Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

311–320 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#311
post #180

Earlier quoted context omitted.

Not OP. But I would give all my data to the police/government... in an encrypted manner that has guarantees in place that only valid criminal investigations can decrypt. Heck, we do it on some level all the time anyways when it comes to things such as filing taxes, getting married, running companies, enforcing contracts and various other day-to-day benign interactions. At this point, I'm more inclined to believe that…

How exactly would you do this? > in an encrypted manner that has guarantees in place that only valid criminal investigations can decrypt What constitutes a valid criminal investigation, who decides? Do you, does a prosecutor, a judge, the police? Is it a valid to decrypt your data just see if you were at a specific location at a specific time? What about so the police can check a theory? How about to see if you joine…

>"What constitutes a valid criminal investigation, who decides? Do you, does a prosecutor, a judge, the police?"

Some sort of formal process with reasonable oversight the necessity of multiple points of compromise and/or collusion in order for the data to be abused for non-governmental use. Bottom line, I can't say I've "solved" the problem and have the perfect answer to your question. But I'm sure we, collectively as a society filled with smart people that want to move us forward, could put down some (fundamental?) tools/rules/processes that would negate the potential for abuse up until a certain point. Maybe we can't do 100%, but we could do 95 or 98%?

>"Is it a valid to decrypt your data just see if you were at a specific location at a specific time? What about so the police can check a theory? How about to see if you joined an unsanctioned protest, smoked a joint, speed while driving, downloaded a movie?"

Yes, very much so Yes! Especially the location based stuff as it's perfect for investigations without revealing details. "List all people that were within 50m of this crime location during this timespan." already giving the data (car's black-box) to government (and private insurance companies) in order to facilitate an investigation.

But to your point about drug-use, speeding and copyright infringement. If we don't want something prosecuted then we shouldn't have it as a crime. But as it stands now, a bunch of what you mentioned is a crime. That represents an implicit agreement by all of us in society that says we deem those things punishable. We can't hide behind lack of capability to police said crimes, but still label them as such. That is ripe for offical-power abuse. For all we know, if we lived in a society where we had such strict enforcement of laws as I suggest, we'd potentially have greater churn and change in our laws to match the opinions of society as it changed and evolved.

> "Privacy is a fundamental tool for allowing society to progress and change, and for avoiding totalitarianism."

I disagree. I'm not seeing it. There is just way too much going wrong today in 1-st world countries whilst we have really good privacy for it to be the case. We're downright descending into totalitarianism and thought/opinion control territory, all whilst our "privacy" is mostly maintained and respected. Are you saying we need more of it? What would that look like to you?

Re: Ok Google: please publish your DKIM secret keys

#312

Earlier quoted context omitted.

> Exactly. If one enters into an contract using an e-mail, then DKIM can be used as a proof to the court of law that the contract was accepted by both sides. It would make a good TV drama plot, but courts don't work this way in real life. If that were the case, courts wouldn't be able to enforce contracts with wet signatures (which are straightforward to forge), or verbal contracts (which are valid contracts and regu…

> If that were the case, courts wouldn't be able to enforce contracts with wet signatures (which are straightforward to forge) I'm pretty confident that I could sign an email with a DKIM key if that were published, however, there's nothing that would give me the confidence that I could forge a pen signature in such a way that not even an expert could detect the forgery. > or verbal contracts (which are valid contract…

I'm not a a lawyer, but according to the first google result "the Uniform Commercial Code [...] requires that contracts for the sale of goods over $500 to be in writing".[1]

In practice, this doesn't seem to mean that every time you buy an iPhone, Apple provides you a paper contract authenticated with an actual verifiable hand-signed signature of an authorised officer.

Re: Ok Google: please publish your DKIM secret keys

#313
post #309

Earlier quoted context omitted.

> Yes, because it ignores the sentence that precedes it. This sentence? "Serious secure messengers have been designed to avoid non-repudiation since OTR." I don't see how this sentence supposedly alters the meaning of the sentence that comes after it? At this point it seems like you just want to sow confusion. If I had misinterpreted your words in some way, you could have clarified the misunderstanding like 10 times…

"once counterparties have authenticated each other's messages" is the omission that changes the meaning of the quote.

> "once counterparties have authenticated each other's messages" is the omission that changes the meaning of the quote.

No, it doesn't. The dispute isn't about the need for counterparties to authenticate each other. Yes, we all agree that it's good if email receivers can validate the authenticity of the sender. That's not at dispute. The question is, is it good if third parties also have the ability to authenticate the sender of an email at a later point in time (using DKIM specifically). tptacek claimed that there is no legitimate need for such a thing, and I provided a counter-example to that.

