Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

341–350 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#341
post #18

So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. It seems to me that especially when an elected official has something they don't want others to know about that…

> So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. I don't think Matthew Green is arguing against transparency. What he's observing is that non-repudiation is a…

I haven't the faintest why this conversation is only about politicians.

I don't want a nation-state to be able to contrive fake historical signatures for my own emails.

Re: Ok Google: please publish your DKIM secret keys

#342
post #238

Earlier quoted context omitted.

>I'm illustrating the severity of the identifiable public record. This is an argument in favor of emails being non-verifiable, so now I'm confused. Previously you seem to be supporting the idea that email should be verifiable. Now you seem to be arguing the opposite. Everything you wrote above correlates with the opinions I've expressed so far. You also wrote: > If you live in a [country where homosexuality is illega…

Not at all. a) email being verifiable is fine b) nobody should be so stupid as to use email for anything personal. it is not privileged communication and potentially permanent public record. c) if you want to use email, you'd better encrypt it and only for recipients that you trust.

As you well know, people use email for things they shouldn't. Why not make email slightly better? What's the harm? Isn't greatly reducing the chance of blackmail unequivocally positive?

So far, you've just been repeating disparaging comments on less technically minded ("stupid") people. You've not presented an argument for why this change would be detrimental.

We can continue educating people about the inherit insecurity of email while still improving it for those that (a) will never get it and (b) simply don't have access to alternatives.

Re: Ok Google: please publish your DKIM secret keys

#343
post #311

Earlier quoted context omitted.

How exactly would you do this? > in an encrypted manner that has guarantees in place that only valid criminal investigations can decrypt What constitutes a valid criminal investigation, who decides? Do you, does a prosecutor, a judge, the police? Is it a valid to decrypt your data just see if you were at a specific location at a specific time? What about so the police can check a theory? How about to see if you joine…

>"What constitutes a valid criminal investigation, who decides? Do you, does a prosecutor, a judge, the police?" Some sort of formal process with reasonable oversight the necessity of multiple points of compromise and/or collusion in order for the data to be abused for non-governmental use. Bottom line, I can't say I've "solved" the problem and have the perfect answer to your question. But I'm sure we, collectively a…

Here is an example of how location data can be abused, accidentally or otherwise [0]. If you go down this road, then smart criminals will just take steps to avoid carry location tracking devices. What do you do then? Force everyone to carry and maintain a GPS tracker? Arrest them if they fail to charge it properly, because they could use that window to commit a crime without being tracked?

> We can't hide behind lack of capability to police said crimes, but still label them as such.

Most laws are written with the implicit assumption it’s not possible to perfectly enforce them. That provides some natural wriggle room to interpret the laws, avoids the need to write a long list of when it’s ok to speed for example.

Perfect enforcement breaks all of that. A knowledgable police officer could almost certainly stop you on any day the week and find you guilt of some obscure and ancient crime that’s no longer relevant.

> For all we know, if we lived in a society where we had such strict enforcement of laws as I suggest, we'd potentially have greater churn and change in our laws to match the opinions of society as it changed and evolved.

How do you imagine society would evolve its opinions and change them in a world of perfect enforcement? How the gay community show the world there nothing wrong with their way of life, if they simply couldn’t live it?

How would society change its views on smoking weed, if it was impossible to smoke it?

It’s impossible for a society to change its view on existing laws, if it’s completely unable to experiment with ignoring, or re-interpreting them.

It would be like expecting a child to ask for food they had never eaten, and never seen anyone else eat. How could they possibly know it existed, much less if it was good or bad for them?

> I disagree. I'm not seeing it. There is just way too much going wrong today in 1-st world countries whilst we have really good privacy for it to be the case. We're downright descending into totalitarianism and thought/opinion control territory, all whilst our "privacy" is mostly maintained and respected

Hahahaha, seriously. You complain of thought control, but advocate for world where the government can watch your every move, and perfectly enforce every law. Have you read 1984? I see little difference between world in that book, and the one your advocating for.

> Are you saying we need more of it? What would that look like to you?

Yes I am. How can you control someone’s though and opinions if you don’t know what they are? How can a totalitarian government rule with an iron fist if they don’t know where their citizens are, or what they’re doing?

Totalitarian governments come into existence because people want control and order, and they’re great if you fit into that governments view of what control and order look like. If you don’t, we’ll there are plenty of genocides that can be studied.

[0] https://www.google.com/amp/s/www.theverge.com/platform/amp/2...

Re: Ok Google: please publish your DKIM secret keys

#344
post #70
post #25

I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?

