Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

161–170 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#161

Earlier quoted context omitted.

> His point was that you pointed out a use case for some sort of cryptographic signing, not for (ab-) using DKIM for this purpose rather than what it was designed for. First, thank you for the clarification. Second, to answer tptacek's point, I understand that authenticating emails as a third party is an unintended side effect of the DKIM protocol. I understand that cryptographers would like people to move onto using…

It's just really clear that people in this thread are trying to approach this from first principles without any engagement in the field that they're discussing. That's a fun thing to do as, like, a game or a way to pass the time, and I guess that's what HN is, but it's still crazymaking, because essentially every paper written about messaging cryptography refutes this comment. Cryptographers would like to move people…

Ok, my GPG example was wrong. And yes, you got me, I'm not a professional cryptographer. But can you address the point? You said "once counterparties have authenticated each other's messages, the legitimate need for authentication is gone". I provided a counter-example to demonstrate that your statement was an exaggeration. You clearly dispute some part of this, but it's unclear to me what the disputed part is.

Edit: Hacker News doesn't allow me to post replies to the posts under this post, so I will answer by editing this comment. I'm addressing the following comment:

> Which counterexample is that exactly? Your counterexample involving a store is incorrect -- the store's email would still be authenticated for a smaller amount of time which would allow your server to verify that it is a valid email that came from the store's servers.

If you actually read my counter example, you will see that I wrote: "if a third party (like a court) can authenticate the message".

Yes, my email server can authenticate the email when it arrives, but that will be of little help later when I try to dispute claims in court. If the court can authenticate the email, that will be helpful to the honest party in the dispute.

Re: Ok Google: please publish your DKIM secret keys

#162
post #80
post #45

Meanwhile, the IETF is speccing more messaging protocols with non-repudiation and HN users seem to be cheering that shortcoming along: https://news.ycombinator.com/item?id=25100316 I think it's kind of unfortunate that there are many people that suddenly care when its powerful people or their families that are getting caught out by DKIM, these aren't the people who need protection from it the most. No one would even…

I think you are missing part of the irony here. A good number of those Hillary emails should have been on a government server in the first place, signed for entirety by the government for archival. Non-repudiation is an explicit design goal for the communication of public officials.

I think you're confused. Very few Clinton emails were ever leaked or released. The major leak people like to talk about was of John Podesta's emails. Podesta was a private employee of the Clinton campaign, he never worked at the state department. And of course being the campaign manager, having his email be provided by a government agency would have been a huge campaign finance violation to begin with.

Re: Ok Google: please publish your DKIM secret keys

#163

Wow. This blog post is appalling. I completely disagree with it. Consider this excerpt from the blog post: > But DKIM authenticity is great! Don’t we want to be able to authenticate politicians’ leaked emails? > Modern DKIM deployments are problematic because they incentivize a specific kind of crime: theft of private emails for use in public blackmail and extortion campaigns. An accident of the past few years is tha…

I'm not going to present a moral argument (what is a moral argument in this context?), only two direct rebuttals of your objections:

1. DKIM provides neither truthfulness nor objectivity. It's a signature mechanism used between mail servers to reduce spam. For implementation reasons, most DKIM users sign with RSA keys that are either currently crackable or will be crackable in a matter of years. Consequently, "signed" emails that are leaked years after their alleged transmission provide a false sense of non-repudiation.

2. Per 1, these emails are already impossible to authenticate after a period of time. This just makes the expectation more explicit. More generally, however, this just isn't a fruitful (or intended) application of DKIM: if the government wants to obtain evidence of a crime, they're going to subpoena the email provider and retrieve the originals. If the suspected criminal is sufficiently important, they'll use pointier methods. The outcomes of our criminal justice system intentionally doesn't hinge on the validity of a few DNS-published RSA keys.

Re: Ok Google: please publish your DKIM secret keys

#164

Wow. This blog post is appalling. I completely disagree with it. Consider this excerpt from the blog post: > But DKIM authenticity is great! Don’t we want to be able to authenticate politicians’ leaked emails? > Modern DKIM deployments are problematic because they incentivize a specific kind of crime: theft of private emails for use in public blackmail and extortion campaigns. An accident of the past few years is tha…

The word "appalling" describes something that creates surprising distress or dismay (itself implying surprise).

To be surprised at a cryptographer advocating for deniable messaging is to suggest that you're unacquainted with the field of messaging cryptography, in which deniable messaging has been a foundational goal for almost 2 decades, going back to Ian Goldberg and Nikita Borisov, who once yelled at me on Twitter for giving OTR short shrift and thus ensured I'd always associate his name with OTR and thus, I'm sure to his delight, his name being dropped on this thread.

