Earlier quoted context omitted.
I don’t understand the fascination with DKIM on this thread. Yes, journalists verified it. But they consider it supporting data, just as they wouldn’t automatically ignore any email that had no DKIM signature. Phone calls are never authenticated. Does anyone automatically believe or disbelieve recorded phone calls? I mean, “conspiracy theorists” (in the common usage of that terms) already believe only what they want…
I don't think it's a fascination, it's what the OP is about. We're talking about the subject of a blog post, no? I think the point boils down to expectation management: journalists (and ...) barely understand non-repudiation, much less why each of the following scenarios pans out: * 2006 email + 512-bit RSA, leaked in 2006: probably authentic * 2008 email + 512-bit RSA, leaked in 2012: potentially inauthentic * 2008…
The wrong solution is to make previously private keys public to make any reasoning about past data impossible in the name of “hut journalists might get a wrong impression”