Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

401–410 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#401
post #82

I know threads change over time, and it's dangerous to write a comment in response to the perceived gestalt of an HN thread, but, I have to say, it's pretty wild reading a thread on this site arguing so strenuously against the premise of secure messaging. In messaging cryptography, non-repudiability has for almost 2 decades been considered a vulnerability, not a feature. The OTR protocol[1] takes the step of publishi…

I agree completely.

Non-repudiation is of course a needed property for many systems, but it is not a property a system, especially an everyday messaging system like email, should have by accident - even "weak" non-repudiation such as DKIM. It is a violation of privacy. The suggestion the author makes of course doesn't completely get rid of it, but at least makes it time-limited.

Re: Ok Google: please publish your DKIM secret keys

#402

Earlier quoted context omitted.

Woh, the idea that private letters shouldn't be private is WAY far away from the privacy standards that have been around in liberal democracies for centuries. Mail being secure from surveillance is a foundational freedom. I have no idea where you are getting the idea that we all should have to answer for what we send in private correspondence.

Letters and emails are private. DKIM does not change that. This discussion about DKIM is about non-repudiation and the ability to prove that a certain person sent the email. If you send me a letter, I (or someone else who gains possession of that letter) should be able to prove that you sent the letter and hold you accountable for the contents. DKIM does that for emails.

The author's suggestion, as I understood it, doesn't prevent this, it only prevents them from doing it beyond a certain point in the future.

If you got an email that warrants "holding someone accountable", you would have plenty of time before the keys are released. So if you receive an email and call the police, nothing would change.

What you couldn't do it save it for years and keep it as blackmail material / until it's politically opportune to use. Of course it's not as clear cut as that, and an email may look harmless at the time, and only later, with more context, you might realize it contains evidence of misdeeds. So even a good faith actor might unknowingly sit on evidence.

Re: Ok Google: please publish your DKIM secret keys

#403
What motivation would Google have to pay any attention to this request?

The only one I can imagine is that Google wants to get some positive PR out of it. Other than that it seems to me like Google will just ignore this as they ignore anything else they don't see as in their benefit to exert effort on.

Re: Ok Google: please publish your DKIM secret keys

#404

Earlier quoted context omitted.

Why is this argument not equivalent to the much-derided “nothing to hide” or “ban encryption by law” arguments? The way to have transparency into politician’s communications is to require them by law to be made public, and to use law enforcement to make sure that this actually happens. It seems that relying on information going over email (as opposed to eg signal), and getting hacked (perhaps you want it all hacked,…

That’s a false equivocation. Private citizens having “nothing to hide” in their personal lives is disimilar to public officials having nothing to hide in relation to their official duties. Blackmail related to embarrassing sexual proclivities or anything like that is unfortunate, but kindly asking politicians to be transparent isn’t a realistic answer. Of course they will use official channels and be transparent abou…

When John Podesta’s email was hacked, he was not a public official. He also was never up for election.

In fact, none of the examples in the article were from people up for election.

Re: Ok Google: please publish your DKIM secret keys

#405

The problem with the author's paper is that his assumption (and that of, apparently, media organizations, Wikileaks, and others) of DKIM "ensuring non-repudiation of emails" is simply wrong. >DKIM provides a life-long guarantee of email authenticity that anyone can use to cryptographically verify the authenticity of stolen emails, even years after they were sent. No, it doesn't. It simply offers an assurance that, at…

> It simply offers an assurance that, at around the time of sending, a given email was mostly likely sent from the server that signed it. It can't prove _anything_ about who actually sent it, because it can't guarantee the ownership of the email account.

Not on it's own, but it's a critical step in this chain:

1. DKIM verifies that a message was sent by Gmail.

2. We assume Gmail is careful with its keys.

3. We assume Gmail doesn't forge addresses.

4. Find evidence that links me to that address.

Most people will readily grant #2 and #3. Now we just need #4, which can be easy.

No, it's not cryptographically verified end-to-end, but it's good enough to convince a court or to convince a respectable news organization to run a story.

