Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

391–400 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#391
post #41

Earlier quoted context omitted.

> The threat is not limited to politicians. Anyone (including you and your family members) could be blackmailed or otherwise publicly embarrassed. ... for what they actually did. You think the solution is allowing people to be blackmailed or otherwise publicly embarrassed for things they didn't do, while removing their ability to verify that they didn't do them?

You're misunderstanding how this works. You can't be blackmailed by someone who has no plausible evidence.

I'm afraid there's also a misunderstanding how the real world works. Cryptographic and real-world plausibility are two entirely different things.

People get blackmailed, shamed, hurt and even killed over mere rumors, speculations and suspicions. As long as people believe in something (because something merely look plausible), there's no need for a fancy crypto to prove some machine sent some email. I'd dare to say most people don't even understand what cryptography is and what digital signatures really are (who signs what and what exactly this means).

I'm yet to hear a story of, let's say, a brave dissident who got out of jail because of cryptographic plausible deniability property making their oppressors unable to prove authenticity of some leaked or intercepted correspondence.

Re: Ok Google: please publish your DKIM secret keys

#392
post #55

Earlier quoted context omitted.

Among messaging cryptographers, it's not even an argument. Serious secure messengers have been designed to avoid non-repudiation since OTR. Non-repudiation is a vulnerability: once counterparties have authenticated each other's messages, the legitimate need for authentication is gone; allowing random strangers to authenticate messages concedes information to them. Here, have a link, from 2004: https://otr.cypherpunks…

Cryptographers don't have some sort of monopoly on what is right or what makes sense. Deniability is actually a good example of this. The idea of deniability as some sort of desirable feature in messaging came out of nowhere. It wasn't anything that anyone asked for or worried about before the OTR proposal suggested it. It is a cool idea but it has little practical value. That is particularly true when it depends on…

Translation: privacy is only good when it applies to speech I support.

Re: Ok Google: please publish your DKIM secret keys

#393

Earlier quoted context omitted.

Letters and emails are private. DKIM does not change that. This discussion about DKIM is about non-repudiation and the ability to prove that a certain person sent the email. If you send me a letter, I (or someone else who gains possession of that letter) should be able to prove that you sent the letter and hold you accountable for the contents. DKIM does that for emails.

If you want to transfer assurance of the authenticity of an email to someone else, you can do so without DKIM; just sign a timestamp or something. The problem with current DKIM configurations is that it provides that assurance to everybody , including strangers who have no business having it. Which is why the ask here is for Google to do with DKIM what OTR does with MAC keys: burn them periodically, so that only peop…

That seems less usable for the average email recipient. Most people who need to prove authenticity to a third party (eg of politically sensitive or offensive messages) aren't techies.

Too, it's easy to imagine not knowing you need proof until some time after you receive an email.

If it isn't usable and enabled by default, it won't be used in practice - for the same reason almost nobody uses PGP.

Re: Ok Google: please publish your DKIM secret keys

#394
post #18

So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. It seems to me that especially when an elected official has something they don't want others to know about that…

Checking the DKIM key doesn't prove anything with certainty - the keys could have been leaked or stolen, or the mail server hacked. Or, the operator of the mail server could even forge the message. Many possibilities.

The purpose of DKIM is to help prevent spam, not to verify the authenticity of the sender.

Re: Ok Google: please publish your DKIM secret keys

#395
post #386

Earlier quoted context omitted.

Private emails are not speech. Are you suggesting all private conversations should be public? That seems absurd to me. Do you subscribe to the "surveillance isn't bad if you have nothing to hide" concept?

Sending death threats or racial invectives by private message is as much speech as sending them by Twitter post. All private conversations shouldn't be published. That isn't necessary to hold people accountable for dangerous or violent speech. Publication and repudiation aren't the same thing.

There is no way to allow the verification of a death threat message without also allowing the verification of political dissidents, for example.

Yes, it might make it harder to punish death threats, but privacy is too important to sacrifice.

Re: Ok Google: please publish your DKIM secret keys

#396

Earlier quoted context omitted.

Do you trust all future governments? Germany 1933, Donald Trump today, far right extremism in Europe are all examples of how trustworthy governments become evil governments. Democracy doesn’t offer a defence against “evil” governments. Only that you need a majority (and frequently not even a majority) to vote for one.

I'm not clear what you are arguing for? Do you not want a functioning, effective police force now, in case they become evil in the future (or already are evil, depending on your point of view)? If a government turns full evil, they don't need evidence against you, they can just lock you up without charge.

I think it's perfectly reasonable to take a non-absolute position here. You can want a somewhat functioning, somewhat effective police force, but not one that is more functioning or effective than the one we have in reality; or, in fact, you can want one that is less functioning and effective than the one we have now, without being completely dysfunctional and ineffective.

(One could imagine a police force that is effective enough to stop murderers, but not effective enough to stop dissidents. Such a police force would be more useful for a society that wants no murder than for one that wants no dissent.)

Re: Ok Google: please publish your DKIM secret keys

#397
He should be complaining to the standards bodies. DKIM keys should expire like most other asymmetric cryptosystems. There will always need to be backward compatibility, but then it's your fault if you're using outdated software or not using a major mail provider (who would very certainly support the new standard). Directing this complaint to one company seems bizarre because most people who care about this kind of thing aren't using Gmail to begin with.

Re: Ok Google: please publish your DKIM secret keys

#398
Meta: HN should enforce post size minimums on contentious topics like this. Basically every long post is a sincere perspective from the author trying to convey their viewpoint, and 9/10 of the short posts is reddit/twitter level snark like "Translation: You're a dictator-wannabe"

Re: Ok Google: please publish your DKIM secret keys

#399
I understand that the arguments both for and against the current DKIM regime are fairly nontrivial (should we analyse it as a loss of rights to the public (your past emails can be attributed to you) or a gain (you can hold the powerful to account)?), but either way, it seems that the only position that is consistent with the author's would be one that is enthusiastically in favour of improvement and proliferation of DeepFake technology. After all, we already live in a world where technology has created a novel form of attribution that could be used for blackmail: slightly over 100 years ago, nobody could prove or disprove that you said or did something in the past, whereas nowadays a video (given some pixel-level forensics) works as irrevokable proof positive.

Re: Ok Google: please publish your DKIM secret keys

#400

The problem with the author's paper is that his assumption (and that of, apparently, media organizations, Wikileaks, and others) of DKIM "ensuring non-repudiation of emails" is simply wrong. >DKIM provides a life-long guarantee of email authenticity that anyone can use to cryptographically verify the authenticity of stolen emails, even years after they were sent. No, it doesn't. It simply offers an assurance that, at…

Your conceptions of what is good and bad are not everyone's. When a potentially important email dump is leaked individuals will use any reasonable means to gain information about it's authenticity. Knowing that DKIM headers are on those emails and that the service provider hasn't published those keys changes the question from: "Did you send this email" to "Was your email address compromised at this time?"

> “Was your email address compromised at this time?"

How would the accused sender be able to prove it was or was not? And is it his or her burden?

Yes, individuals will use any reasonable to prove its authenticity. My point is that DKIM is not a reasonable means.

Post reply on HN