Live data from Hacker News

Ok Google: please publish your DKIM secret keys

blog.cryptographyengineering.com

271–280 of 492 posts

Re: Ok Google: please publish your DKIM secret keys

#271
Repudiation doesn't seem to be desired by email users. Whether it's a valid encryption principle or not. The example crimes were not facilitated by this, but were merely verified. Had the DKIM keys been rotated, Podesta's emails would still have been stolen and leaked.

Re: Ok Google: please publish your DKIM secret keys

#272

Earlier quoted context omitted.

People who are protected from blackmail by email repudiation are by definition people who have incriminating emails. Maybe everyone had skeletons in their closet, but if you have email proof of skeletons I'm starting to wonder if you're such a good person. Also there's an argument that "good people" can be blackmailed for INVENTED misconduct, but wouldn't such fake emails be more convincing without the ability to ver…

Ah yes, the good old, “If you haven’t done anything wrong, you’ve got nothing to hide” argument. The authoritarians favourite argument for a police state. I guess you’re the type of person that would happily hand over all your personal files to the police on a regular basis as you have nothing to hide.

To be clear, the reason I was presenting that is that the OP says the opposite, essentially "You have to fear being blackmailed, even if you have done nothing wrong". I'm suggesting that non-repudiation is actually a good defense against blackmail for people who have "done nothing wrong". thinkharderdev provides a more concrete example of one of the problems that arises in the police state, in that "wrong"-ness is not consistent, and you could be persecuted for things you say or who you are based on a backwards interpretation of what is "wrong".

Personally I am fine with the idea (as represented in this comment https://news.ycombinator.com/item?id=25115654) that email is providing something similar to a "paper trail", and when you send an email you can expect that people can prove you sent it, should they get their hands on the email. However, I totally understand the position that private secure messaging is important and that email should default to that.

In the authoritarian argument, "you've got nothing to hide", is followed by "you are now forced to reveal all", in my execution it would be "you are accountable for all emails you send, forever, should they be released". I am ok with that specific lack of privacy in that context, but I can understand the position that non-repudiability should be opt-in, and privacy the default.

Re: Ok Google: please publish your DKIM secret keys

#273
post #82

I know threads change over time, and it's dangerous to write a comment in response to the perceived gestalt of an HN thread, but, I have to say, it's pretty wild reading a thread on this site arguing so strenuously against the premise of secure messaging. In messaging cryptography, non-repudiability has for almost 2 decades been considered a vulnerability, not a feature. The OTR protocol[1] takes the step of publishi…

> To allow a stranger to authenticate a messages is to concede information to them, and avoiding concessions is the point of messaging cryptography.

Whilst I agree with you that email messages should be repudiable , I have a feeling you're trying to pass something off as axiomatic that isn't. For example isn't a confidential business agreement basically exactly, by design, an authenticated non-repudiable message that can be authenticated by third parties (such as courts)?

Re: Ok Google: please publish your DKIM secret keys

#274
post #180

Earlier quoted context omitted.

Not OP. But I would give all my data to the police/government... in an encrypted manner that has guarantees in place that only valid criminal investigations can decrypt. Heck, we do it on some level all the time anyways when it comes to things such as filing taxes, getting married, running companies, enforcing contracts and various other day-to-day benign interactions. At this point, I'm more inclined to believe that…

> I'm struggling to find compelling and valid reasons why we can't pursue a general solution that involves us giving all this "private" data to a government entity for legitimate investigations, fraud prevention and crime-solving whilst keeping that data free from abuse. Because that's not logically possible. It would be nice if it were, but just think about it: if you give data to the government, humans can look at…

But, the message you are replying to points out governments already have piles of information about you -- your taxes for example. They can easily add to this (in appropriate legal situations), by reaching out to banks in your country for example.

While I understand the problem of evil governments, I broadly trust mine. I want them to have the power to investigate me, and my fellow citizens, for crimes. I don't want to love in a lawless country.

Re: Ok Google: please publish your DKIM secret keys

#275
post #149

Earlier quoted context omitted.

The Hunter Biden email is a terrible example. It's very likely that what's been found on "Hunter Biden's" laptop is just hacked material which has been stuffed on a laptop to disguise the original source of the breach. In this case the DKIM signatures are being used to lend credibility to the story that the laptop was mysteriously left in repair shop, never to be reclaimed. DKIM is not meant to validate conversations…

It's not farfetched to believe a crack-addicted wealthy individual who seemed to live a very "promiscuous" lifestyle, would have forgotten some cheap laptop at a repair shop. These people are humans, at the end of the day.