Re: Ok Google: please publish your DKIM secret keys

#314

Earlier quoted context omitted.

But we already have functioning and effective police forces in the western world without having to give up our rights to privacy. Why would we want to give up more?

Some people want to be more private than current (for example, this discussion of email keys). As more things move online, it is worth thinking where the balance should be (we probably agree on that), I think the balance should be less privacy (I'm sure you don't agree with that, a full discussion on that won't fit well in a ycombinator thread).

You’re right on you final points. My two rebuttals for advocating for less privacy online is that being online naturally makes you less private, not more.

Previously if someone, government or otherwise, wanted to learn about you, they would need to physically follow you, tap your phones, intercept your post etc. Warrants for searches were built around this.

Online, you can dig into the private life of someone on the other side of the plant who you’ve never met. With the application of computers you can dig into the lives of hundreds of people you’ve never met. All without leaving the comfort of your desk.

The opportunity for fishing expedition is unprecedented at the moment, and it always easy to justify a fishing expedition if you pick a horrific enough crime (child pornography seems to be the favourite right now).

Finally privacy is the strongest bulwark we have against government overreach. That doesn’t mean some top down conspiracy of a totalitarian-elect government. It can be normal everyday government administrators who decide to step outside their bounds for personal reasons, or belief of moral superiority.

Simply put, there’s no better deterrent for bad behaviour than hard work. Privacy makes bad actors work hard for their lunch. It makes the good actors work hard as well, but the solution to that isn’t less privacy, it’s more funding and resources for good actors.

Re: Ok Google: please publish your DKIM secret keys

#315

Earlier quoted context omitted.

Why not just rotate them frequently? Like weekly? Or daily even? ProtonMail makes you setup 3 CNAMEs for DKIM just so they can frequently rotate without your intervention or disruption. Sendgrid uses 2 for the same thing.

What's stopping someone from recording each public key as it is entered into service and providing a DKIM authentication service with it? There are already such things for domain data.

Hi! Check out our Usenix 2021 paper on exactly this topic. The key insight is to release private keys over time:

http://www.mit.edu/~specter/blog/2020/dkim/

Re: Ok Google: please publish your DKIM secret keys

#316
post #18

So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. It seems to me that especially when an elected official has something they don't want others to know about that…

> So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. I don't think Matthew Green is arguing against transparency. What he's observing is that non-repudiation is a…

[deleted]

Re: Ok Google: please publish your DKIM secret keys

#317
post #282

Earlier quoted context omitted.

> once counterparties have authenticated each other's messages, the legitimate need for authentication is gone; allowing random strangers to authenticate messages concedes information to them. As you know, there are many legitimate needs to authenticate messages of strangers. For example, when you order products over the internet, an e-mail of your purchase is often the only proof of what was agreed in the purchase.…

Yeah the man-off-the-street expects that if you have an email in your inbox it's proof positive that it was received like that. They don't know that you can upload counterfeit emails using imap or anything like that. Introducing non-repudiation would violate everyone's expectations and create a total mess. I'm saying this as someone who often and deliberately uses deniable messengers.

> Yeah the man-off-the-street expects that if you have an email in your inbox it's proof positive that it was received like that. They don't know that you can upload counterfeit emails using imap or anything like that. Introducing non-repudiation would violate everyone's expectations and create a total mess.

If the "man-off-the-street" expects email to have non-repudiation property, then how exactly would "introducing non-repudiation" violate their expectations?

Re: Ok Google: please publish your DKIM secret keys

#318
I agree with the author but would Google have reasons to keep a copy of the private key? Is it possible that they have deliberately destroyed it?

P.S. This brought back memories. To anyone unaware of this, read about Pizzagate. You'll find that it has supposedly been debunked as a "conspiracy theory"... except for the emails which we know are legit.

Re: Ok Google: please publish your DKIM secret keys

#320
post #159

Earlier quoted context omitted.

It's easy to see why there are divided opinions on this. When someone sends an email, the recipient often wants to be able to prove that they did so. We think of email as something capable of leaving a paper trail, proof that certain people sent certain emails. It's reasonable for secure messaging to want to fill a different niche, more like private conversation. I've seen messaging apps advertised on the basis that…

I appreciate the re-framing of this comment and its parent. Personally I found the original article's argument to feel more like "people shouldn't be accountable for their correspondence" than "the default mode of email should be more of private secure messaging". Both are advocating for the same changes but only one seems reasonable to me. That may just be my flawed reading of the blog post, but regardless, I can be…

People shouldn't be accountable for their correspondence! That's the whole point of secure messaging!
Post reply on HN