28 ms·
Ok Google: please publish your DKIM secret keys
- hashtagmarkup 6y agoYou ain't bright. If you pee in a cup of someone else's pee, you destroyed evidence. That is what publishing DKIM keys would do. A flood of fake messages to taint and destroy the ability to validate the would-be truth. I would have appreciated it if you didn't waste the last decade of your life counting internet points. [0] [0] u dum
- darig 6y agoYou are a pathetic, pathetic, pathetic person. I'm aghast that you don't understand that. You attempted to hijack my thread with your ignorance. You have beyond been proven wrong. You haven't been restrained. You've been ignorant. You don't belong here. You count fake internet points, and yet I've gained about 106 in less than 24 hours while it took you over 10 years to get a smidgen over 2000. Hey, at least that's more than you raised for charity when you spent more than 10 times as much to fail to summit Everest. Congratulations????? sad.
- bawolff 6y agoI don't see non repudation as that bad a thing. Are people any less likely to be blackmailed due to technical deniability of email contents? I feel that for most, that wouldn't matter.
- busterarm 6y agoNo, this post has absolutely nothing to do with Hunter Biden's emails having valid Google DKIM. Nothing at all.
- gnarbarian 6y agoWhat would that accomplish though for either side? Have the signatures been validated? You don't need the private key to do so. Assuming the keys are valid; either the emails are real, or the keys were stolen and the emails forged. I suppose if keys are released it gives plausible deniability for any leaked emails that occur AFTER the key release. So I can see why people sending incriminating emails would support this.
- deleted 6y ago[deleted]
- arkadiyt 6y agoInteresting/educational read but I'm still not convinced that this unintended side effect is a bad thing - it seems like a desirable property to have authenticated emails. Matt argues this might lead to regular folks (as opposed to politicians) getting blackmailed, but: 1) it seems unlikely this cryptographic proof is needed (he acknowledges this criticism in the post), and 2) what seems more likely to me is that politicians would intentionally _not_ opt in to any alternate solution and use that deniability for their own advantage. (Also as an alternate he proposes GPG, which I know Matt knows is laughable).
- busterarm 6y agoYou might want to validate your emails more than a few months out. Regardless of if your emails are valid or not, blackmail is still a crime. Not being able to have your emails validated doesn't protect you from blackmail. The power of blackmail is often in the social cost of the accusation itself. The thing that protects you from blackmail is not getting involved in things you can be blackmailed for. This is like saying don't lock your doors so that nobody can break and enter into your house.
- vorpalhex 6y ago> The thing that protects you from blackmail is not getting involved in things you can be blackmailed for. This is incorrect, because the things that someone can be blackmailed for is not the same as the set of immoral or unethical acts. You can be blackmailed for being gay, or for having a serious medical condition that's undisclosed. Neither of those situations is a "well just don't do that" kind of thing. The defense against blackmail is to make blackmail difficult (eg release DKIM keys), severely punish people who engage in blackmail, and guard your secrets effectively. > This is like saying don't lock your doors so that nobody can break and enter into your house. This is like saying the latch on your fence is a security mechanism. Nobody intended that fence latch to keep your safe or secure and hiding behind it won't make you safer. Rip away the false pretense.
- michaelmrose 6y ago
- Google234 6y agoI find it pretty funny that the author wrote this because they are salty that the leaked hunter Biden emails could be verified with DKIM
- edoceo 6y agoThis is false. The article pointed to DKIM being used for journalistic verification for multiple parties (persons and organizations) across the political spectrum. It's not salty or overtly political.
- whereshunter 6y agoTheir lack of addressing Hunter's emails says the most.
- megous 6y agoCan't you just set up your mailserver so that it drops all the crypto headers (DKIM-Signature, ...) after verifying them and storing the result in Authentication-Results? Only your server's Authentication-Results header is really relevant to spam filtering, anyway. Unless you're debugging something those headers seem irrelevant anyway, and they bloat the messages very much. (often times they are 3-4x the size of actual email)
- some_furry 6y ago> Can't you just set up your mailserver so that it drops all the crypto headers (DKIM-Signature, ...) after verifying them and storing the result in Authentication-Results? Matthew Green's ask isn't about protecting users that are tech-savvy enough to just set up their own mailserver and configure it a special way. It's about protecting the billions of users that aren't.
