Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

481–490 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#481

Earlier quoted context omitted.

By making the DKIM keys public, you are converting solid evidence of something that was said into something that was either really said, or someone else pretended that they said. Evidence was destroyed.

No, destruction of evidence involves things like making something impossible to analyze and evaluate. Publication of a key doesn't erase the original messages and does not make it impossible to look into their contents to try to establish authencity by external means. Causing ambiguity is not destruction of evidence.

What do you call it when someone pees into someone else's pee sample?

Re: Ok Google: please publish your DKIM secret keys

#482
post #479

Earlier quoted context omitted.

Still ignorant and wrong tho...

That could certainly be. But why not use HN in the intended spirit? It would be better for everyone, you included.

I wouldn't want to be a part of anything that denied the truth in favor of civility.

Dang, I thought you would have understood that.

Re: Ok Google: please publish your DKIM secret keys

#483
post #479

Earlier quoted context omitted.

That could certainly be. But why not use HN in the intended spirit? It would be better for everyone, you included.

I wouldn't want to be a part of anything that denied the truth in favor of civility. Dang, I thought you would have understood that.

But there are many different ways to stick up for the truth, and some have positive side effects and some not—hammering people over the head, for example. The side effects are actually more important.

If you'd be willing to take a look at https://news.ycombinator.com/item?id=25130956, I'd be curious to hear your reaction.

Re: Ok Google: please publish your DKIM secret keys

#484
post #483

Earlier quoted context omitted.

I wouldn't want to be a part of anything that denied the truth in favor of civility. Dang, I thought you would have understood that.

But there are many different ways to stick up for the truth, and some have positive side effects and some not—hammering people over the head, for example. The side effects are actually more important. If you'd be willing to take a look at https://news.ycombinator.com/item?id=25130956 , I'd be curious to hear your reaction.

After 5 replies, there isn't much room for logic. Trolls gonna troll... you should consider that.

I can help. Fly out, I got a guest room. I guarantee you won't regret it.

Re: Ok Google: please publish your DKIM secret keys

#485

Earlier quoted context omitted.

And now we're talking ethics. On one hand we have the Utilitarianist view of security. If increased security results in "more good" than evil, it is inherently ethical and thus acceptable. In this view, the idea that a good person may be blackmailed is perfectly acceptable, as long as it exposes political malfeasance. On the other hand there's the Kantian view. If you have to lie, it it hurts someone, or it wouldn't…

I honestly don't care about this Sophomore Dorm Room stuff, as long as we can all at least acknowledge the role of deniability in messaging security. If you want to argue that email isn't messaging, that's fine, I disagree, but at least you'll be vindicating my "never use encrypted email" argument.

I was more pointing out that the choice of how to move forward isn't simple, and that the premise is probably flawed due to bad design, but that we probably won't fix the design because it works.

Re: Ok Google: please publish your DKIM secret keys

#486

Earlier quoted context omitted.

> Additionally you’re also ignoring the whole “people have the right, to not have their emails stolen” argument No, just the opposite, that is an excellent argument and I think that the privacy should be the real focus when we discuss the freedom, and not the accountability. Because freedom is not to be able to get away for the lack of evidence, freedom is not to put innocent people in that kind of situation in the f…

LOL! You believe in justice. Learn how the real world works, muggle.

Ok, that's enough and I think we have to ban you again. Pity.

https://news.ycombinator.com/newsguidelines.html

Re: Ok Google: please publish your DKIM secret keys

#487
post #479

Earlier quoted context omitted.

Still ignorant and wrong tho...

That could certainly be. But why not use HN in the intended spirit? It would be better for everyone, you included.

>even when the other person is ignorant or wrong

>It's not a valid reason to break HN's rules.

>That could certainly be.

>But there are many different ways to stick up for the truth

Whoa. Dang, I have to say, I feel a little slighted. I'm neither ignorant, nor wrong, and I'm aghast that you would insinuate that.

I've contributed faithfully to this site for a decade. The other commenter has -15 karma because, as you noticed, his comments are largely childish, combative and unsubstantive. It's embarrassing that you are validating him.

His claim was that Google publishing DKIM keys as described in the article would be "destruction of evidence", but that's provably untrue since there would be neither intent or willfull neglect on anyones part.

Literally (yes, I mean literally) no-one else here on HN, or anywhere on the internet, has legitimately attempted to argue this. It just doesn't hold up to basic scrutiny. "Destruction of evidence" is a very specific legal term with very specific meaning [0][1][2]. He seems to be distorting it in a Guilianni-esque fashion - "It's fraud! ....But no, your honor, not in the legal sense. More like in my own made-up imaginary sense!".

I've been restrained and as courteous as possible (under the circumstances), but even after you tried to squash the thread, and I stopped commenting, he's continued to insult me. You seem to be tolerating it.

I would have appreciated it if you enforced sanctions against obviously bad actors and remained completely neutral. That is what you're known for, but I respectful think you've failed in this case. At any rate, I know you have just about the hardest job on the internet, so I'll go ahead and chalk this up to misunderstanding.

[0] https://definitions.uslegal.com/d/destruction-of-evidence/ [1] https://www.criminaldefenselawyer.com/crime-penalties/federa... [2] https://en.wikipedia.org/wiki/Spoliation_of_evidence

Re: Ok Google: please publish your DKIM secret keys

#488

Earlier quoted context omitted.

No, destruction of evidence involves things like making something impossible to analyze and evaluate. Publication of a key doesn't erase the original messages and does not make it impossible to look into their contents to try to establish authencity by external means. Causing ambiguity is not destruction of evidence.

What do you call it when someone pees into someone else's pee sample?

That would be an act of submitting false evidence, where you actively make a false claim regarding who the sample belongs to.

Which is very distinctly different from a passive act of not maintaining evidence of the origin of every single thing. Keep in mind that no data is altered - the equivalent of all collected samples remaining intact.

It's still just as possible to collect email logs, their contents do not magically dissappear. They would have to be actively manipulated by the party which holds the copy that would be provided to the police (either reported to them or confiscated, etc). That same party could already decide to delete the emails or strip signatures and then alter them.

Re: Ok Google: please publish your DKIM secret keys

#489

Earlier quoted context omitted.

EDIT: Apologies probably wrong name of the phallacy, so I removed that. Regardless, the fact that deep-fakes exist has absolutely no impact on whether DKIM has problems or not.

FYI the word is spelled fallacy. I wouldn't have bothered with the correction were it not for the unfortunate similarity to a very different word.

Ugh, thanks. Sadly, I can't edit... I can only apologize.

Re: Ok Google: please publish your DKIM secret keys

#490
You ain't bright.

If you pee in a cup of someone else's pee, you destroyed evidence. That is what publishing DKIM keys would do. A flood of fake messages to taint and destroy the ability to validate the would-be truth.

I would have appreciated it if you didn't waste the last decade of your life counting internet points. [0]

[0] u dum

Post reply on HN