Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

331–340 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#331
post #176

Earlier quoted context omitted.

Current events prove otherwise. See Hunter Biden.

I have not seen a single mention of DKIM w.r.t to Hunter Biden. Did you? Was any evidence presented? I couldn’t find any. I fail to see how admissibility or lack of it, in a court of law or of public opinion, has anything to do with DKIM+Hunter Biden. Can you elaborate?

>I have not seen a single mention of DKIM w.r.t to Hunter Biden. Did you? Was any evidence presented? I couldn’t find any.

You really couldn't find any? Come on. Did you Google "DKIM Biden"?

Re: Ok Google: please publish your DKIM secret keys

#332
post #18

So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. It seems to me that especially when an elected official has something they don't want others to know about that…

Why is this argument not equivalent to the much-derided “nothing to hide” or “ban encryption by law” arguments?

The way to have transparency into politician’s communications is to require them by law to be made public, and to use law enforcement to make sure that this actually happens. It seems that relying on information going over email (as opposed to eg signal), and getting hacked (perhaps you want it all hacked, perhaps you are more happy while it is the side you don’t like getting hacked, either way I think one must acknowledge that by focusing on what is hacked, one is granting those hackers great control of the narrative) is not really very useful.

Re: Ok Google: please publish your DKIM secret keys

#333
post #226

Earlier quoted context omitted.

It doesn't at all. You're misunderstanding. Or, are you using the word "literally" in the modern sense of "not literally"?

Are you just nitpicking my choice of words or are you going to explain how auto-disappearing messages aren't potentially destroying evidence in the exact same way you've described? As for encrypted messaging, yes it is not the same as "literally" destroying evidence. But it is hiding evidence (based on your logic). The end result is the same in the context of the claims you previously made. That is: justice is potent…

No one is auto-disappearing messages. You are just not understanding.

Evidence that used to exist no longer exists as hard evidence. It isn't "hidden"... everything is still there. With secure DKIM justice can be served. With public after the fact DKIM, a shady lawyer claims the message could have been forged. Would-be hard evidence no longer exists as it can be painted as possibly forged.

Destroy: transitive verb: to put out of existence.

Are you just not learning what words mean?

Re: Ok Google: please publish your DKIM secret keys

#334

Earlier quoted context omitted.

Thank you for this link, this did not come across my radar. From your link: > The only way the email could have been faked is if someone hacked into Google's servers, found the private key, and used it to reverse engineer the email's DKIM signature, Graham, said. https://www.zdnet.com/article/google-fixes-major-gmail-bug-s... is from Aug 2020 and discusses an SPF/DMARC vulnerability that was in Google since forever (…

Sure, you raise very important points. I just found it weird that NYPost was happy just releasing the emails and not the DKIM, and when one was validated, it received literally no coverage. I thought it might catch steam after the election, but the literal silence is surprising to me. I am not insinuating any wrongdoing from anyone, just bringing it to your attention, as you claimed to not know about it.

Thank you. I indeed did not know about it. I do try to read all sides, but this did not come on my radar (Though I did not, before you posted this, google DKIM+Biden, I did read tens of articles about those emails mostly from republican leaning outlets, and it wasn't mentioned in any of those I read).

But it does support my thesis that DKIM or no DKIM is not what gives (or doesn't give) any credence to the authenticity (or lack of it) -- here we have a high profile case, with DKIM validation (which a lot of people on this thread cleim "is considered proof by people who don't understand it") and it seems to make no difference even in the court of public opinion - those who accepted it, accpeted it without DKIM, and those who rejected it as russian disinformation, rejected it even with DKIM.

Re: Ok Google: please publish your DKIM secret keys

#335

Earlier quoted context omitted.

Because the DKIM keys were not made public, and a message sent from their account could be confirmed to be authentic. If the keys were public, they could claim forgery. Regardless they could claim their account was hacked, but they couldn't deny the message was sent from their account.

I'm not asking how the technical mechanism proves the messages may be legitimate. I'm asking how you could use that knowledge in the specific situation you outlined to accomplish anything productive.

I'm not the person who said outting people as gay was productive. The other person claimed it could be destructive.

Re: Ok Google: please publish your DKIM secret keys

#336

Earlier quoted context omitted.