I'd again like to point out how clear it is, the epistemic approach being taken in this thread. You can disagree with deniable messaging as a valid goal (it'd set you apart from cryptography engineers, but that's fine). But you can't be appalled by it in 2020, because the idea is old enough to drink in a bar in Canada, and motivated at least two of the most famous protocols in all of cryptography.

Instead, what people are doing here is skimming this post, digging no further, and then calling to mind their understanding of current events. Then, from that tiny thread of information and a bunch of axioms invented, I presume, in the span of just a minute or two, they're deriving an entire first-principles explanation of how messaging security is supposed to work.

You can do that, but I think it's more than fair to point out that there are people that have dedicated their entire career to studying this subject and publishing on it, and if commenters are going to make it clear that they haven't even tried to engage with that material, it's unclear why they should be taken seriously.

Also, Google should publish DKIM keys.

Re: Ok Google: please publish your DKIM secret keys

#165
post #102

Earlier quoted context omitted.

Okay, but what about a topic that is legal and acceptable in today's society but not in the society 20, 30 or 40 years down the line? What if being gay becomes socially unacceptable again? Or supporting the second amendment? Or [literally anything]? The problem is that what is socially and legally acceptable changes over time . Just 30 years ago, the standard for social acceptable commentary was wildly different in t…

Yes, you should absolutely think about everything that you commit to public record. Yes, you might be totally fine now. You might be hanging out and get photographed with this creepy billionaire named Jeffrey Epstein who is just another creepy billionaire at your creepy billionaire parties. Then 20 years from now we find out he's running pedophile island and people start looking into your associations. We are not tea…

Using the billionaire pedophile example is a disgusting trick. You're trying to set me up for appearing to support that.

Why not use more neutral examples? Like being gay or supporting certain political causes? What if those later become controversial or illegal? What then?

Do you want to live in a world where you have to guard everything you say in semi-private conversations, just in case it one day becomes controversial? That sounds like an oppressive nightmare.

The social media argument is tangential but I do agree with you there.

Re: Ok Google: please publish your DKIM secret keys

#166
post #25

I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?

> Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Exactly. If one enters into an contract using an e-mail, then DKIM can be used as a proof to the court of law that the contract was accepted by both sides.

Entering an contract via an email is a ridiculous idea from the start.

Re: Ok Google: please publish your DKIM secret keys

#167
post #142
post #25

I think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?

A counter to the non-repudiation of old emails is the fact that people who own their own mail servers can rotate their DKIM keys. So it's already possible for e.g politicians to have their email set up in such a way that they're insulated from leaks. The argument here is more that customers of gmail and other email services are not offered repudiation as a feature.

"Rotating keys" isn't the important part. "Publishing keys" is the important part. "Rotating keys" is an implementation requirement of "DKIM with repudiability via eventually-published keys."

Re: Ok Google: please publish your DKIM secret keys

#168

Earlier quoted context omitted.

> Exactly. If one enters into an contract using an e-mail, then DKIM can be used as a proof to the court of law that the contract was accepted by both sides. It would make a good TV drama plot, but courts don't work this way in real life. If that were the case, courts wouldn't be able to enforce contracts with wet signatures (which are straightforward to forge), or verbal contracts (which are valid contracts and regu…

> If that were the case, courts wouldn't be able to enforce contracts with wet signatures (which are straightforward to forge) I'm pretty confident that I could sign an email with a DKIM key if that were published, however, there's nothing that would give me the confidence that I could forge a pen signature in such a way that not even an expert could detect the forgery. > or verbal contracts (which are valid contract…

> the Uniform Commercial Code [...] requires that contracts for the sale of goods over $500 to be in writing

Yes, but not all contracts do that. For example, any contract for services is not covered by the UCC.

Re: Ok Google: please publish your DKIM secret keys

#170
post #82

I know threads change over time, and it's dangerous to write a comment in response to the perceived gestalt of an HN thread, but, I have to say, it's pretty wild reading a thread on this site arguing so strenuously against the premise of secure messaging. In messaging cryptography, non-repudiability has for almost 2 decades been considered a vulnerability, not a feature. The OTR protocol[1] takes the step of publishi…

The problem of deniability and "disavowing keys" is subjective and requires technical skill to understand, that average person will not find this "equalization of legit and forged data" intuitive and will believe that keys/signatures/encryption on content adds authenticity on equal level with "legit data" - instead of "repudiation" you have a 'weak proof of authenticity' that could be disproved later(the burden of proof shift here is important psychologically since keys/encryption are perceived as legitimizing content).
Post reply on HN