Earlier quoted context omitted.
> In which scenario Amazon would deny sending an email and you would be protected by DKIM? You want a specific scenario of a dispute between a vendor and a customer? Ok. Let's say I email Amazon's customer support to ask them if a specific order is going to incur customs fees, and the Amazon representative emails me back that the order is not going to incur customs fees. Then I make the order, and to my surprise, I d…
You can dispute that without DKIM. How many disputes like that have been resolved with DKIM?
Ok Google: please publish your DKIM secret keys
461–470 of 492 posts
Re: Ok Google: please publish your DKIM secret keys
#462Earlier quoted context omitted.
> "with DKIM" is the part of your argument you've failed to back up. Yes, you have a counter-example that requires authenticated emails. You don't have one that requires authenticating emails with DKIM. That's because we aren't discussing a proposal to switch from DKIM authentication to a different method of authentication. We're discussing a proposal to abandon the partial non-repudiation property that's accidentall…
I'd argue that we currently have that "nothing" and are just trying to be explicit about it.
If you want concrete examples of how the partial non-repudiation property provided by DKIM is not "nothing", you have to look no further than the examples provided in OP.
Re: Ok Google: please publish your DKIM secret keys
#463Earlier quoted context omitted.
> Nobody's talking about the world moving away from google. We're talking about the world simply not having non-repudiation built into email. A sender of an email doesn't owe you non-repudiation as a feature. Sorry if you think otherwise. Senders can add non-repudiation as a feature if they want to, which satisfies your purchase receipt scenario. Please explain to me how I can make Amazon (or any other webshop) add n…
You can't force their DKIM signatures to be good forever either. You're basing some sense of security on a cryptographic property that simply isn't true. Would the world be worse off if you couldn't rely on DKIM signatures indefinitely? I don't know, are we worse off? Because whether you accept it or not, that's the exact situation we're in now.
Re: Ok Google: please publish your DKIM secret keys
#464Earlier quoted context omitted.
You can dispute that without DKIM. How many disputes like that have been resolved with DKIM?
If you run a campaign to make email repudiable, and make sure people should know email is repudiable, then emails will no longer be convincing evidence.
Again: How many disputes like that have been resolved with DKIM?
Re: Ok Google: please publish your DKIM secret keys
#465Earlier quoted context omitted.
If you run a campaign to make email repudiable, and make sure people should know email is repudiable, then emails will no longer be convincing evidence.
You do realize that email is older than DKIM? And that commerce existed before emails? You don't need DKIM to solve the issues you've pointed out. Again: How many disputes like that have been resolved with DKIM?
The original email spec doesn't provide any security against forgeries. The "sent from" field in email is about as secure as the "sent from" field in physical letters. The only reason why laypersons consider email to be non-repudiable is because of additional protocols like SPF and DKIM that were implemented after the original spec. Without these protocols email would be considered repudiable, which OP considers to be a preferrable outcome.
> And that commerce existed before emails?
Yes, and? I'm not claiming that all commerce would come to a halt immediately if this campaign for email repudiability was successful. Of course commerce would continue to exist. But the world would be worse off, not better. There would be slightly more disputes, and dishonest parties would increase their chances of defrauding honest parties.
> You don't need DKIM to solve the issues you've pointed out.
Are you alluding to hypothetical alternative protocols for authenticating contracts? If you can make the world move off from email, that's great! Email is horrible! But if you can't make people move away from email, you won't make the world a better place by making email less secure.
> Again: How many disputes like that have been resolved with DKIM?
How many? As in, you expect me to have statistics on it? Are we pretending that when people resolve disputes, they mark their disputes in some kind of global database that we can query for statistics? You're not making any sense.
Re: Ok Google: please publish your DKIM secret keys
#466Earlier quoted context omitted.
You do realize that email is older than DKIM? And that commerce existed before emails? You don't need DKIM to solve the issues you've pointed out. Again: How many disputes like that have been resolved with DKIM?
> You do realize that email is older than DKIM? The original email spec doesn't provide any security against forgeries. The "sent from" field in email is about as secure as the "sent from" field in physical letters. The only reason why laypersons consider email to be non-repudiable is because of additional protocols like SPF and DKIM that were implemented after the original spec. Without these protocols email would b…
You really think that laypersons have any idea of what DKIM is?
> But the world would be worse off, not better.
That's the whole point of this discussion. You seem to be arguing that the world would be better with non-repudiable email. But then I ask how many disputes have been resolved with DKIM and you have no idea. So basically your argument has zero basis in reality.
You're asking for every email user to have non-repudiation enforced unwillingly to them in every email they send so that someone maybe someday may solve some imaginary dispute with Amazon by using DKIM.
Re: Ok Google: please publish your DKIM secret keys
#467Earlier quoted context omitted.
> You do realize that email is older than DKIM? The original email spec doesn't provide any security against forgeries. The "sent from" field in email is about as secure as the "sent from" field in physical letters. The only reason why laypersons consider email to be non-repudiable is because of additional protocols like SPF and DKIM that were implemented after the original spec. Without these protocols email would b…
> The only reason why laypersons consider email to be non-repudiable is because of additional protocols like SPF and DKIM that were implemented after the original spec You really think that laypersons have any idea of what DKIM is? > But the world would be worse off, not better. That's the whole point of this discussion. You seem to be arguing that the world would be better with non-repudiable email. But then I ask h…
The layperson doesn't have to understand the intricacies of email protocols, it's enough that they consider email to be non-repudiable. This is why a copy of an email typically suffices as "proof" of a contract. If you successfully run a campaign to make email repudiable, then laypersons will no longer consider email to be non-repudiable, and emails no longer suffice as "proof" of a contract. If you disagree with something I said here, can you specify which part it is exactly that you disagree with?
