Earlier quoted context omitted.
Receipts can be signed with gnupg, it actually provides non-repudiation guarantee you want, DKIM doesn't provide that, it's only for journalists.
> Receipts can be signed with... In the real world it doesn't matter which cryptographic protocols are theoretically available for use. What matters is which protocols everyone else is using. For example, in the case of receipts for purchases on the web, literally everyone is using email. You will not be able to get amazon to sign a receipt with gnupg. If you want to embark on a path of convincing the world to move a…
Ok Google: please publish your DKIM secret keys
321–330 of 492 posts
Re: Ok Google: please publish your DKIM secret keys
#322Earlier quoted context omitted.
(a) I wasn't aware of this. (b) Thanks for the link! (c) The IETF is such a shitshow for cryptography.
The IETF is an open organisation. Specs are written & ratified by the people who show up. And often that means folks from large companies. If you don’t like that status quo, get involved. They would love to have you @tptacek.
Re: Ok Google: please publish your DKIM secret keys
#323Earlier quoted context omitted.
Current events prove otherwise. See Hunter Biden.
I have not seen a single mention of DKIM w.r.t to Hunter Biden. Did you? Was any evidence presented? I couldn’t find any. I fail to see how admissibility or lack of it, in a court of law or of public opinion, has anything to do with DKIM+Hunter Biden. Can you elaborate?
I am not sure why the DKIM for all emails were not released, or why this did not catch more media coverage by other news organizations I consider more reliable (like NYT).
Re: Ok Google: please publish your DKIM secret keys
#324So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. It seems to me that especially when an elected official has something they don't want others to know about that…
In fact, it does not authenticate any emails without a corresponding public key currently published to DNS. It provides specifically for "empty" or revoked keys to avoid such retro-validation.
Seems the central thesis is that because these messages are patently no longer authenticated by DKIM, we should eliminate any remaining hope of them being construed as authenticated by DKIM.
Re: Ok Google: please publish your DKIM secret keys
#325Earlier quoted context omitted.
Nobody is telling you to not be gay. If you being gay is a secret, then don't send that secret over _plain fucking text email_. Do you send your social security number to people in emails? Email has never been privileged communication and the problem isn't one of validation but one of not understanding one's level of privacy and risk. It uses relays without end-to-end encryption and there's no guarantee that what you…
If a global infrastructure provider can, without downside, offer non-repudiability – why shouldn't they? Not everyone is tech savvy. Not everyone understands encryption. Not everyone makes rational choices all the time. Does that mean everybody should suffer the consequences of an arguably unintentional side effect of the technical implementation of DKIM?
> Does that mean everybody should suffer the consequences of an arguably unintentional side effect of the technical implementation of law?
Thankfully this is not law, but people should understand the things that can get them in serious trouble. A lot of legal concepts follow from basic principles and history.
Privacy concepts are the same way. It's simply not sufficient that we don't educate everyone about these things anymore. Ignorance isn't going to protect anyone from the fallout of misuse of technology.
The solution isn't to coddle people, it's to provide better technology that does the thing the way people intend to use it.
Re: Ok Google: please publish your DKIM secret keys
#326Earlier quoted context omitted.
I have not seen a single mention of DKIM w.r.t to Hunter Biden. Did you? Was any evidence presented? I couldn’t find any. I fail to see how admissibility or lack of it, in a court of law or of public opinion, has anything to do with DKIM+Hunter Biden. Can you elaborate?
I saw this news ( https://www.washingtonexaminer.com/news/cybersecurity-expert... ) a few days before the election. There is also a github repo. I am not sure why the DKIM for all emails were not released, or why this did not catch more media coverage by other news organizations I consider more reliable (like NYT).
From your link:
> The only way the email could have been faked is if someone hacked into Google's servers, found the private key, and used it to reverse engineer the email's DKIM signature, Graham, said.
https://www.zdnet.com/article/google-fixes-major-gmail-bug-s... is from Aug 2020 and discusses an SPF/DMARC vulnerability that was in Google since forever (and though reported 4 months before public disclosure, was fixed only 7 hours after public disclosure). The last google DKIM bug I'm aware of was in 2012, so I can't counter the specific claim about DKIM with evidence, but the assertion that "the only way to spoof x is to hack and get the private key" is not any absolute truth.
(P.S: I have seen no denial nor confirmation about the authenticity of the Hunter Biden data - only claims of Russian involvement. Make of that what you will. The DKIM is circumstantial data until there is confirmation or denial - especially, as you say, it's not all released).
Re: Ok Google: please publish your DKIM secret keys
#327I doubt Google will publish old private keys that were not designed to become public later. I would guess that it's too dangerous or cumbersome to do the security analysis. What if someone realizes that Google uses a broken cryptographically secure pseudorandom number generator (CSPRNG) à la Debian ? Unlikely but the risks exists, so not going to happen in my opinion.
1. Someone with bad intentions figuring that out could start spamming other domains using gmail.com From Addresses.
2. Someone with good intentions would contact google security for a bug bounty or maybe just publish a zero-day report. Google would correct the issue and the world would be a slightly more secure place.
#2 would almost certainly happen, I suspect. And if #1 happened _before_ #2 then there'd be more spam in the world, temporarily.
To me the risk seems low.
Re: Ok Google: please publish your DKIM secret keys
#328Earlier quoted context omitted.
I don't think it's a fascination, it's what the OP is about. We're talking about the subject of a blog post, no? I think the point boils down to expectation management: journalists (and ...) barely understand non-repudiation, much less why each of the following scenarios pans out: * 2006 email + 512-bit RSA, leaked in 2006: probably authentic * 2008 email + 512-bit RSA, leaked in 2012: potentially inauthentic * 2008…
The right solution in this case is to educate journalists - they are up to date on things like deep fakes and should be on DKIM. The wrong solution is to make previously private keys public to make any reasoning about past data impossible in the name of “hut journalists might get a wrong impression”
Re: Ok Google: please publish your DKIM secret keys
#329Earlier quoted context omitted.
I saw this news ( https://www.washingtonexaminer.com/news/cybersecurity-expert... ) a few days before the election. There is also a github repo. I am not sure why the DKIM for all emails were not released, or why this did not catch more media coverage by other news organizations I consider more reliable (like NYT).
Thank you for this link, this did not come across my radar. From your link: > The only way the email could have been faked is if someone hacked into Google's servers, found the private key, and used it to reverse engineer the email's DKIM signature, Graham, said. https://www.zdnet.com/article/google-fixes-major-gmail-bug-s... is from Aug 2020 and discusses an SPF/DMARC vulnerability that was in Google since forever (…
I am not insinuating any wrongdoing from anyone, just bringing it to your attention, as you claimed to not know about it.
Re: Ok Google: please publish your DKIM secret keys
#330Earlier quoted context omitted.
The right solution in this case is to educate journalists - they are up to date on things like deep fakes and should be on DKIM. The wrong solution is to make previously private keys public to make any reasoning about past data impossible in the name of “hut journalists might get a wrong impression”
The OP is looking for a systemic solution to the problem, somewhat akin to the way establishing a bug bounty program aligns incentives. Your solution is like asking your team to please work harder to not release exploitable bugs.