Yes, it is far-fetched given that the story doesn't add up. Also, cocaine isn't known to cause people to suddenly become poor thinkers. I've seen this narrative pushed multiple times that somehow him doing cocaine made him fly across country and drop off his laptop to a blind computer repair shop owner and leave it there with sensitive information on it which was verified by a blind man with his signature, which was then turned over to Rudy Gulliani because he was concerned about the material.

Re: Ok Google: please publish your DKIM secret keys

#276
post #180

Earlier quoted context omitted.

Ah yes, the good old, “If you haven’t done anything wrong, you’ve got nothing to hide” argument. The authoritarians favourite argument for a police state. I guess you’re the type of person that would happily hand over all your personal files to the police on a regular basis as you have nothing to hide.

Not OP. But I would give all my data to the police/government... in an encrypted manner that has guarantees in place that only valid criminal investigations can decrypt. Heck, we do it on some level all the time anyways when it comes to things such as filing taxes, getting married, running companies, enforcing contracts and various other day-to-day benign interactions. At this point, I'm more inclined to believe that…

How exactly would you do this?

> in an encrypted manner that has guarantees in place that only valid criminal investigations can decrypt

What constitutes a valid criminal investigation, who decides? Do you, does a prosecutor, a judge, the police?

Is it a valid to decrypt your data just see if you were at a specific location at a specific time? What about so the police can check a theory? How about to see if you joined an unsanctioned protest, smoked a joint, speed while driving, downloaded a movie?

Speeding and copyright theft are both criminal, are you saying that your happy to make it trivial to investigate you for these crimes an prosecute you for them?

It used to be criminal to engage in homosexual behaviour, and in some parts of the world. Once upon a time that would be a valid criminal investigation in the US. For a short while it was looking like abortions might become criminal in the not too distant future.

Privacy is a fundamental tool for allowing society to progress and change, and for avoiding totalitarianism.

Re: Ok Google: please publish your DKIM secret keys

#277

The problem with the author's paper is that his assumption (and that of, apparently, media organizations, Wikileaks, and others) of DKIM "ensuring non-repudiation of emails" is simply wrong. >DKIM provides a life-long guarantee of email authenticity that anyone can use to cryptographically verify the authenticity of stolen emails, even years after they were sent. No, it doesn't. It simply offers an assurance that, at…

Your conceptions of what is good and bad are not everyone's.

When a potentially important email dump is leaked individuals will use any reasonable means to gain information about it's authenticity.

Knowing that DKIM headers are on those emails and that the service provider hasn't published those keys changes the question from:

"Did you send this email" to "Was your email address compromised at this time?"

Re: Ok Google: please publish your DKIM secret keys

#278

As a security professional I 100% agree with the author. The comments here on Hacker News seem to have tripped on the examples given (keywords: politicians, journalists) and turned this into the more generic and politically loaded discussion whether it's desirable to "cryptographically verify" what politicians write. But that's not the point! The point is that DKIM is technically not designed for this use case and th…

Technically, DKIM probably shouldn't take away deniability. But to be fair, this discussion doesn't exist in vacuum. Requesting that Google publish private keys is inherently politically loaded, given recent events. (and it's was neither goal or anti-goal in DKIM design, so it's not that there is mistake in protocol or something).

If some provider decides to implement this proposal, I don't think they should do it retroactively and publish old keys. It would be just inviting additional political shitstorm.

Re: Ok Google: please publish your DKIM secret keys

#279
post #214

The piece seems to be arguing from a general principle. Repudiation is a feature of most secure messaging applications and it is a feature that should be introduced to GMail. This argument doesn't fully address how technologies are actually used today. As far as I can tell, people who need repudiation are already using apps that have repudiation (eg Signal), because they know they are in a vulnerable position. The pe…

> The people who need non-repudiation already have it. Can you really not think of a scenario where non-repudiation could be important even to people "not in power"?

I edited my comment, as I intended to say "The people who need repudiation already have it."

Re: Ok Google: please publish your DKIM secret keys

#280

Earlier quoted context omitted.

> I'm struggling to find compelling and valid reasons why we can't pursue a general solution that involves us giving all this "private" data to a government entity for legitimate investigations, fraud prevention and crime-solving whilst keeping that data free from abuse. Because that's not logically possible. It would be nice if it were, but just think about it: if you give data to the government, humans can look at…

But, the message you are replying to points out governments already have piles of information about you -- your taxes for example. They can easily add to this (in appropriate legal situations), by reaching out to banks in your country for example. While I understand the problem of evil governments, I broadly trust mine. I want them to have the power to investigate me, and my fellow citizens, for crimes. I don't want…

Do you trust all future governments?

Germany 1933, Donald Trump today, far right extremism in Europe are all examples of how trustworthy governments become evil governments.

Democracy doesn’t offer a defence against “evil” governments. Only that you need a majority (and frequently not even a majority) to vote for one.

Post reply on HN