3 ms·
> Yes, that's the point though: To make DKIM not serve as a non-repudiation mechanism. The devil is right in the details... it is serving just as perfectly fin
by outsomnia 6y ago
> Yes, that's the point though: To make DKIM not serve as a non-repudiation mechanism.
The devil is right in the details... it is serving just as perfectly fine as a non-repudiation mechanism as it ever was, just constrained in time to a day or so as suggested by the article. Depending on what you said to whom that you wish you hadn't said, that can be all you need to get into trouble.
- some_furry 6y agoAre you familiar with the concept of Post-Compromise Security?
- outsomnia 6y agoThere is no compromise and no security breached. Just a guy who really did say something and wishes there was no evidence he said it. Publishing the privkey just makes it so in other circumstances where he might strongly wish that he had evidence he HAD said something, the dkim signature is devalued.
- some_furry 6y agoThe author is nonbinary, not male.