Re: Ok Google: please publish your DKIM secret keys

#406
> And it happened again this year, when the recipients of an alleged “Hunter Biden laptop” provided a single 2015 email to Rob Graham for DKIM verification

I contacted Bruce Schneier a few days back and he claimed that Robert Graham is lying and that this was fabricated, in addition that one is unable to establish the integrity and authenticity of a message by using DKIM.

I personally think that if Bruce Schneier is wrong and one is indeed able to establish the integrity and authenticity of a message by using DKIM then it is useful for the one receiving the message to prove to others that the mail indeed came the one who sent them the message. Consider a harassing email or a promise for example.

Re: Ok Google: please publish your DKIM secret keys

#407
post #18

So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. It seems to me that especially when an elected official has something they don't want others to know about that…

> So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available.

No matter what you think about politicians, it is a failure of cryptography, or perhaps our common application of it, that the signatures we use to assure our conversation partner of our identity can also be used for our conversation partner (or divers third parties) to prove what we said.

Compare https://en.wikipedia.org/wiki/Off-the-Record_Messaging which solved this problem quite a few years ago. Off-the-Record Messaging allows your conversation partner to know that they are talking to the real you, but does not empower them to prove that to anyone else.

Re: Ok Google: please publish your DKIM secret keys

#408
post #18

So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. It seems to me that especially when an elected official has something they don't want others to know about that…

> So the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. I don't think Matthew Green is arguing against transparency. What he's observing is that non-repudiation is a…

> By 2030, a motivated nation state will probably have the ability to crack the 2048-bit RSA keys that Google is currently using for DKIM. Do you really want someone in 2031 to be able to contrive fake signatures for the emails of politicians in 2021?

By this logic, what the article is arguing for is to bring that same truth today: if DKIM no longer offers the same guarantees, but people think that it does, than it can trivially be used to forge emails that people will then wrongly trust, which is obviously worse than the status quo.

Of course, the more likely result is what the article suggests - if the scheme can be defeated, people will stop trusting it, and there will be no chance of forgery (at least not for very much longer).

Re: Ok Google: please publish your DKIM secret keys

#409

Earlier quoted context omitted.

Your conceptions of what is good and bad are not everyone's. When a potentially important email dump is leaked individuals will use any reasonable means to gain information about it's authenticity. Knowing that DKIM headers are on those emails and that the service provider hasn't published those keys changes the question from: "Did you send this email" to "Was your email address compromised at this time?"

> “Was your email address compromised at this time?" How would the accused sender be able to prove it was or was not? And is it his or her burden? Yes, individuals will use any reasonable to prove its authenticity. My point is that DKIM is not a reasonable means.

For certain scandals just losing control of an email address is enough to cause serious concern.

Willfully admitting that control was lost could be a story in and of it's self.

Email is not a reasonable means to conduct business, qwerty is a terrible keyboard layout, different countries driving on different sides of the road seems like a really silly thing to do.

Just because something isn't reasonable doesn't really hold much sway when it comes to will people use it.

Re: Ok Google: please publish your DKIM secret keys

#410

Earlier quoted context omitted.

I think the entire point is that non-repudiation shouldn't just magically happen unless intended, so yes, this is by design, and anyone who wants to send a signed email should explicitly send a signed email.

> I think the entire point is that non-repudiation shouldn't just magically happen unless intended, so yes, this is by design, and anyone who wants to send a signed email should explicitly send a signed email. Let's not pretend that the world would move away from email if Google made this change. We both know that's not going to happen. Given that, can you explain why you think the world would be a better place when…

First, "innocent people can be framed" is not that simple.

Without non-repudiation, you don't automatically get to frame someone for whatever. You need to provide the usual (non-DKIM) evidence of whatever you're claiming.

And even with non-repudiation, you can still try and frame someone. Not having the DKIM signature might be suspicious in some circumstances, but it doesn't eliminate the possibility.

Second, "innocent" is not that simple.

I don't want my private communication to become public, or publicly verifiable. That doesn't mean I'm not "innocent". This is not a fringe concept: https://en.wikipedia.org/wiki/Nothing_to_hide_argument

"Give me six lines written by the most honest man in the world, and I will find enough in them to hang him." - Cardinal Richelieu

Post reply on HN