Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

291–300 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#291
post #119
post #91

Earlier quoted context omitted.

Other than whistleblowers and activists fighting the dictatorships (and they can work-around this), what is the case where not being able to prove who sent the email would be a good thing?

-- Example -- Dear Ivanhoe, I regret to inform you that your HIV test came back positive. Please contact my office at your earliest convenience to arrange a follow up. Sincerely, Your doctor

Or it could be:

"Hey Ivanhoe, your buddy from government here. That thing that we discussed, no problem I arranged everything, T says it's cool, just wire us the money and the project is yours."

In my view, if someone is going to blackmail me for some sensitive topic like being HIV positive or dox me in revenge, solution is not that I have to go public and lie that it's not real (and risk to be counter-proven it is) - but to have police put their blackmailing asses in the jail. That's the type of protection of my freedom and privacy that I hope for.

And in the end, who has ever believed people doing public denials? Once the word gets out, by the time you publish the rebuttal majority of folks will already have an opinion on it and that will stick with you for long time no matter what you say later.

Re: Ok Google: please publish your DKIM secret keys

#292

Earlier quoted context omitted.

But, the message you are replying to points out governments already have piles of information about you -- your taxes for example. They can easily add to this (in appropriate legal situations), by reaching out to banks in your country for example. While I understand the problem of evil governments, I broadly trust mine. I want them to have the power to investigate me, and my fellow citizens, for crimes. I don't want…

Do you trust all future governments? Germany 1933, Donald Trump today, far right extremism in Europe are all examples of how trustworthy governments become evil governments. Democracy doesn’t offer a defence against “evil” governments. Only that you need a majority (and frequently not even a majority) to vote for one.

I'm not clear what you are arguing for? Do you not want a functioning, effective police force now, in case they become evil in the future (or already are evil, depending on your point of view)?

If a government turns full evil, they don't need evidence against you, they can just lock you up without charge.

Re: Ok Google: please publish your DKIM secret keys

#293
post #243

Earlier quoted context omitted.

>this should be an opt-in feature (and not provided server-side, at that). Why?

It just feels like the baseline expected behavior of a communications system to me that makes no explicit claims otherwise. Legal signatures are heavily ritualized (blue/black ink only, initial here and sign there etc.) in most societies for good reason – it makes the signer stop for a moment and reconsider what they are doing, if the document they are signing is truly aligned with their intentions and so on. As anot…

> It just feels like the baseline expected behavior of a communications system to me that makes no explicit claims otherwise.

Why do you feel like email "makes no explicit claims" about the authenticity of emails? Laypeople are not even aware of the possibility of spoofing the sender field in emails. Technical people can check the "explicit claims" of a protocol like e-mail, SPF, DKIM, etc. to understand what it claims to do. In other words, email makes both implicit claims, and explicit claims about the verifiability of the sender field.

Re: Ok Google: please publish your DKIM secret keys

#294

Earlier quoted context omitted.

People who are protected from blackmail by email repudiation are by definition people who have incriminating emails. Maybe everyone had skeletons in their closet, but if you have email proof of skeletons I'm starting to wonder if you're such a good person. Also there's an argument that "good people" can be blackmailed for INVENTED misconduct, but wouldn't such fake emails be more convincing without the ability to ver…

I don't think the implication that only "bad" people can be blackmailed is valid. You could be blackmailed for being a homosexual in many parts of the US still or doubting the existence of god or having unacceptably conservative political views. We do all sorts of things that are not at all wrong but may carry a significant social or economic cost if they were to be exposed publicly.

I think people are overlooking this. It can even be worse in other countries. Some of those things (among numerous other things) can lead to death in a few countries.

Re: Ok Google: please publish your DKIM secret keys

#295

Earlier quoted context omitted.

(a) I wasn't aware of this. (b) Thanks for the link! (c) The IETF is such a shitshow for cryptography.

The IETF is an open organisation. Specs are written & ratified by the people who show up. And often that means folks from large companies. If you don’t like that status quo, get involved. They would love to have you @tptacek.

The problem isn't any one individual who is/isn't involved, it's the consensus mechanism. If you bring in a great sous chef and ask them to make you an omelet, they will make a great omelet. If you bring in a committee of people -- some sell omelet pans, some run hotel chains where free omelets are part of the package, some want you to adopt their vegan egg substitute -- you are not going to get a great omelet spec. Adding one omelet expert to the committee doesn't add anything over just asking an omelet expert to make some eggs.

Re: Ok Google: please publish your DKIM secret keys

#296

Earlier quoted context omitted.

