Ok Google: please publish your DKIM secret keys
271–280 of 492 posts
Re: Ok Google: please publish your DKIM secret keys
#272Earlier quoted context omitted.
People who are protected from blackmail by email repudiation are by definition people who have incriminating emails. Maybe everyone had skeletons in their closet, but if you have email proof of skeletons I'm starting to wonder if you're such a good person. Also there's an argument that "good people" can be blackmailed for INVENTED misconduct, but wouldn't such fake emails be more convincing without the ability to ver…
Ah yes, the good old, “If you haven’t done anything wrong, you’ve got nothing to hide” argument. The authoritarians favourite argument for a police state. I guess you’re the type of person that would happily hand over all your personal files to the police on a regular basis as you have nothing to hide.
Personally I am fine with the idea (as represented in this comment https://news.ycombinator.com/item?id=25115654) that email is providing something similar to a "paper trail", and when you send an email you can expect that people can prove you sent it, should they get their hands on the email. However, I totally understand the position that private secure messaging is important and that email should default to that.
In the authoritarian argument, "you've got nothing to hide", is followed by "you are now forced to reveal all", in my execution it would be "you are accountable for all emails you send, forever, should they be released". I am ok with that specific lack of privacy in that context, but I can understand the position that non-repudiability should be opt-in, and privacy the default.
Re: Ok Google: please publish your DKIM secret keys
#273I know threads change over time, and it's dangerous to write a comment in response to the perceived gestalt of an HN thread, but, I have to say, it's pretty wild reading a thread on this site arguing so strenuously against the premise of secure messaging. In messaging cryptography, non-repudiability has for almost 2 decades been considered a vulnerability, not a feature. The OTR protocol[1] takes the step of publishi…
Whilst I agree with you that email messages should be repudiable , I have a feeling you're trying to pass something off as axiomatic that isn't. For example isn't a confidential business agreement basically exactly, by design, an authenticated non-repudiable message that can be authenticated by third parties (such as courts)?
Re: Ok Google: please publish your DKIM secret keys
#274Earlier quoted context omitted.
Not OP. But I would give all my data to the police/government... in an encrypted manner that has guarantees in place that only valid criminal investigations can decrypt. Heck, we do it on some level all the time anyways when it comes to things such as filing taxes, getting married, running companies, enforcing contracts and various other day-to-day benign interactions. At this point, I'm more inclined to believe that…
> I'm struggling to find compelling and valid reasons why we can't pursue a general solution that involves us giving all this "private" data to a government entity for legitimate investigations, fraud prevention and crime-solving whilst keeping that data free from abuse. Because that's not logically possible. It would be nice if it were, but just think about it: if you give data to the government, humans can look at…
While I understand the problem of evil governments, I broadly trust mine. I want them to have the power to investigate me, and my fellow citizens, for crimes. I don't want to love in a lawless country.
Re: Ok Google: please publish your DKIM secret keys
#275Earlier quoted context omitted.
The Hunter Biden email is a terrible example. It's very likely that what's been found on "Hunter Biden's" laptop is just hacked material which has been stuffed on a laptop to disguise the original source of the breach. In this case the DKIM signatures are being used to lend credibility to the story that the laptop was mysteriously left in repair shop, never to be reclaimed. DKIM is not meant to validate conversations…
It's not farfetched to believe a crack-addicted wealthy individual who seemed to live a very "promiscuous" lifestyle, would have forgotten some cheap laptop at a repair shop. These people are humans, at the end of the day.
Re: Ok Google: please publish your DKIM secret keys
#276Earlier quoted context omitted.
Ah yes, the good old, “If you haven’t done anything wrong, you’ve got nothing to hide” argument. The authoritarians favourite argument for a police state. I guess you’re the type of person that would happily hand over all your personal files to the police on a regular basis as you have nothing to hide.
Not OP. But I would give all my data to the police/government... in an encrypted manner that has guarantees in place that only valid criminal investigations can decrypt. Heck, we do it on some level all the time anyways when it comes to things such as filing taxes, getting married, running companies, enforcing contracts and various other day-to-day benign interactions. At this point, I'm more inclined to believe that…
> in an encrypted manner that has guarantees in place that only valid criminal investigations can decrypt
What constitutes a valid criminal investigation, who decides? Do you, does a prosecutor, a judge, the police?
Is it a valid to decrypt your data just see if you were at a specific location at a specific time? What about so the police can check a theory? How about to see if you joined an unsanctioned protest, smoked a joint, speed while driving, downloaded a movie?
Speeding and copyright theft are both criminal, are you saying that your happy to make it trivial to investigate you for these crimes an prosecute you for them?
It used to be criminal to engage in homosexual behaviour, and in some parts of the world. Once upon a time that would be a valid criminal investigation in the US. For a short while it was looking like abortions might become criminal in the not too distant future.
Privacy is a fundamental tool for allowing society to progress and change, and for avoiding totalitarianism.
Re: Ok Google: please publish your DKIM secret keys
#277The problem with the author's paper is that his assumption (and that of, apparently, media organizations, Wikileaks, and others) of DKIM "ensuring non-repudiation of emails" is simply wrong. >DKIM provides a life-long guarantee of email authenticity that anyone can use to cryptographically verify the authenticity of stolen emails, even years after they were sent. No, it doesn't. It simply offers an assurance that, at…
When a potentially important email dump is leaked individuals will use any reasonable means to gain information about it's authenticity.
Knowing that DKIM headers are on those emails and that the service provider hasn't published those keys changes the question from:
"Did you send this email" to "Was your email address compromised at this time?"
Re: Ok Google: please publish your DKIM secret keys
#278As a security professional I 100% agree with the author. The comments here on Hacker News seem to have tripped on the examples given (keywords: politicians, journalists) and turned this into the more generic and politically loaded discussion whether it's desirable to "cryptographically verify" what politicians write. But that's not the point! The point is that DKIM is technically not designed for this use case and th…
If some provider decides to implement this proposal, I don't think they should do it retroactively and publish old keys. It would be just inviting additional political shitstorm.
Re: Ok Google: please publish your DKIM secret keys
#279The piece seems to be arguing from a general principle. Repudiation is a feature of most secure messaging applications and it is a feature that should be introduced to GMail. This argument doesn't fully address how technologies are actually used today. As far as I can tell, people who need repudiation are already using apps that have repudiation (eg Signal), because they know they are in a vulnerable position. The pe…
> The people who need non-repudiation already have it. Can you really not think of a scenario where non-repudiation could be important even to people "not in power"?
Re: Ok Google: please publish your DKIM secret keys
#280Earlier quoted context omitted.
> I'm struggling to find compelling and valid reasons why we can't pursue a general solution that involves us giving all this "private" data to a government entity for legitimate investigations, fraud prevention and crime-solving whilst keeping that data free from abuse. Because that's not logically possible. It would be nice if it were, but just think about it: if you give data to the government, humans can look at…
But, the message you are replying to points out governments already have piles of information about you -- your taxes for example. They can easily add to this (in appropriate legal situations), by reaching out to banks in your country for example. While I understand the problem of evil governments, I broadly trust mine. I want them to have the power to investigate me, and my fellow citizens, for crimes. I don't want…
Germany 1933, Donald Trump today, far right extremism in Europe are all examples of how trustworthy governments become evil governments.
Democracy doesn’t offer a defence against “evil” governments. Only that you need a majority (and frequently not even a majority) to vote for one.