Live data from Hacker News

Cracking a 512-bit DKIM key for less than $8 in the cloud

dmarcchecker.app

241–250 of 433 posts

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#241
post #3

Earlier quoted context omitted.

Yeah, so I guess there's no point in picking any of the low hanging fruit to make it more secure.

Email is actually quite secure, just in a different way that web. For instance, once you disregard so called transactional mail and spam, real email is almost all encrypted for all practical purposes. DKIM and DMARC also work quite well for spoofing protection, aside from the corner cases like the above. Average Software Engineers have an outdated idea of email, formed by 1990 era Internet.

I think your view of email is romanticized, or perhaps skewed because of your social circle. Email servers sometimes use TLS to talk with eachother, and emails are signed. But that's the extent of encryption when it comes to "real email". Email content is not encrypted in "almost all" of "real email" because almost nobody uses PGP.

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#242

Me writing over 14 years ago: https://blog.jgc.org/2010/06/facebooks-dkim-rsa-key-should-b... This was doable 14 years ago for 512-bit keys.

> "Keys of 512 bits have been shown to be practically breakable in 1999 when RSA-155 was factored by using several hundred computers and are now factored in a few weeks using common hardware." So we went to a few weeks to 8h in 14 years give or take

I'm pretty sure I can do it in two hours.

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#243
post #163
post #59

Earlier quoted context omitted.

You should read the blog post Prof. Green linked to. All of your questions are addressed there.

Yes, I've now read it and it answered those questions. But it also stumbled upon an easier possible solution without realizing it: if you wish to pretend you didn't send some emails, you can still claim that someone stole your password. Whether this claim will be believed or not, is independent of DKIM. Spoofing is a better excuse than a stolen password only in the case of a single email. If there's a conversation sp…

I used to spoof emails to my teachers in high school asking them to come to the principle's office asap, and email the principle from another random teacher at the same time for him to come to the class room, and that random teacher to expect the principal at a certain time. We'd be teacher free for quite awhile because the principal wasn't there, and our teacher was.

You don't need a conversation to cause havoc.

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#244

Earlier quoted context omitted.

It's roughly half as fast as 4096, which sounds bad until you realize that 3072 is already 20% as fast as 2048, 3% as fast as 1024, and 1% as fast as 512. In terms of performance tradeoff it's downright mild compared to the other steps up.

If I could waive a magic wand and get a 40-100% performance boost on a service by changing 3-4 characters (s/4096/3072/) why wouldn't I take it? (Assuming I need security go to beyond RSA 2028.)

Its not a 40-100% performance boost overall, its just during one specific step that is a very small part of the entire overall system.

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#245
post #129

Earlier quoted context omitted.

I forget where but someone proposed regularly rotating your DKIM key and publishing old keys for deniability. So you can still use strong keys and provide a level of deniability.

Doing this only provides deniability in public. If this was brought to a court there are enough server logs to build out if that DKIM record was valid along with a number of DNS history providers.

Right. There’s generally going to be other evidence. Rotating the DKIM isn’t going to save anyone relying on the shaggy defense.

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#246
post #82
post #16

Earlier quoted context omitted.

> Even simple things like forcing TLS 1.3 instead of 1.2 from client side breaks things...including hn site. That’s the reason, it breaks things, and some of them are important and can’t simply be updated.

> That’s the reason, it breaks things, and some of them are important and can’t simply be updated. IMO this is not a valid excuse. If it's exposed to the internet it needs to be able to be updated with relative ease to respond to a changing threat landscape. Especially if it's "important". If it cannot be then it is already broken and needs to be fixed. Whether that fix is doing a hard upgrade to get to the point tha…

> IMO this is not a valid excuse.

The world is full of things that aren't "valid excuses". Explaining why something is the way it is is not the same as justifying it.

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#247
post #129

Earlier quoted context omitted.

Doing this only provides deniability in public. If this was brought to a court there are enough server logs to build out if that DKIM record was valid along with a number of DNS history providers.

As if courts care about any of that. They'll just ask the witness "did you send this email"

Which is why you say "No". Then when they try to prove that you did in fact send it, this comes up.

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#248

Earlier quoted context omitted.

Which is why post-quantum algos were invented.

> Which is why post-quantum algos were invented. Yup. And I don't even think quantum resistance was the goal of some of the algos that, yet, happen to be believed to be quantum resistant. Take "Lamport signatures" for example: that's from the late seventies. Did anyone even talk about quantum computers back then? I just checked and the word "quantum" doesn't even appear in Lamport's paper.

> Did anyone even talk about quantum computers back then?

Not unless they have a time machine. Shor's algorithm was discovered in the 90s (sure the concept of a quantum computer predates that, but i don't think anyone really realized they had applications to cryptography)

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#249
post #18

Earlier quoted context omitted.

We are doing that, just not everyone is as concerned by safety and make different tradeoffs against things like ease of use or accessibility. Different applications have different tolerances and that’s fine. If and when anything quantum is able to yield results (I wouldn’t worry much about this), increasing key size is pretty much meaningless, you need to move to other encryption schemes (there’s lots of options alre…

In the case of RSA it's not meaningless to increase key size to fend off quantum computers. Quantum computing vs RSA is a case of being the largest contender, because quantum computing in itself doesn't definitively unravel the integer factorization problem.

That seems suspect to me.

Getting a working qc to reasonable scale is the hard part. Once you have done that most of the hard engineering problems are solved. I doubt doubling its size at that point would be very much of a problem.

If we are making (uninformed) predictions, i bet we wont see QC solving 1024 bit RSA in the next 15 years (at least), but once it does it will only take a year or two more to solve 4096.

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#250

Earlier quoted context omitted.

had a bounty. the RSA challenge unexpectly finished in 2007, task is left to the reader to speculate what happened in 2007.

Oh, I wasn't aware of the end of the challenge. But 1024 was definitely not broken by then, at least not by brute force.

none of it is "brute force", GNFS is a process that rapidly excludes numbers from the search space that cannot be the answer, in principle similar to the way they broke enigma.

numberphile has a great video on that one https://www.youtube.com/watch?v=V4V2bpZlqx8

Also, taking the OP as a "worse case", afaik:

512bit = $8

so

1024 = 8^2 = $64

2048 = 8^2^2 = $4,096

4096 = 8^2^2 = $16,777,216

noting $8 for 512 seems very expensive to me.

Post reply on HN