4 ms·
> With this technique, people cannot verify whether or not you said it, the email might be a fraud and so people are less likely to believe the sensitive thing
by outsomnia 6y ago
> With this technique, people cannot verify whether or not you said it, the email might be a fraud and so people are less likely to believe the sensitive thing about you.
If the recipient can prove he had the signed email before the signing private key was made public, eg, by contemporary third party notarization, the keys becoming public later don't help with disclaiming it at all.
- some_furry 6y agoYes, that's the point though: To make DKIM not serve as a non-repudiation mechanism. It forces actors to go through other notarization steps instead of relying on DKIM.
- outsomnia 6y ago> Yes, that's the point though: To make DKIM not serve as a non-repudiation mechanism. The devil is right in the details... it is serving just as perfectly fine as a non-repudiation mechanism as it ever was, just constrained in time to a day or so as suggested by the article. Depending on what you said to whom that you wish you hadn't said, that can be all you need to get into trouble.
- some_furry 6y agoAre you familiar with the concept of Post-Compromise Security?
- outsomnia 6y agoThere is no compromise and no security breached. Just a guy who really did say something and wishes there was no evidence he said it. Publishing the privkey just makes it so in other circumstances where he might strongly wish that he had evidence he HAD said something, the dkim signature is devalued.
- some_furry 6y agoThe author is nonbinary, not male.
- ryan-c 6y agoI'm not a he, but you're correct that a counterparty can easily break delayed key disclosure as a way to have plausible deniability. This was brought up in the Twitter thread (though reading a conversation on Twitter that has any forks is... a chore) started by Matthew Green.
- Thorrez 6y agoYes. In the specific example that I gave though (the recipient being your friend), it likely wouldn't happen because your friend is not going to get something notarized to use against you. There could still be a problem if the hacker has control of your friend's email account while you send your email, because then the attacker can get it notarized.
- Thorrez 6y agoThinking about this more, maybe an alternate technique to provide plausible deniability is to setup a service that acts as a signing oracle with your private key. To avoid it being used for impersonation you might be able to implement a system that receives signing requests via email, and will only sign emails that have the "to" address equal the source of where the signing request came from.
- ryan-c 6y agoAttack: Sign up for email accounts at major providers, use the signing oracle to sign spam emails, submit to provider, domain's reputation becomes spammy. The handling rules standardized by DMARC are to ignore failing SPF when there is a valid DKIM signature, even if the domain doesn't use DMARC. Google, in particular, ignored SPF failures on DKIM signed messages last I checked.
- Thorrez 6y agoInteresting. What if you required payment, say via Monero, for each signature? That would slow down the creation of spam emails.
- ryan-c 6y agoIf you're a low volume email sender, anything attributed to your domain getting marked as spam can cause serious pain. It's an interesting idea, but not an experiment I care to run.