I don't think it's a fascination, it's what the OP is about. We're talking about the subject of a blog post, no? I think the point boils down to expectation management: journalists (and ...) barely understand non-repudiation, much less why each of the following scenarios pans out: * 2006 email + 512-bit RSA, leaked in 2006: probably authentic * 2008 email + 512-bit RSA, leaked in 2012: potentially inauthentic * 2008…

The right solution in this case is to educate journalists - they are up to date on things like deep fakes and should be on DKIM. The wrong solution is to make previously private keys public to make any reasoning about past data impossible in the name of “hut journalists might get a wrong impression”

That is... naive. The incentives for journalists don't necessarily align the the interests of the general public (transparency, thorough research, etc. etc.).

The point is that DKIM can be abused to lend undue credibility to falsified data... not that it can credibly attest true data.

These is absolutely no way you're going be able to educate the general public on the nuances of this. I mean, there are lots and lots of people who doubt the efficacy of vaccines and masks...

Re: Ok Google: please publish your DKIM secret keys

#337
post #331

Earlier quoted context omitted.

I have not seen a single mention of DKIM w.r.t to Hunter Biden. Did you? Was any evidence presented? I couldn’t find any. I fail to see how admissibility or lack of it, in a court of law or of public opinion, has anything to do with DKIM+Hunter Biden. Can you elaborate?

>I have not seen a single mention of DKIM w.r.t to Hunter Biden. Did you? Was any evidence presented? I couldn’t find any. You really couldn't find any? Come on. Did you Google "DKIM Biden"?

I just did, and I have less than 15 related results in the first 4 pages, only two of which are sources I've ever heard of before (washingtonexaminer and nypost). I'm logged out of google, but it's been a while since I deleted my cookies.

I've read literally hundreds of pieces on the hunter biden laptop, about half of them from republican leaning outlets, (I try to keep a balanced diet....) and none of them mentioned DKIM validation.

(For the record: I don't live in the US, I don't watch television, but I do try to keep a balanced news diet)

Re: Ok Google: please publish your DKIM secret keys

#338

Earlier quoted context omitted.

The right solution in this case is to educate journalists - they are up to date on things like deep fakes and should be on DKIM. The wrong solution is to make previously private keys public to make any reasoning about past data impossible in the name of “hut journalists might get a wrong impression”

That is... naive. The incentives for journalists don't necessarily align the the interests of the general public (transparency, thorough research, etc. etc.). The point is that DKIM can be abused to lend undue credibility to falsified data... not that it can credibly attest true data. These is absolutely no way you're going be able to educate the general public on the nuances of this. I mean, there are lots and lots…

> The point is that DKIM can be abused to lend undue credibility to falsified data... not that it can credibly attest true data.

So can deep fakes. What makes deep fakes explainable and DKIM unexplainable?

If the journalists interests do not align about DKIM, how come they align about deepfakes?

I'm not saying journalists have any integrity. I'm just wondering why specifically for DKIM a "throw the baby out with the bathwater" solution is advocated, whereas for things like deep fake it isn't -- where the underlying truth is the same: "You can't trust what you see/hear".

Re: Ok Google: please publish your DKIM secret keys

#339
post #282

Earlier quoted context omitted.

Yeah the man-off-the-street expects that if you have an email in your inbox it's proof positive that it was received like that. They don't know that you can upload counterfeit emails using imap or anything like that. Introducing non-repudiation would violate everyone's expectations and create a total mess. I'm saying this as someone who often and deliberately uses deniable messengers.

> Yeah the man-off-the-street expects that if you have an email in your inbox it's proof positive that it was received like that. They don't know that you can upload counterfeit emails using imap or anything like that. Introducing non-repudiation would violate everyone's expectations and create a total mess. If the "man-off-the-street" expects email to have non-repudiation property, then how exactly would "introducin…

My bad, meant to say introducing "repudiability".

Re: Ok Google: please publish your DKIM secret keys

#340

Earlier quoted context omitted.

The right solution in this case is to educate journalists - they are up to date on things like deep fakes and should be on DKIM. The wrong solution is to make previously private keys public to make any reasoning about past data impossible in the name of “hut journalists might get a wrong impression”

The OP is looking for a systemic solution to the problem, somewhat akin to the way establishing a bug bounty program aligns incentives. Your solution is like asking your team to please work harder to not release exploitable bugs.

What I don't understand is why it is clear to almost everyone but myself that DKIM-truth incentives are different than deepfake-truth incentives.

And yet, the deepfake equivalent to the suggested solution is one of "start showing deepfake as news" or "stop showing any video as news", neither of which anyone would consider a reasonable response to deepfakes. I just don't understand how DKIM is suddenly so revered as truth when almost no one knows what it is.

Post reply on HN