I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?
Among messaging cryptographers, it's not even an argument. Serious secure messengers have been designed to avoid non-repudiation since OTR. Non-repudiation is a vulnerability: once counterparties have authenticated each other's messages, the legitimate need for authentication is gone; allowing random strangers to authenticate messages concedes information to them. Here, have a link, from 2004: https://otr.cypherpunks…
Ok Google: please publish your DKIM secret keys
261–270 of 492 posts
Re: Ok Google: please publish your DKIM secret keys
#262This is true with the added proviso that, by "us", he means "the guilty". The rest are protected, on the contrary, to this very particular form of these crimes.
Re: Ok Google: please publish your DKIM secret keys
#263Earlier quoted context omitted.
> His point was that you pointed out a use case for some sort of cryptographic signing, not for (ab-) using DKIM for this purpose rather than what it was designed for. First, thank you for the clarification. Second, to answer tptacek's point, I understand that authenticating emails as a third party is an unintended side effect of the DKIM protocol. I understand that cryptographers would like people to move onto using…
It's just really clear that people in this thread are trying to approach this from first principles without any engagement in the field that they're discussing. That's a fun thing to do as, like, a game or a way to pass the time, and I guess that's what HN is, but it's still crazymaking, because essentially every paper written about messaging cryptography refutes this comment. Cryptographers would like to move people…
Re: Ok Google: please publish your DKIM secret keys
#264Earlier quoted context omitted.
> Exactly. If one enters into an contract using an e-mail, then DKIM can be used as a proof to the court of law that the contract was accepted by both sides. It would make a good TV drama plot, but courts don't work this way in real life. If that were the case, courts wouldn't be able to enforce contracts with wet signatures (which are straightforward to forge), or verbal contracts (which are valid contracts and regu…
Not to mention that DKIM only validates that en email was sent with particular content from a particular email address. It cannot ensure who was actually sitting at the keyboard composing the email.
Re: Ok Google: please publish your DKIM secret keys
#265Earlier quoted context omitted.
Entering an contract via an email is a ridiculous idea from the start.
I don't know about your country, but in mine (The Netherlands), it is a completely and utterly valid way to enter a contract. Actually, you are free to enter a contract in any way possible. It is vormvrij (translated: form-free). Excluded is the purchase of a house, as far as I know. But for the rest, you are free to come to an agreement via WhatsApp, Facebook, email, or a scrawl on a piece of paper.
Re: Ok Google: please publish your DKIM secret keys
#266Earlier quoted context omitted.
I don't know about your country, but in mine (The Netherlands), it is a completely and utterly valid way to enter a contract. Actually, you are free to enter a contract in any way possible. It is vormvrij (translated: form-free). Excluded is the purchase of a house, as far as I know. But for the rest, you are free to come to an agreement via WhatsApp, Facebook, email, or a scrawl on a piece of paper.
In the U.S., many contracts (but not all) can in principle by default be oral and still be enforceable by law. https://smallbusiness.findlaw.com/business-contracts-forms/w...
Re: Ok Google: please publish your DKIM secret keys
#267Earlier quoted context omitted.
Entering an contract via an email is a ridiculous idea from the start.
wtf? it happens all the time. I've raised VC money based on emailed contracts, bought businesses based on them, bought domain names. It is incredibly standard and legal (in almost all of the jurisdictions I've worked in, which is a lot).)
Re: Ok Google: please publish your DKIM secret keys
#268Re: Ok Google: please publish your DKIM secret keys
#269As a security professional I 100% agree with the author. The comments here on Hacker News seem to have tripped on the examples given (keywords: politicians, journalists) and turned this into the more generic and politically loaded discussion whether it's desirable to "cryptographically verify" what politicians write. But that's not the point! The point is that DKIM is technically not designed for this use case and th…
> First of all the only field that it's required to sign is the From: header
OK, I've never looked into DKIM before, but 6376 looks fairly recent, and it reports the message body must be hashed. Now sure, there may be issues with the hash to allow arbitrary collisions, and of course the key may have been leaked or broken, and in any case today's key is unlikely to be secure against nation states now, let alone in 10 years time.
I agree in general the idea that having "DKIM signed" mails means they are authentic is an issue -- in 20 years time it will be easy enough for anyone to forge a DKIM signature for any email they want that they claim was sent today, but from what I can see the message body is signed.
Re: Ok Google: please publish your DKIM secret keys
#270Earlier quoted context omitted.
I don't know about your country, but in mine (The Netherlands), it is a completely and utterly valid way to enter a contract. Actually, you are free to enter a contract in any way possible. It is vormvrij (translated: form-free). Excluded is the purchase of a house, as far as I know. But for the rest, you are free to come to an agreement via WhatsApp, Facebook, email, or a scrawl on a piece of paper.
Same in Sweden. "Are you okey with paying extra for X?" "Yes, please go ahead." And that's how a new contract gets signed! No need to fly someone 1500km just for that.