Live data from Hacker News

How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

wired.com

41–50 of 107 posts

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#41
post #21
post #17

Earlier quoted context omitted.

The article did not become propaganda.

The article up to that point was great. However, that sentence "But the government of Iran probably could" made the preceding paragraphs appear to be a vehicle to deliver a meme (like a shaggy-dog story). The rest of the article could have been great, I just stopped reading. The journalist could have made a neutral statement about what entities have the resources to crack a 768-bit key. But they or their editor chose…

I don't understand. That statement was part of a quote during the interview. A single, continuous quote. Do you consider reporting what someone said to be propaganda. Should the journalist have left out that part of the quote?

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#42
post #20
post #13

Earlier quoted context omitted.

Or paranoid. Or naive. Or narcissistic. It might be somewhat feasible if they wanted him to be security engineer, not a devop. Still, he expected they have set up what essentially is an elaborate prank just to send a cold-call email to just one of probably numerous potential candidates. How likely this is? What would be the risk-to-reward ratio for doing that, considering that many of unsolicited recruiting mails are…

Google has done this kind of stunt in the past. Remember {first 10-digit prime found in consecutive digits of e}.com?

Sure, but that's not exactly subtle.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#43
post #35
post #32

Earlier quoted context omitted.

Are you saying that 1) anti-spam is not about about security and that 2) DKIM, even if properly implemented, doesn't make spoofing harder and security better?

I'm saying that DKIM is an anti-spam mechanism, and that there are real ways to authenticate the actual sender of a message, like PGP or S/MIME. Calling a cracked DKIM key a "massive Internet security hole" is like calling a bug in SpamAssassin a "massive Internet security hole".

You didn't answer the questions. That's because you well know that anti-spam is security. Just because DKIM isn't foolproof, doesn't make it useless as a layer in anti-spam and security.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#44
post #30
post #22

Earlier quoted context omitted.

Nit-picky corrections: 1. Top Putnam score in Colorado . There's a pretty big difference between that, and say, top Putnam score in Massachusetts (which is more likely the same as top overall due to many Putnam Fellows coming from Harvard or MIT). 2. Elementary proficiency in Classical and Leventine Arabic, Mandarin Chinese, and Koine Greek

Wow, #1 sets off my tryhard alarm. Especially at the college level where a huge portion of high Putnam scorers migrate to locations like Cambridge and California. top 50 or even 200 overall or whatever is far more impressive than #1 in a state that has no reputation for high scores.

Maybe he loves the place he lives in, he's quite happy doing the kind of work he does, and thus want to stay instead of moving to another place.

The rat race is not for everyone.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#45
post #37

Seriously old news... I attacked Facebook's 512 bit DKIM key back in 2010: http://blog.jgc.org/2010/06/facebooks-dkim-rsa-key-should-be...

So this is one key, used for all a domain's email for a long time, right? How lazy must you be to use an under specced key?

Plenty of crappy DNS web admin "tools" limit the maximum length of a TXT record. Sometimes it's harder than just typing "1024" instead of "512"...

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#46
post #28

Earlier quoted context omitted.

It authenticates the domain of the sender, right?

If you want to impute that much authority to it, sure, but the actual signature verification depends on the insecure DNS anyways. Do not make security decisions based on DKIM. It's an anti-spam mechanism and that's all.

Curious - does DNSSEC add much to the amount of trust one can assign to DKIM verification? Or are there better solutions (both for trusted DNS and DKIM-alike)?

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#47
post #21

Earlier quoted context omitted.

The article up to that point was great. However, that sentence "But the government of Iran probably could" made the preceding paragraphs appear to be a vehicle to deliver a meme (like a shaggy-dog story). The rest of the article could have been great, I just stopped reading. The journalist could have made a neutral statement about what entities have the resources to crack a 768-bit key. But they or their editor chose…

I don't understand. That statement was part of a quote during the interview. A single, continuous quote. Do you consider reporting what someone said to be propaganda. Should the journalist have left out that part of the quote?

Good observation. I stand corrected. I wonder how Zachary Harris would defend the lack of neutrality of that quote, if he was asked to do so.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#48
post #4

>But the government of Iran probably could, or a large group with sufficient computing resources could pull it off. Yes, I can see it now: Iran endures crushing sanctions in order to pursue spam email program.

SPAM is not the only attack that can be carried out with this kind of exploit.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#49
post #43
post #35

Earlier quoted context omitted.

I'm saying that DKIM is an anti-spam mechanism, and that there are real ways to authenticate the actual sender of a message, like PGP or S/MIME. Calling a cracked DKIM key a "massive Internet security hole" is like calling a bug in SpamAssassin a "massive Internet security hole".

You didn't answer the questions. That's because you well know that anti-spam is security. Just because DKIM isn't foolproof, doesn't make it useless as a layer in anti-spam and security.

You asked a question that had nothing to do with my comment, so I've declined to engage with you on that point. I'm not interested in litigating whether DKIM is "useless" or not.

But I'm happy to continue backing up why this particular Wired headline is silly. DKIM is a cryptosystem backed by the insecure DNS. Mail has been spoofable since before RFC822. The whole idea behind phishing attacks is that you can't trust email. Nobody credible has ever suggested that DKIM resolves that problem; you will find no credible Internet security advice anywhere suggesting that a DKIM signature on a piece of email from Paypal or Chase means you should click on a link in that email and log into something.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#50
post #46
post #28

Earlier quoted context omitted.

If you want to impute that much authority to it, sure, but the actual signature verification depends on the insecure DNS anyways. Do not make security decisions based on DKIM. It's an anti-spam mechanism and that's all.

Curious - does DNSSEC add much to the amount of trust one can assign to DKIM verification? Or are there better solutions (both for trusted DNS and DKIM-alike)?

The limitations of DKIM are bigger than the fact that it relies on DNS. The bigger challenge is that domain names are not a particularly valuable trust boundary. Applications on the Internet are full of bugs that allow attackers to source messages from other domains.

DNSSEC is a boondoggle, and so far as I know no popular application on the entire Internet relies on it for security. But we don't need to hash out DNSSEC vs. DNS to see why a cracked DKIM key isn't a major Internet security hole.

Post reply on HN