Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

301–310 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#301

Earlier quoted context omitted.

I don’t understand the fascination with DKIM on this thread. Yes, journalists verified it. But they consider it supporting data, just as they wouldn’t automatically ignore any email that had no DKIM signature. Phone calls are never authenticated. Does anyone automatically believe or disbelieve recorded phone calls? I mean, “conspiracy theorists” (in the common usage of that terms) already believe only what they want…

I don't think it's a fascination, it's what the OP is about. We're talking about the subject of a blog post, no? I think the point boils down to expectation management: journalists (and ...) barely understand non-repudiation, much less why each of the following scenarios pans out: * 2006 email + 512-bit RSA, leaked in 2006: probably authentic * 2008 email + 512-bit RSA, leaked in 2012: potentially inauthentic * 2008…

The right solution in this case is to educate journalists - they are up to date on things like deep fakes and should be on DKIM.

The wrong solution is to make previously private keys public to make any reasoning about past data impossible in the name of “hut journalists might get a wrong impression”

Re: Ok Google: please publish your DKIM secret keys

#302
post #175

Earlier quoted context omitted.

I think he's referring to this? https://www.trumpaccountability.net/

That website's owners already abandoned the project under suspicious pretenses of "unity".

The biggest pretence is that it's 'abandoned'

Re: Ok Google: please publish your DKIM secret keys

#303

Earlier quoted context omitted.

I'm not clear what you are arguing for? Do you not want a functioning, effective police force now, in case they become evil in the future (or already are evil, depending on your point of view)? If a government turns full evil, they don't need evidence against you, they can just lock you up without charge.

But we already have functioning and effective police forces in the western world without having to give up our rights to privacy. Why would we want to give up more?

Some people want to be more private than current (for example, this discussion of email keys). As more things move online, it is worth thinking where the balance should be (we probably agree on that), I think the balance should be less privacy (I'm sure you don't agree with that, a full discussion on that won't fit well in a ycombinator thread).

Re: Ok Google: please publish your DKIM secret keys

#304
post #262

>it makes us all more vulnerable to extortion and blackmail This is true with the added proviso that, by "us", he means "the guilty". The rest are protected, on the contrary, to this very particular form of these crimes.

Adding a proviso to your proviso, "the guilty" here could include those guilty of being transexual, associating with undesirables, holding unpopular opinions, having mental health issues, or, ya know, having anything private they prefer not to be disclosed.

Re: Ok Google: please publish your DKIM secret keys

#305

Earlier quoted context omitted.

wtf? it happens all the time. I've raised VC money based on emailed contracts, bought businesses based on them, bought domain names. It is incredibly standard and legal (in almost all of the jurisdictions I've worked in, which is a lot).)

Sure. But what authenticates the contract? Do you sign and scan them?

PDFs with e-signatures are very common place now. Have you heard of DocuSign or other similar services?

Re: Ok Google: please publish your DKIM secret keys

#306

Earlier quoted context omitted.

Ok, my GPG example was wrong. And yes, you got me, I'm not a professional cryptographer. But can you address the point? You said "once counterparties have authenticated each other's messages, the legitimate need for authentication is gone". I provided a counter-example to demonstrate that your statement was an exaggeration. You clearly dispute some part of this, but it's unclear to me what the disputed part is. Edit:…

> I provided a counter-example to demonstrate that your statement was an exaggeration. Which counterexample is that exactly? Your counterexample involving a store is incorrect -- the store's email would still be authenticated for a smaller amount of time which would allow your server to verify that it is a valid email that came from the store's servers. EDIT: Since you responded with an edit, I suppose I should as we…

> Accidental non-repudiability can have negative consequences itself. For one, relying on the kind of poor man's non-repudiability that DKIM gives you leaves powerful central entities with the ability to forge email while convincing almost everyone that it is legitimate.

I fully agree.

> From reading everything that you wrote, I think that your thesis is that email, specifically, ought to be non-repudiable. That might be a worthwhile idea, but it should be presented as such at the forefront. If others agree that this is a valid and useful concept, then a non-repudiability mechanism could be added to email explicitly, just as DKIM was added. But don't use DKIM for this, since it is a poor substitute.

