Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

361–370 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#361

Earlier quoted context omitted.

I appreciate the re-framing of this comment and its parent. Personally I found the original article's argument to feel more like "people shouldn't be accountable for their correspondence" than "the default mode of email should be more of private secure messaging". Both are advocating for the same changes but only one seems reasonable to me. That may just be my flawed reading of the blog post, but regardless, I can be…

People shouldn't be accountable for their correspondence! That's the whole point of secure messaging!

Speech has consequences. Given the good done in holding rogue "politicians" accountable, not seeing that as axiomatically desirable is at least a little bit suspicious...

Re: Ok Google: please publish your DKIM secret keys

#362
post #18

So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. It seems to me that especially when an elected official has something they don't want others to know about that…

> So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. I don't think Matthew Green is arguing against transparency. What he's observing is that non-repudiation is a…

> Do you really want someone in 2031 to be able to contrive fake signatures for the emails of politicians in 2021?

How could it be used for that purpose then if it’s proven to be unreliable?

It would seem that there’s more to gain in the short-term by those that have hacked Gmail accounts by exposing this, so it seems disingenuous, which you have to know, so it seems like people are fake-goading Google, causing others to actually goad Google, maybe to try to expose those that have hacked Gmail...

Pretty sneaky sis!

Re: Ok Google: please publish your DKIM secret keys

#363
post #361

Earlier quoted context omitted.

People shouldn't be accountable for their correspondence! That's the whole point of secure messaging!

Speech has consequences. Given the good done in holding rogue "politicians" accountable, not seeing that as axiomatically desirable is at least a little bit suspicious...

Let's see your mail spool. After all, how else can we know you're not having illicit conversations with politicians that we all deserve to know about?

Re: Ok Google: please publish your DKIM secret keys

#364
post #18

So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. It seems to me that especially when an elected official has something they don't want others to know about that…

Why is this argument not equivalent to the much-derided “nothing to hide” or “ban encryption by law” arguments? The way to have transparency into politician’s communications is to require them by law to be made public, and to use law enforcement to make sure that this actually happens. It seems that relying on information going over email (as opposed to eg signal), and getting hacked (perhaps you want it all hacked,…

I understand the sentiment

For local politics this would expose the haggling/threats/backdowns not good for image making very hard to make deals

For international, how do you expect this to work when a politician is getting briefing Or guidances or heads up about dealing with an dictatorship or a unfriendly global power or an foreign company ?

Perhaps have a classification system ? Then everything will be secret classification

Re: Ok Google: please publish your DKIM secret keys

#365
post #18

So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. It seems to me that especially when an elected official has something they don't want others to know about that…

Why is this argument not equivalent to the much-derided “nothing to hide” or “ban encryption by law” arguments? The way to have transparency into politician’s communications is to require them by law to be made public, and to use law enforcement to make sure that this actually happens. It seems that relying on information going over email (as opposed to eg signal), and getting hacked (perhaps you want it all hacked,…

That’s a false equivocation. Private citizens having “nothing to hide” in their personal lives is disimilar to public officials having nothing to hide in relation to their official duties. Blackmail related to embarrassing sexual proclivities or anything like that is unfortunate, but kindly asking politicians to be transparent isn’t a realistic answer. Of course they will use official channels and be transparent about everything they _should_ be doing, but it’s exactly the things they want hidden that will go over alternate channels.

What I think is most shocking in this age of political hacks and leaks is the fact that people are outraged by it when it’s their side. Sure, the timing can be unfortunate when it harms their chances of re-election, but I’m surprised that I hear more about that, and calling it election interference, than I do about the actual contents of the leaks. Don’t like it when your side’s dirty laundry hurts their campaign? Solution: nominate candidates with less dirty laundry.

Re: Ok Google: please publish your DKIM secret keys

#366

Earlier quoted context omitted.

