Earlier quoted context omitted.
The article did not become propaganda.
The article up to that point was great. However, that sentence "But the government of Iran probably could" made the preceding paragraphs appear to be a vehicle to deliver a meme (like a shaggy-dog story). The rest of the article could have been great, I just stopped reading. The journalist could have made a neutral statement about what entities have the resources to crack a 768-bit key. But they or their editor chose…
How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
41–50 of 107 posts
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#42Earlier quoted context omitted.
Or paranoid. Or naive. Or narcissistic. It might be somewhat feasible if they wanted him to be security engineer, not a devop. Still, he expected they have set up what essentially is an elaborate prank just to send a cold-call email to just one of probably numerous potential candidates. How likely this is? What would be the risk-to-reward ratio for doing that, considering that many of unsolicited recruiting mails are…
Google has done this kind of stunt in the past. Remember {first 10-digit prime found in consecutive digits of e}.com?
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#43Earlier quoted context omitted.
Are you saying that 1) anti-spam is not about about security and that 2) DKIM, even if properly implemented, doesn't make spoofing harder and security better?
I'm saying that DKIM is an anti-spam mechanism, and that there are real ways to authenticate the actual sender of a message, like PGP or S/MIME. Calling a cracked DKIM key a "massive Internet security hole" is like calling a bug in SpamAssassin a "massive Internet security hole".
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#44Earlier quoted context omitted.
Nit-picky corrections: 1. Top Putnam score in Colorado . There's a pretty big difference between that, and say, top Putnam score in Massachusetts (which is more likely the same as top overall due to many Putnam Fellows coming from Harvard or MIT). 2. Elementary proficiency in Classical and Leventine Arabic, Mandarin Chinese, and Koine Greek
Wow, #1 sets off my tryhard alarm. Especially at the college level where a huge portion of high Putnam scorers migrate to locations like Cambridge and California. top 50 or even 200 overall or whatever is far more impressive than #1 in a state that has no reputation for high scores.
The rat race is not for everyone.
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#45Seriously old news... I attacked Facebook's 512 bit DKIM key back in 2010: http://blog.jgc.org/2010/06/facebooks-dkim-rsa-key-should-be...
So this is one key, used for all a domain's email for a long time, right? How lazy must you be to use an under specced key?
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#46Earlier quoted context omitted.
It authenticates the domain of the sender, right?
If you want to impute that much authority to it, sure, but the actual signature verification depends on the insecure DNS anyways. Do not make security decisions based on DKIM. It's an anti-spam mechanism and that's all.
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#47Earlier quoted context omitted.
The article up to that point was great. However, that sentence "But the government of Iran probably could" made the preceding paragraphs appear to be a vehicle to deliver a meme (like a shaggy-dog story). The rest of the article could have been great, I just stopped reading. The journalist could have made a neutral statement about what entities have the resources to crack a 768-bit key. But they or their editor chose…
I don't understand. That statement was part of a quote during the interview. A single, continuous quote. Do you consider reporting what someone said to be propaganda. Should the journalist have left out that part of the quote?
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#48>But the government of Iran probably could, or a large group with sufficient computing resources could pull it off. Yes, I can see it now: Iran endures crushing sanctions in order to pursue spam email program.
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#49Earlier quoted context omitted.
I'm saying that DKIM is an anti-spam mechanism, and that there are real ways to authenticate the actual sender of a message, like PGP or S/MIME. Calling a cracked DKIM key a "massive Internet security hole" is like calling a bug in SpamAssassin a "massive Internet security hole".
You didn't answer the questions. That's because you well know that anti-spam is security. Just because DKIM isn't foolproof, doesn't make it useless as a layer in anti-spam and security.
But I'm happy to continue backing up why this particular Wired headline is silly. DKIM is a cryptosystem backed by the insecure DNS. Mail has been spoofable since before RFC822. The whole idea behind phishing attacks is that you can't trust email. Nobody credible has ever suggested that DKIM resolves that problem; you will find no credible Internet security advice anywhere suggesting that a DKIM signature on a piece of email from Paypal or Chase means you should click on a link in that email and log into something.
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#50Earlier quoted context omitted.
If you want to impute that much authority to it, sure, but the actual signature verification depends on the insecure DNS anyways. Do not make security decisions based on DKIM. It's an anti-spam mechanism and that's all.
Curious - does DNSSEC add much to the amount of trust one can assign to DKIM verification? Or are there better solutions (both for trusted DNS and DKIM-alike)?
DNSSEC is a boondoggle, and so far as I know no popular application on the entire Internet relies on it for security. But we don't need to hash out DNSSEC vs. DNS to see why a cracked DKIM key isn't a major Internet security hole.