If the choice was between "DKIM for non-repudiability" and "a better mechanism for non-repudiability", of course I would support the better mechanism. But that's not the choice here. The proposal here is to remove this accidental, partial non-repudiability mechanism that currently exists, and replace it with nothing. That would leave the world worse off, not better. DKIM protects innocent people from being framed for saying horrible things, and DKIM protects innocent people from guilty people who do horrible things. And sure, sometimes DKIM might be used against innocent people in some way, but the balance seems heavily in favor of DKIM (from the perspective of innocent people).

Re: Ok Google: please publish your DKIM secret keys

#307

Earlier quoted context omitted.

Ah yes, the good old, “If you haven’t done anything wrong, you’ve got nothing to hide” argument. The authoritarians favourite argument for a police state. I guess you’re the type of person that would happily hand over all your personal files to the police on a regular basis as you have nothing to hide.

To be clear, the reason I was presenting that is that the OP says the opposite, essentially "You have to fear being blackmailed, even if you have done nothing wrong". I'm suggesting that non-repudiation is actually a good defense against blackmail for people who have "done nothing wrong". thinkharderdev provides a more concrete example of one of the problems that arises in the police state, in that "wrong"-ness is no…

I find this a little ironic

> that email is providing something similar to a "paper trail"

because paper doesn’t provide non-repudiation and never has done.

The whole point of a “paper trail” is the “trail” bit, as it provides providence of a sequence of actions or communications that logically fit together. Hopefully providing evidence for your side of a dispute.

There’s no need for email to be non-repudiatable to achieve this. In fact I serious doubt a court would care if an email is DKIM signed. Very rarely are disputes so simple and straightforward that proving a single email was sent is enough to produce an outcome.

In short DKIM non-repudiation by default gives up everyones privacy, to protect a tiny group of individuals engaged in extra edge case disputes, where the entire outcome of the disputes hangs on the validity of a single email.

Re: Ok Google: please publish your DKIM secret keys

#308
post #238

Earlier quoted context omitted.

I'm not setting you up as supporting anything. I'm illustrating the severity of the identifiable public record. When the Nazis started rounding up people to put in camps, they looked at the _extremely detailed_ Christian Parish records saying who was what and where they lived. They were thought to be innocuous and important records to keep at the time. Actually I think in the Scandinavian countries the state Church i…

>I'm illustrating the severity of the identifiable public record. This is an argument in favor of emails being non-verifiable, so now I'm confused. Previously you seem to be supporting the idea that email should be verifiable. Now you seem to be arguing the opposite. Everything you wrote above correlates with the opinions I've expressed so far. You also wrote: > If you live in a [country where homosexuality is illega…

Not at all.

a) email being verifiable is fine b) nobody should be so stupid as to use email for anything personal. it is not privileged communication and potentially permanent public record. c) if you want to use email, you'd better encrypt it and only for recipients that you trust.

Re: Ok Google: please publish your DKIM secret keys

#309

Earlier quoted context omitted.

Yes, because it ignores the sentence that precedes it.

> Yes, because it ignores the sentence that precedes it. This sentence? "Serious secure messengers have been designed to avoid non-repudiation since OTR." I don't see how this sentence supposedly alters the meaning of the sentence that comes after it? At this point it seems like you just want to sow confusion. If I had misinterpreted your words in some way, you could have clarified the misunderstanding like 10 times…

"once counterparties have authenticated each other's messages" is the omission that changes the meaning of the quote.

Re: Ok Google: please publish your DKIM secret keys

#310

Earlier quoted context omitted.

You said "there is never a legitimate need to do X". I gave an example of a legitimate need to do X. Your rebuttal is that... I'm confused? Yeah, you're gonna have to be more specific than that if you want to convince anybody.

You gave a example of a 'need' to do X that is specifically not legitimate. I'm not sure (and decline to speculate) whether you're confused or malicious or some other problem entirely, but you are wrong.

> You gave a example of a 'need' to do X that is specifically not legitimate.

The example was that two parties are disputing a contract, the court is attempting to resolve the dispute, and the court has a need to authenticate the contract. Can you explain why you think that this is not a legitimate need to authenticate a document?

> I'm not sure (and decline to speculate) whether you're confused or malicious or some other problem entirely, but you are wrong.

You "decline to speculate", and then proceed to speculate anyway? Ok. Well, it's certainly easier to resort to calling me names, than actually defending your position with arguments.

Post reply on HN