> You seem to be arguing that the world would be better with non-repudiable email.
Yes, the world is better off now, at a time when laypersons consider e-mail to be non-repudiable, compared to a hypothetical future where this is no longer the case.
> But then I ask how many disputes have been resolved with DKIM and you have no idea. So basically your argument has zero basis in reality.
So if I can't give the exact number of times that DKIM has helped in dispute resolution, then my argument "has zero basis in reality"? This doesn't make any sense. If I said that "the existence of courts prevents vigilantes", you could say the same thing: "well what's the exact number of times that the existence of courts has prevented vigilanteeism? ha! you don't know the exact number! your argument has zero basis in reality then." We could apply your logic to many other scenarios: what's the number of times that existence of guards has prevented prison breaks? What's the number of infections prevented by vaccines? We don't know the exact numbers for any of these things, and yet we can logicly deduce that courts prevent vigilantes, guards prevent prison breaks, vaccines prevent infections, and DKIM prevents breaking contracts.
> You're asking for every email user to have non-repudiation enforced unwillingly to them in every email they send so that someone maybe someday may solve some imaginary dispute with Amazon by using DKIM.
Laypersons already believe that emails have non-repudiation property. People are free to use secure messengers to communicate privately. When people choose to communicate with email, they are choosing non-repudiation over privacy. You are the one who is asking to change e-mail protocols so that they would work differently than people currently expect. I'm the one saying e-mail should work like people expect e-mail to work.
Re: Ok Google: please publish your DKIM secret keys
#468Earlier quoted context omitted.
> The only reason why laypersons consider email to be non-repudiable is because of additional protocols like SPF and DKIM that were implemented after the original spec You really think that laypersons have any idea of what DKIM is? > But the world would be worse off, not better. That's the whole point of this discussion. You seem to be arguing that the world would be better with non-repudiable email. But then I ask h…
> You really think that laypersons have any idea of what DKIM is? The layperson doesn't have to understand the intricacies of email protocols, it's enough that they consider email to be non-repudiable . This is why a copy of an email typically suffices as "proof" of a contract. If you successfully run a campaign to make email repudiable, then laypersons will no longer consider email to be non-repudiable, and emails n…
They consider it non-repudiable not because of DKIM, it's just a common misconception. People believed that before DKIM. They will still believe it if Google discloses its DKIM keys.
They totally should not believe it, though.
> So if I can't give the exact number of times that DKIM has helped in dispute resolution, then my argument "has zero basis in reality"?
Of course that's not what I meant, I don't care about exact numbers. Just give me some evidence that DKIM is relevant to solve disputes anywhere else other than in the minds of HN commenters. Otherwise your claim that the world is better off now with non-repudiable email has no basis in reality.
> they are choosing non-repudiation over privacy
They totally are not. They have no idea what are the properties of email. As an example, a non-tech friend of mine was once surprised that email does not provide any confidentiality.
Re: Ok Google: please publish your DKIM secret keys
#469Earlier quoted context omitted.
You said - > By making the DKIM keys public, you are converting solid evidence of something that was said into something that was either really said, or someone else pretended that they said. Evidence was destroyed. > Destroy: transitive verb: to put out of existence. As the other commenter stated, nothing was destroyed. Nothing. The plausibility of a certain piece of evidence was called into question, but that's not…
A victim used to be able to prove they didn't send a message. A leaker used to be able to prove someone did send a message. Those evidentiary options no longer exist. They were destroyed when the DKIM keys were made public. You're not very bright. Concede that.
Period.
End of discussion.
>You're not very bright. Concede that.
At least I understand that for a crime to be committed there has to be an entity (organization or person) who committed it. That only requires a grade school level of legal understanding. But given your insults, I'm beginning to understand that maybe that's just about the upper limit of your intellect.
Re: Ok Google: please publish your DKIM secret keys
#470Earlier quoted context omitted.
I'm from Serbia, so no, I'm not really privileged with any of that as we've got oppressive regime in power, inefficient police used to look the other way on crimes, and fairly close-minded and conservative society. Of course, there are places where it's far worse, but I had fairly enough of shit happen to me so far in life (break-up of the country, years of war, living under UN sanctions, hyperinflation, working for…
I can't follow your argument. Above, you said - > the solution is [...] to have police put their blackmailing asses in the jail. But now, you're saying you don't have meaningful access to law enforcement (in this context). So, why did you suggest a solution you know isn't viable? I don't get it. To my mind, you've just made a strong argument for publishing DKIM keys since you readily admit law enforcement cannot tack…
B) Even though it's not viable for me to do anything to someone in Russia or China or even US for leaking my data, I see that as the only proper way to address this type of situations. If it's not possible now, then we should concentrate on fixing it and making it possible, instead of trying to lessen the impact, but at the same time helping those same blackmailers to easier hide their own steps (and a bunch of other shady characters who'd rather not be linked to their emails, from pedophiles to corrupted politicians). And also I don't see denying as a reasonable move here, as it comes down to basically lying publicly about the origin of your data and can just get you deeper in the trouble, especially if you're in any sensitive position and there're people out there actively looking to dig your dirt. AFAIK all PR handbooks on damage control say the same.