Please read the whole article before jumping into a conclusion about the author, Matthew Green. He sighted two examples where incorrect crypto science affected both a Democrat and a Republican. He is not trying to protect any particular side. He is simply articulating a method by which the key can be invalidated after its intended life time. If you have a technical argument, please explain that.

The timing is extremely suspect, and seems tailor written to protect a single political party.

Re: Ok Google: please publish your DKIM secret keys

#345
Am I the only one thinking that the issue comes from the fact that DKIM stuff is (I assume) inserted into the email's headers? DKIM is used for transfer of email, to make sure that the originating server is who it pretends to be. Shouldn't that be part of an envelope of the email, which would be discarded once the email has been received and its sending server verified and authenticated? Like for paper mail, one does _usually_ not keep the envelope (though I admit that there may be exceptional situations where it may be preferable to keep the envelope).

-- In the interest of users (will most probably never happen), all incoming emails should be ignored and dismissed unless the recipient has explicitly specified that it accepts email sent from a given email address. Wouldn't this give the power back to the users?

Re: Ok Google: please publish your DKIM secret keys

#346
post #119

Earlier quoted context omitted.

-- Example -- Dear Ivanhoe, I regret to inform you that your HIV test came back positive. Please contact my office at your earliest convenience to arrange a follow up. Sincerely, Your doctor

Or it could be: "Hey Ivanhoe, your buddy from government here. That thing that we discussed, no problem I arranged everything, T says it's cool, just wire us the money and the project is yours." In my view, if someone is going to blackmail me for some sensitive topic like being HIV positive or dox me in revenge, solution is not that I have to go public and lie that it's not real (and risk to be counter-proven it is)…

>to have police put their blackmailing asses in the jail.

Email is global. You and I are in privileged positions regarding access to capable law enforcement. We're also privileged with what our societies deems acceptable. We are the exception, not the rule.

If you're only thinking about how it affects you and what remedies you would have, then you clearly aren't looking at the big picture.

Re: Ok Google: please publish your DKIM secret keys

#347
post #342

Earlier quoted context omitted.

Not at all. a) email being verifiable is fine b) nobody should be so stupid as to use email for anything personal. it is not privileged communication and potentially permanent public record. c) if you want to use email, you'd better encrypt it and only for recipients that you trust.

As you well know, people use email for things they shouldn't. Why not make email slightly better? What's the harm? Isn't greatly reducing the chance of blackmail unequivocally positive? So far, you've just been repeating disparaging comments on less technically minded ("stupid") people. You've not presented an argument for why this change would be detrimental . We can continue educating people about the inherit insec…

It isn't solving the right problem.

What we should be doing is making end-to-end encryption easier to use.

PGP & S/MIME failed at this completely.

Re: Ok Google: please publish your DKIM secret keys

#348

Earlier quoted context omitted.

Same in Sweden. "Are you okey with paying extra for X?" "Yes, please go ahead." And that's how a new contract gets signed! No need to fly someone 1500km just for that.

Sure. So why do we need DKIM to authenticate contracts?

Because, without DKIM, a dishonest party can repudiate the email. Just as a written contract is superior to an oral contract, a non repudiable written contract is superior to a repudiable written contract.

Re: Ok Google: please publish your DKIM secret keys

#349

Earlier quoted context omitted.

That is... naive. The incentives for journalists don't necessarily align the the interests of the general public (transparency, thorough research, etc. etc.). The point is that DKIM can be abused to lend undue credibility to falsified data... not that it can credibly attest true data. These is absolutely no way you're going be able to educate the general public on the nuances of this. I mean, there are lots and lots…

> The point is that DKIM can be abused to lend undue credibility to falsified data... not that it can credibly attest true data. So can deep fakes. What makes deep fakes explainable and DKIM unexplainable? If the journalists interests do not align about DKIM, how come they align about deepfakes? I'm not saying journalists have any integrity. I'm just wondering why specifically for DKIM a "throw the baby out with the…

EDIT: Apologies probably wrong name of the phallacy, so I removed that.

Regardless, the fact that deep-fakes exist has absolutely no impact on whether DKIM has problems or not.

Re: Ok Google: please publish your DKIM secret keys

#350

Earlier quoted context omitted.

> So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. I don't think Matthew Green is arguing against transparency. What he's observing is that non-repudiation is a…

I haven't the faintest why this conversation is only about politicians. I don't want a nation-state to be able to contrive fake historical signatures for my own emails .

[deleted]
Post reply on HN