- adrianmonk 6y agoGmail (and other email providers) could also protect these billions by making the header-stripping change at the server level for everyone. After all, Green is proposing for them to change their servers anyway, so either way it requires some kind of server change. The advantage of Green's approach is it gets results quickly because with one change they can protect a lot of emails. But, while quick results are nice, is this problem really so urgent that only the fastest solution should be considered? Another difference is the set of users who are protected. If you rotate DKIM keys, you protect Gmail users against non-repudiation risks because their outgoing emails become more deniable. But if you strip headers from Gmail users' inboxes, you protect Gmail users against hacking, because now hacking a Gmail account gets you less-valuable data. Also, publishing old DKIM secret keys will require some distribution method. Where do you actually put them? For a given email provider, where do you go look to find them? It's a solvable problem but it's one that doesn't exist with the header-stripping approach.
- hamburglar 6y agoYes, the call isn't for GMail to kill non-repudiation protections on mail they receive (and was signed by others), it's to kill it on emails they've signed and thus are sitting on someone else's server.
- blibble 6y ago> Google could launch the process right now by releasing its ancient 2016-era private keys. Since the secrecy of these serves literally no security purpose at this point, except for allowing third parties to verify email leaks, there’s no case for keeping these values secret at all. I've used Google's DKIM signatures to timestamp call recordings for years by putting a sha256 of the attached recording in the subject, so "literally no security purpose" isn't true! (though I should probably go through and timestamp those signatures right now them using another method, just in case this guy's idea gains any traction)
- taldo 6y agoThe answer to every problem: blockchain!
- thinkharderdev 6y agoIf you have a specific use case where you need non-repudiation then there are numerous other tools you can accomplish that with. I think the author is arguing that it shouldn't be on by default.
- advisedwang 6y agoIf Google did rotate the keys, it's quite likely some enterprising people would log observed keys. With access to a log of keys (that you don't believe has been tampered with) then rotating keys doesn't prevent non-repudation. An alternative would be for email servers to strip the DKIM headers on inbound emails after recording that the email was validated. The email stored at rest then no longer provides non-repudation. Nothing is stopping you doing this today.
- arkadiyt 6y ago> rotating keys doesn't prevent non-repudation That's why he says Google also needs to publish the private keys.
- deleted 6y ago[deleted]
- kennywinker 6y agoI'm not a fan of offloading that trust onto my email host. Not that I validate dkim headers, but the fact that I have access to them keeps my email host honest.
- punnerud 6y agoDKIM secrets should also be added to GDPR-dump/export, and releasing keys in the same way after a while. Would make imports into other services possible, by trusting the legitimacy of export.
- hpoe 6y agoSo the author's central thesis essentially seems to boil down to that leaked emails were able to be cryptographically verified, because of DKIM and so we should prevent that so people can't use email to blackmail politicians? Ultimately I prefer the more information that we can get on politicians available. It seems to me that especially when an elected official has something they don't want others to know about that it should be public knowledge. After all an efficient marketplace only is efficient if all actors have access to as much information as possible. EDIT: As a follow up, several people point out that it could happen to me or a family member, but this seems even further reason to have DKIM so that if someone attempts to blackmail me based on the contents of my email, checking the DKIM signature makes it even easier to disprove a bad blackmail attempt.
- mthoms 6y agoThe threat is not limited to politicians. Anyone (including you and your family members) could be blackmailed or otherwise publicly embarrassed.
- hashtagmarkup 6y ago> The threat is not limited to politicians. Anyone (including you and your family members) could be blackmailed or otherwise publicly embarrassed. ... for what they actually did. You think the solution is allowing people to be blackmailed or otherwise publicly embarrassed for things they didn't do, while removing their ability to verify that they didn't do them?
- blendergeek 6y agoNo. Once DKIM keys are published, one can simply deny all emails published "from their account". We currently have a way for an attacker to prove an email's origin years after the fact.
