Live data from Hacker News

Cracking a 512-bit DKIM key for less than $8 in the cloud

dmarcchecker.app

291–300 of 433 posts

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#291

Earlier quoted context omitted.

Counter-example example: I've been an expert witness in court to prove an email was a forgery; using DKIM.

It'd be funny if we were working together and just telling the same story behind our aliases.

My case was a family court dispute where one parent forged an email from the other parent about the child's care. It was a pretty wild case. After that, I was pretty convinced some people are just evil.

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#292
post #283

Earlier quoted context omitted.

If you publish DKIM keys, you don't have to convince anybody that you were targeted by someone who stole your password, because your stolen email spool no longer reveals to attackers the authenticity of your emails, which is what you as a user want.

But you need to convince someone that someone targeted you and used the published key to forge an email. Where is the difference?

[deleted]

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#293
post #34

Earlier quoted context omitted.

I never suggested that Yahoo uses 512bit keys, that's a misunderstanding. The article clearly states that Yahoo is one of the 3 clients that didn't reject 512bit keys the way they should per RFC. Yahoo Mail inbox users are vulnerable _receivers_ of spoofed emails.

remember when yahoo mail was the first one to implement DKIM validation and then all mailing list owners added a footer telling their subscribers not to use yahoo mail because it was broken, instead of calling their mailing list providers to upload a key? yeah nobody remembers, but yahoo probably do. i doubt they will err on the side of security again.

The Yahoo that built Yahoo Mail no longer exists, so actually they probably don't remember.

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#294

Earlier quoted context omitted.

> it's a grave privacy violation. I'm missing something here. DKIM mostly proves an email from person@from.me was sent by a server @from.me controls. There is also a bloody great audit trail inside of the email with together with SPF can do a pretty good job of proving the same thing. I'm struggling to see how an email sent to me, that presumably was always intended to be readable by me could suddenly become a privac…

It's nobody else's business whether the emails in your inbox are valid or not, and that's basically all non-deniable DKIM signatures do: durable secure verifiable DKIM signatures are "security feature" with real-world value exclusively for attackers .

If you’re under Rule 26 discovery or disclosure requirements, it absolutely might be my business whether emails in your client are valid, but I suppose you could classify opposing counsel as an “attacker,” so you’re not wrong.

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#295
post #283

Earlier quoted context omitted.

But you need to convince someone that someone targeted you and used the published key to forge an email. Where is the difference?

No you don't. You just say "that email is fake and you can't prove otherwise", and you're right. What's almost more important is: there is no reason not to give users that affordance. They literally do not benefit from the non-repudiability of their email archive. The OTR paper got this right 20 years ago, and in the process basically created the entire field of secure messaging. It is wild to see people argue agains…

I think here is where the problem isn't purely a technical one anymore. You're right that, from a legal perspective, there is a difference as the burden of proof would now be on someone else. But, if this actually matters or not, depends entirely on the situation. If you're a criminal trying to get away with something then the change in the burden of proof is all you need. If instead you're a politician trying to avoid some imbarassment, the situation isn't any different: you're claiming in both cases that someone is trying to frame you for something you didn't say. In one case, this person stole your password, in the other he/she used an old and by now publicly available DKIM key. But if people believe you or not (and this would be everything a politician would care about) depends on factors outside the scope of cryptography. Regarding OTR: IIRC it is based on a shared secret. This can work for IM, but it wouldn't scale for emails as it would pose the key distribution issues that made us discover public key cryptography.

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#296
post #295

Earlier quoted context omitted.

No you don't. You just say "that email is fake and you can't prove otherwise", and you're right. What's almost more important is: there is no reason not to give users that affordance. They literally do not benefit from the non-repudiability of their email archive. The OTR paper got this right 20 years ago, and in the process basically created the entire field of secure messaging. It is wild to see people argue agains…

I think here is where the problem isn't purely a technical one anymore. You're right that, from a legal perspective, there is a difference as the burden of proof would now be on someone else. But, if this actually matters or not, depends entirely on the situation. If you're a criminal trying to get away with something then the change in the burden of proof is all you need. If instead you're a politician trying to avo…

If you are a politician trying to get away with something, the public might have an interest in your secure messaging system being bad, but you yourself do not. Secure messaging systems generally take the side of their users, not the public.

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#297
post #47

Earlier quoted context omitted.

Isn't deniability at odds with DKIM's goal? What would be the point of setting DKIM then? Sure, it helps with spam scores. But most companies rely on a major email provider to send emails, so maybe they wouldn't have deliverability issues anyway?

Do take a look at the blog post I cited above, where I go into this in loads of detail. The TL;DR is that DKIM only needs to ensure origin authenticity for the time it takes to deliver an email, which is usually a few hours or a day at most. The unintentional problem DKIM is causing is that it actually provides non-repudiation for many years. Those signed emails can sit in someone's mailbox for years, then get stolen…

  > Reasonable people (e.g., high-integrity newspapers, courts of law) will say "how can we trust that these stolen emails are authentic given that there's no chain of custody?" DKIM signatures nearly answer that question, which makes stolen emails much more valuable than they would be otherwise.
Thank you for clarifying where the vulnerability chain begins and ends.

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#298

Earlier quoted context omitted.

It's nobody else's business whether the emails in your inbox are valid or not, and that's basically all non-deniable DKIM signatures do: durable secure verifiable DKIM signatures are "security feature" with real-world value exclusively for attackers .

If you’re under Rule 26 discovery or disclosure requirements, it absolutely might be my business whether emails in your client are valid, but I suppose you could classify opposing counsel as an “attacker,” so you’re not wrong.

Note, just to rub this in: you don't even get the verification you're looking for, because DKIM verifies domains and not users.

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#299

I don't understand why didn't Yahoo fail due to SPF check failure.

Considering that Yahoo doesn't really exist anymore, and that Yahoo Mail is just a relic of Yahoo's heyday that is somehow still hanging around, I assume nobody has bothered to actually maintain its handling of security protocols for about a decade.

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#300

Earlier quoted context omitted.

It's also only true so long as we don't discover more efficient ways of factoring large numbers. We haven't come up with any dramatic improvements lately, but it's always possible that something will come up. Symmetric crypto systems like AES are on much firmer ground, as they don't depend as heavily on the difficulty of any single mathematical problem.

By "lately" you mean...

I'm hedging a little because I'm not an expert. :) As far as I'm aware, the last major algorithmic development was GNFS in 1993.
Post reply on HN