Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

351–360 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#351

The problem with the author's paper is that his assumption (and that of, apparently, media organizations, Wikileaks, and others) of DKIM "ensuring non-repudiation of emails" is simply wrong. >DKIM provides a life-long guarantee of email authenticity that anyone can use to cryptographically verify the authenticity of stolen emails, even years after they were sent. No, it doesn't. It simply offers an assurance that, at…

Spot on! I use to work for a company that helped Yahoo on the RFC (We were in the email spam space). DKIM is not meant to prove the payload is authentic/un-tampered, merely the person sending the email was authorized to use the domains SMTP server in question. Thats it. DKIM is a one bit in preventing spam.

Lets just say it. The emails that sparked all this are looking for something that simply isnt there. They see what they need to see to fit a world view

Re: Ok Google: please publish your DKIM secret keys

#352

Earlier quoted context omitted.

> So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. I don't think Matthew Green is arguing against transparency. What he's observing is that non-repudiation is a…

I haven't the faintest why this conversation is only about politicians. I don't want a nation-state to be able to contrive fake historical signatures for my own emails .

A sufficiently powerful adversary will simply steal your emails. That's the actual real threat, not that the adversary will convincingly lie about you. That part they can already do without the benefit of your emails.

Re: Ok Google: please publish your DKIM secret keys

#353
post #82

I know threads change over time, and it's dangerous to write a comment in response to the perceived gestalt of an HN thread, but, I have to say, it's pretty wild reading a thread on this site arguing so strenuously against the premise of secure messaging. In messaging cryptography, non-repudiability has for almost 2 decades been considered a vulnerability, not a feature. The OTR protocol[1] takes the step of publishi…

And now we're talking ethics.

On one hand we have the Utilitarianist view of security. If increased security results in "more good" than evil, it is inherently ethical and thus acceptable. In this view, the idea that a good person may be blackmailed is perfectly acceptable, as long as it exposes political malfeasance.

On the other hand there's the Kantian view. If you have to lie, it it hurts someone, or it wouldn't work if it applied to everyone, then it's unethical. This doesn't seem to work at all, because we have to allow lying (non-repudiation). But non-repudiation could prevent someone from being hurt. And applying it to everyone would allow for the least harm, rather than the most good.

In the end Utilitarianism usually reigns because it's easier. But it does ignore the edge cases, which we should consider. Perhaps the way forward is not to pick one or the other, but actually re-make the world to embrace the good and avoid the bad. Sadly, that's probably the most difficult choice of all; when's the last time we replaced a working standard just because it had crappy outcomes?

Re: Ok Google: please publish your DKIM secret keys

#354
post #119

Earlier quoted context omitted.

-- Example -- Dear Ivanhoe, I regret to inform you that your HIV test came back positive. Please contact my office at your earliest convenience to arrange a follow up. Sincerely, Your doctor

No doctor should be writing that email in the first place; it would be an example of such a flagrantly negligent treatment of PHI that cryptographic signatures and reputability are kind of irrelevant.

Call me back when they ban faxes. Email with server verification is way more secure than that.

Re: Ok Google: please publish your DKIM secret keys

#355
post #159

Earlier quoted context omitted.

It's easy to see why there are divided opinions on this. When someone sends an email, the recipient often wants to be able to prove that they did so. We think of email as something capable of leaving a paper trail, proof that certain people sent certain emails. It's reasonable for secure messaging to want to fill a different niche, more like private conversation. I've seen messaging apps advertised on the basis that…

My problem isn't that people have divided opinions on this. My problem is that people who oppose it write as if they're just now discovering that the opposite opinion exists --- in one case on this thread, someone suggested that the only reason Matthew Green held this opinion at all was political. A serious argument against deniable messaging would start by acknowledging deniability as one of the shibboleths of the f…

Only because you circularly define experts in the field as those who agree with you.

Re: Ok Google: please publish your DKIM secret keys

#356

Earlier quoted context omitted.

You gave a example of a 'need' to do X that is specifically not legitimate. I'm not sure (and decline to speculate) whether you're confused or malicious or some other problem entirely, but you are wrong.

> You gave a example of a 'need' to do X that is specifically not legitimate. The example was that two parties are disputing a contract, the court is attempting to resolve the dispute, and the court has a need to authenticate the contract. Can you explain why you think that this is not a legitimate need to authenticate a document? > I'm not sure (and decline to speculate) whether you're confused or malicious or some…

> Can you explain why you think that this is not a legitimate need to authenticate a document?

Because it is not legitimate for a court to treat something that was not intentionally (ie, with something other than DKIM) signed as a signed contract. If one party did not sign that contract, a DKIM 'signature' doesn't change that. Conversely, if you have a argument that the document should be treated as a valid contract despite not having been signed, the lack of DKIM 'signature' is obviously irrelevant.

Re: Ok Google: please publish your DKIM secret keys

#357

Earlier quoted context omitted.

Sure. But what authenticates the contract? Do you sign and scan them?

PDFs with e-signatures are very common place now. Have you heard of DocuSign or other similar services?

And so it is the e-signature, not the DKIM that matters.

Re: Ok Google: please publish your DKIM secret keys

#358
post #355

Earlier quoted context omitted.

My problem isn't that people have divided opinions on this. My problem is that people who oppose it write as if they're just now discovering that the opposite opinion exists --- in one case on this thread, someone suggested that the only reason Matthew Green held this opinion at all was political. A serious argument against deniable messaging would start by acknowledging deniability as one of the shibboleths of the f…

Only because you circularly define experts in the field as those who agree with you.

Yeah that must be it. Sucks that I didn't cite sources.

Re: Ok Google: please publish your DKIM secret keys

#359
post #82

I know threads change over time, and it's dangerous to write a comment in response to the perceived gestalt of an HN thread, but, I have to say, it's pretty wild reading a thread on this site arguing so strenuously against the premise of secure messaging. In messaging cryptography, non-repudiability has for almost 2 decades been considered a vulnerability, not a feature. The OTR protocol[1] takes the step of publishi…

And now we're talking ethics. On one hand we have the Utilitarianist view of security. If increased security results in "more good" than evil, it is inherently ethical and thus acceptable. In this view, the idea that a good person may be blackmailed is perfectly acceptable, as long as it exposes political malfeasance. On the other hand there's the Kantian view. If you have to lie, it it hurts someone, or it wouldn't…

I honestly don't care about this Sophomore Dorm Room stuff, as long as we can all at least acknowledge the role of deniability in messaging security. If you want to argue that email isn't messaging, that's fine, I disagree, but at least you'll be vindicating my "never use encrypted email" argument.
Post reply on HN