Why is this argument not equivalent to the much-derided “nothing to hide” or “ban encryption by law” arguments? The way to have transparency into politician’s communications is to require them by law to be made public, and to use law enforcement to make sure that this actually happens. It seems that relying on information going over email (as opposed to eg signal), and getting hacked (perhaps you want it all hacked,…

That’s a false equivocation. Private citizens having “nothing to hide” in their personal lives is disimilar to public officials having nothing to hide in relation to their official duties. Blackmail related to embarrassing sexual proclivities or anything like that is unfortunate, but kindly asking politicians to be transparent isn’t a realistic answer. Of course they will use official channels and be transparent abou…

So your argument is that private citizens' desire for privacy is subordinate to your desire to be able to blackmail "public officials"?

Re: Ok Google: please publish your DKIM secret keys

#367
post #361

Earlier quoted context omitted.

Speech has consequences. Given the good done in holding rogue "politicians" accountable, not seeing that as axiomatically desirable is at least a little bit suspicious...

Let's see your mail spool. After all, how else can we know you're not having illicit conversations with politicians that we all deserve to know about?

Now you're just spouting non sequiturs. Publication and retention are two separate questions.

And not being a politician, and certainly not the one currently trying to hold the White House hostage, I don't see the public interest anyway.

Re: Ok Google: please publish your DKIM secret keys

#368
post #23

Earlier quoted context omitted.

The threat is not limited to politicians. Anyone (including you and your family members) could be blackmailed or otherwise publicly embarrassed.

> The threat is not limited to politicians. Anyone (including you and your family members) could be blackmailed or otherwise publicly embarrassed. ... for what they actually did. You think the solution is allowing people to be blackmailed or otherwise publicly embarrassed for things they didn't do, while removing their ability to verify that they didn't do them?

> for what they actually did

All blackmail involves things a person actually did... otherwise it would be libel or slander.

You seem to be arguing that blackmail shouldn't be illegal.

Re: Ok Google: please publish your DKIM secret keys

#369

Earlier quoted context omitted.

That’s a false equivocation. Private citizens having “nothing to hide” in their personal lives is disimilar to public officials having nothing to hide in relation to their official duties. Blackmail related to embarrassing sexual proclivities or anything like that is unfortunate, but kindly asking politicians to be transparent isn’t a realistic answer. Of course they will use official channels and be transparent abou…

So your argument is that private citizens' desire for privacy is subordinate to your desire to be able to blackmail "public officials"?

No. Private citizens are entitled to privacy and their rights to such should be guarded by both law and responsible security practices at the companies they entrust with their information. Private citizens shouldn’t be shielded from privacy violation by hiding behind the plausible deniability of no DKIM verification. The communications of public officials should be subject to traceability and authentication as having actually come from them, even if they have gone rogue and used non-government-approved communication channels. If corruption is suspected because communications are discovered on the receiving end, say at a company that gets audited or something, it should be simple for investigators to verify the authenticity of those emails. Establishing ownership of the sending email address is another issue, but I imagine that’s possible via regular investigative routes.

This has nothing to do with “blackmailing public officials” and for you to imply that I have such a desire is both uncivil of you to say here and says a lot about your world view. Blackmail is when you use evidence of illegal activity in order to coerce someone to do something against their will. Transparency and audit ability of our public servants is not blackmail.

Re: Ok Google: please publish your DKIM secret keys

#370

Earlier quoted context omitted.

That’s a false equivocation. Private citizens having “nothing to hide” in their personal lives is disimilar to public officials having nothing to hide in relation to their official duties. Blackmail related to embarrassing sexual proclivities or anything like that is unfortunate, but kindly asking politicians to be transparent isn’t a realistic answer. Of course they will use official channels and be transparent abou…

So your argument is that private citizens' desire for privacy is subordinate to your desire to be able to blackmail "public officials"?

You're advocating a standard that hurts innocent people in favor of the provably guilty.
Post reply on HN