…

Because we don't trust the government agents to provide such guarantees, or to honor them if they do?

Re: Ok Google: please publish your DKIM secret keys

#226
post #182

Earlier quoted context omitted.

This describes all encrypted and short lived messages. Edit: Removed the word "literally" because it was incorrect and caused distraction from the actual argument.

It doesn't at all. You're misunderstanding. Or, are you using the word "literally" in the modern sense of "not literally"?

Are you just nitpicking my choice of words or are you going to explain how auto-disappearing messages aren't potentially destroying evidence in the exact same way you've described? As for encrypted messaging, yes it is not the same as "literally" destroying evidence. But it is hiding evidence (based on your logic).

The end result is the same in the context of the claims you previously made. That is: justice is potentially being subverted.

Re: Ok Google: please publish your DKIM secret keys

#227

Earlier quoted context omitted.

No because it's not on us to make moral distinctions between someone who is gay and doesn't want to make that information public, and someone who isn't gay and is being falsly blackmailed. Publishing the DKIM keys makes both cases harder because you no longer have authenticity claims. Neither claim has authenticity value and instead is just a "their word versus yours" situation. Humans are terrible moral adjudicators…

When an angry mob goes after suspected homosexuals, do you think they stop to authenticate DKIM signatures of emails? I'll give you a hint: no. In fact, it's hard to imagine any scenario where anybody goes through the trouble of authenticating e-mails of a "normal person" who is persecuted of something other than crimes.

Homosexuality is considered a crime in quite a few countries.

Re: Ok Google: please publish your DKIM secret keys

#228
post #227

Earlier quoted context omitted.

When an angry mob goes after suspected homosexuals, do you think they stop to authenticate DKIM signatures of emails? I'll give you a hint: no. In fact, it's hard to imagine any scenario where anybody goes through the trouble of authenticating e-mails of a "normal person" who is persecuted of something other than crimes.

Homosexuality is considered a crime in quite a few countries.

Well, then if you live in one of those countries or plan on traveling through them, you're probably at risk if you're an open homosexual.

If you live in one of those countries and secretly a homosexual, do not send emails indicating that you're a homosexual.

You wouldn't tape your key to your front door.

Re: Ok Google: please publish your DKIM secret keys

#229

Wow. This blog post is appalling. I completely disagree with it. Consider this excerpt from the blog post: > But DKIM authenticity is great! Don’t we want to be able to authenticate politicians’ leaked emails? > Modern DKIM deployments are problematic because they incentivize a specific kind of crime: theft of private emails for use in public blackmail and extortion campaigns. An accident of the past few years is tha…

> 1. The truthfulness and reliability of the historical record is important. [...]

Everybody agrees here, but how does one gets to decide that Google, a private corporation, is the one to decide that a given email is an accurate historical email? An email provider is a defacto certificate authority? Are these dkim keys subject to the same standard of care as private keys that CAs manage?

For your regular-person scenario, having a way for a 3rd party private company "certify" an email sent from another private company (example: your online order) may be good enough, but is it good enough in every scenario?

Re: Ok Google: please publish your DKIM secret keys

#230

Earlier quoted context omitted.

> The thing that protects you from blackmail is not getting involved in things you can be blackmailed for. This is incorrect, because the things that someone can be blackmailed for is not the same as the set of immoral or unethical acts. You can be blackmailed for being gay, or for having a serious medical condition that's undisclosed. Neither of those situations is a "well just don't do that" kind of thing. The defe…

Nobody is telling you to not be gay. If you being gay is a secret, then don't send that secret over _plain fucking text email_. Do you send your social security number to people in emails? Email has never been privileged communication and the problem isn't one of validation but one of not understanding one's level of privacy and risk. It uses relays without end-to-end encryption and there's no guarantee that what you…

If a global infrastructure provider can, without downside, offer non-repudiability – why shouldn't they?

Not everyone is tech savvy. Not everyone understands encryption. Not everyone makes rational choices all the time.

Does that mean everybody should suffer the consequences of an arguably unintentional side effect of the technical implementation of DKIM?

Post reply on HN