Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

371–380 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#371

Earlier quoted context omitted.

I appreciate the re-framing of this comment and its parent. Personally I found the original article's argument to feel more like "people shouldn't be accountable for their correspondence" than "the default mode of email should be more of private secure messaging". Both are advocating for the same changes but only one seems reasonable to me. That may just be my flawed reading of the blog post, but regardless, I can be…

People shouldn't be accountable for their correspondence! That's the whole point of secure messaging!

[deleted]

Re: Ok Google: please publish your DKIM secret keys

#372

Earlier quoted context omitted.

Why is this argument not equivalent to the much-derided “nothing to hide” or “ban encryption by law” arguments? The way to have transparency into politician’s communications is to require them by law to be made public, and to use law enforcement to make sure that this actually happens. It seems that relying on information going over email (as opposed to eg signal), and getting hacked (perhaps you want it all hacked,…

That’s a false equivocation. Private citizens having “nothing to hide” in their personal lives is disimilar to public officials having nothing to hide in relation to their official duties. Blackmail related to embarrassing sexual proclivities or anything like that is unfortunate, but kindly asking politicians to be transparent isn’t a realistic answer. Of course they will use official channels and be transparent abou…

I think you're pointing out the problem already.

Email and associated protocols apply to everyone, public-individual or private. The same technology works whether you're a politician or an ex-girlfriend.

I also agree with your parent, if there is something we need politicians to do, it needs to be a law that makes explicit what the intended outcome is, rather than hold up an unintended consequence of a protocol feature as "good enough", especially when there's potential for collateral damage.

Re: Ok Google: please publish your DKIM secret keys

#373

Earlier quoted context omitted.

I appreciate the re-framing of this comment and its parent. Personally I found the original article's argument to feel more like "people shouldn't be accountable for their correspondence" than "the default mode of email should be more of private secure messaging". Both are advocating for the same changes but only one seems reasonable to me. That may just be my flawed reading of the blog post, but regardless, I can be…

People shouldn't be accountable for their correspondence! That's the whole point of secure messaging!

But emails are meant to be accountable. They are the digital equivalent to sending letters. They should leave paper trails. Just like you have written before, secure messaging should be left to secure messaging apps, not email.

Re: Ok Google: please publish your DKIM secret keys

#374
post #372

Earlier quoted context omitted.

That’s a false equivocation. Private citizens having “nothing to hide” in their personal lives is disimilar to public officials having nothing to hide in relation to their official duties. Blackmail related to embarrassing sexual proclivities or anything like that is unfortunate, but kindly asking politicians to be transparent isn’t a realistic answer. Of course they will use official channels and be transparent abou…

I think you're pointing out the problem already. Email and associated protocols apply to everyone, public-individual or private. The same technology works whether you're a politician or an ex-girlfriend. I also agree with your parent, if there is something we need politicians to do, it needs to be a law that makes explicit what the intended outcome is, rather than hold up an unintended consequence of a protocol featu…

[deleted]

Re: Ok Google: please publish your DKIM secret keys

#375
post #361

Earlier quoted context omitted.

People shouldn't be accountable for their correspondence! That's the whole point of secure messaging!

Speech has consequences. Given the good done in holding rogue "politicians" accountable, not seeing that as axiomatically desirable is at least a little bit suspicious...

Private emails are not speech. Are you suggesting all private conversations should be public? That seems absurd to me. Do you subscribe to the "surveillance isn't bad if you have nothing to hide" concept?

Re: Ok Google: please publish your DKIM secret keys

#376
I've responded to a subcomment below explaining why "emails from politicians must be leakable" is not a good argument against the author's case.

That said, I think this would be problematic on some levels not being considered. A good part of the world's email infrastructure is decentralized, and doesn't run on providers who update software well and often. If Google were to publish their keys after rotation, a new class of attacks could emerge where attackers could successfully forge authentic emails from Google that would look secure to an outdated provider. Nigerian prince 2.0 if you will.

Decentralization is one of email's biggest strengths. I agree with the premise here, but I don't think the solution is to publish keys. Perhaps moving to a protocol that explicitly provides non-repudiation while keeping backwards compatibility would work.

Re: Ok Google: please publish your DKIM secret keys

#377
post #367

Earlier quoted context omitted.

Let's see your mail spool. After all, how else can we know you're not having illicit conversations with politicians that we all deserve to know about?

Now you're just spouting non sequiturs. Publication and retention are two separate questions. And not being a politician, and certainly not the one currently trying to hold the White House hostage, I don't see the public interest anyway.

I am not following... we are talking about gmail and email in general, not specifically the White House.

If you think White House emails should be signed and archived indefinitely, that is one thing. That is not what we are talking about.

Re: Ok Google: please publish your DKIM secret keys

#378

Earlier quoted context omitted.

Sure. So why do we need DKIM to authenticate contracts?

Because, without DKIM, a dishonest party can repudiate the email. Just as a written contract is superior to an oral contract, a non repudiable written contract is superior to a repudiable written contract.

So maybe digitally sign the contracts instead of unwillingly sign every single email you send?

Re: Ok Google: please publish your DKIM secret keys

#379
post #55
post #25

I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?

Among messaging cryptographers, it's not even an argument. Serious secure messengers have been designed to avoid non-repudiation since OTR. Non-repudiation is a vulnerability: once counterparties have authenticated each other's messages, the legitimate need for authentication is gone; allowing random strangers to authenticate messages concedes information to them. Here, have a link, from 2004: https://otr.cypherpunks…

Email is not a "serious secure messenger." It is the equivalent of writing a letter and signing your name to it. Email is useful for when you want a paper trail. Otherwise, you would use a secure messenger instead.

Re: Ok Google: please publish your DKIM secret keys

#380

Earlier quoted context omitted.

People shouldn't be accountable for their correspondence! That's the whole point of secure messaging!

But emails are meant to be accountable. They are the digital equivalent to sending letters. They should leave paper trails. Just like you have written before, secure messaging should be left to secure messaging apps, not email.

Woh, the idea that private letters shouldn't be private is WAY far away from the privacy standards that have been around in liberal democracies for centuries.

Mail being secure from surveillance is a foundational freedom.

I have no idea where you are getting the idea that we all should have to answer for what we send in private correspondence.

Post reply on HN