Do you trust all future governments? Germany 1933, Donald Trump today, far right extremism in Europe are all examples of how trustworthy governments become evil governments. Democracy doesn’t offer a defence against “evil” governments. Only that you need a majority (and frequently not even a majority) to vote for one.

I'm not clear what you are arguing for? Do you not want a functioning, effective police force now, in case they become evil in the future (or already are evil, depending on your point of view)? If a government turns full evil, they don't need evidence against you, they can just lock you up without charge.

But we already have functioning and effective police forces in the western world without having to give up our rights to privacy.

Why would we want to give up more?

Re: Ok Google: please publish your DKIM secret keys

#297
post #176

Earlier quoted context omitted.

Yes, but it’s not DKIM or not DKIM that will make it plausible in the court of public opinion.

Current events prove otherwise. See Hunter Biden.

I have not seen a single mention of DKIM w.r.t to Hunter Biden. Did you? Was any evidence presented? I couldn’t find any.

I fail to see how admissibility or lack of it, in a court of law or of public opinion, has anything to do with DKIM+Hunter Biden. Can you elaborate?

Re: Ok Google: please publish your DKIM secret keys

#298

Earlier quoted context omitted.

I agree that e-mail is horrible, and I would prefer if contracts (like purchase receipts) moved off e-mail to something else, but that's tangential to the point. If Google started to publish and rotate DKIM keys, the world wouldn't suddenly move away from email.

Receipts can be signed with gnupg, it actually provides non-repudiation guarantee you want, DKIM doesn't provide that, it's only for journalists.

> Receipts can be signed with...

In the real world it doesn't matter which cryptographic protocols are theoretically available for use. What matters is which protocols everyone else is using. For example, in the case of receipts for purchases on the web, literally everyone is using email. You will not be able to get amazon to sign a receipt with gnupg.

If you want to embark on a path of convincing the world to move away from email, that's great, good for you. Just don't pretend like removing non-repudiation from e-mails is a quest on that path. It's not.

Re: Ok Google: please publish your DKIM secret keys

#299
post #194

Earlier quoted context omitted.

If non-repudiation is important to you, then both parties should consent to it and use a platform that explicitly supports it. It shouldn’t be sprung on people without consent. It would be like saying it’s fine to keep a recording from someone else’s webcam because it might prove a crime later. There’s a reason why justice systems have statues of limitations. People should need to look over their shoulders for the re…

It is not really being sprung on them with how long it has existed. Not at all like continuing recording on a webcam where you might say things never intended for the party receiving it. Are ppl who don't even know DKIM exists but know they have shady emails saved in the cloud or on their personal really just banking on repudiation and thats why they take no other action like deleting the email or putting more though…

Consent needs to be given freely, with knowledge of what you’re consenting to. If it’s not free and knowledgeable, it’s not consent.

I certainly didn’t realise that DKIM can be used as a non-repudiation signature, I’m sure most people using email don’t.

Thus there’s no consent and I would say that non-repudiation has been sprung on me.

The duration has nothing to do with it. Just because you can keep a camera hidden in someones room for an extended period of time doesn’t mean it’s ethical or consensual to record them.

Finally statues of limitations don’t protect people from a trial in social media. Social media is just as capable as the justice system of destroying a persons life. Unfortunately Twitter doesn’t have a statue of limitations.

Re: Ok Google: please publish your DKIM secret keys

#300
post #91

Earlier quoted context omitted.

Other than whistleblowers and activists fighting the dictatorships (and they can work-around this), what is the case where not being able to prove who sent the email would be a good thing?

Toward the end of the blog post, the author points out that while it often is nice to have the ability to authenticate who sent an email, nobody asked for this feature to be enabled by default on all their communications. It seems like a matter of preference, and it isn't clear that people thought about it at all. People change over time and normal human communications have a natural sunset built in as people forget…

> People change over time and normal human communications have a natural sunset built in as people forget exactly who said what.

It's true, but I'm not sure it's as good thing as you believe. I was born in communism, and then later I lived through the transition and have seen many people use this exact mechanism that you mention to whitewash their biographies. People just don't remember long, and thanks to that all of the sudden everyone was a victim of the regime who fought for democracy, while in fact they were exactly the opposite. Many bad people not just got away, but also gain significant benefits thanks to "people forget exactly who said what" and it did a lot of damage to my country and the society. So, while people do change over time, and we all sometimes have said something stupid that we didn't really mean, IMHO as adults we all should stand behind the things that we say and hold accountable to at least some level for it.

And to protect people from other's misusing their past, perhaps it would be more beneficial to educate the crowd not to be overly judgmental and not to jump to conclusions like everyone on soc. medias just loves to do - rather than forcing individuals to lie about their past to defend of blackmailers.

Post reply on HN