- hashtagmarkup 6y agoYes. We are saying the same thing.
- Edmond 6y agoI like the idea of non-repudiation, let the chips fall where they may when such authentic email is maliciously dumped. Perhaps a simple timestamped based appendage can be added for the sake of email client authentication. In other words reject the email if the signature is older than a few hours/minutes.
- FrozenVoid 6y agoA novel type of cryptographic attack "Begging Google to release their secret keys on HN"[2020]
- rurban 6y agoSo I thought Google was already CIA for a long time. But now a CIA shill (or NSA) has to resort to a public plea to remove email authentication, so that future embarrassing email leaks, probably proving corruption and other criminal activity, can easily be plausibly denied. Wtf. Even for old emails, gmail break-ins. They are getting more and more laughable. What about a public plea for justice? Accountability?
- FrozenVoid 6y agoEquating something to a CIA front company is too simplistic(like Zuckerberg's Facebook and Lifelog project), the companies, projects and frameworks grow out of their sponsors reach and evolve into large, complex systems like the Internet(a spin-off from ARPANET created by Advanced Research Projects Agency (ARPA) of the United States Department of Defense ).
- elaborant 6y agoKey disclosure by cryptographic shaming[2020]
- benlivengood 6y agoOnly the recipient has access to the DKIM signatures. If something is politically worth leaking then it's worth signing and time-stamping. At least then there's no question that it's the legitimate email and not falsified.
- xbar 6y agoI think this is a shameful argument. Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail. Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?
- bluu00 6y agoyour arguement seriously makes the whole _privacy arguement_ seem futile. what about a _telegram_ message?
- hyperpape 6y ago"An accident of the past few years is that this feature has been used primarily by political actors working in a manner that many people find agreeable — either because it suits a partisan preference, or because the people who got “caught” sort of deserved it. But bad things happen to good people too. If you build a mechanism that incentivizes crime, sooner or later you will get crimed on."
- tigger0jk 6y agoPeople who are protected from blackmail by email repudiation are by definition people who have incriminating emails. Maybe everyone had skeletons in their closet, but if you have email proof of skeletons I'm starting to wonder if you're such a good person. Also there's an argument that "good people" can be blackmailed for INVENTED misconduct, but wouldn't such fake emails be more convincing without the ability to verify their origins? Making real emails and fake emails more similar protects people who have their incriminating emails leaked, but it also harms the defence of people who have fake emails targeting them "leaked". There's a high bar for obfuscating truth and I don't believe this argument meets it.
- harikb 6y agoPlease read the whole article. If it only takes a "few hours" to create incriminating "evidence" (read, something that didn't exist) - it must be clearly proclaimed as such to the world.
- hammock 6y agoPerversely, this solution could result in MORE emails being hacked MORE OFTEN. Allow me to explain. If a hacker were to retrieve some emails before the DKIM key was made public, they could then sign their hacked emails with their own timestamped signature, proving that they are in fact authentic (since the signed timestamp shows that they were retrieved before the DKIM key was released). Therefore, by rotating the DKIM keys "every few weeks" you are giving the would-be hackers a deadline to retrieve the target emails - a few weeks - which could lead to hackers preemptively hacking as many possibly useful accounts as possible (not just the ones they know they want at a given moment), every few weeks. (The merits of OP's argument notwithstanding)
- hyperpape 6y agoYour threat model appears to be that most email providers are hacked a substantial percent of the time, right? What defenses of anything are going to work with that threat model?
- adrianmonk 6y agoYou don't necessarily have to hack the provider. You can hack the user's laptop and siphon the data out of their email client. If they use a web client, you can read the files it caches. Or maybe you can set up IMAP and have your malware read a copy of everything. To the email provider, all of this just looks like the user is reading their email.
- hyperpape 6y agoFair, though I think it's still true that it's a very difficult threat model. Also worth noting that email clients typically tell you about new logins/clients (though I don't think their way of doing it is particularly robust).
- lolc 6y agoIf crackers could justify the resources, they would already now be doing more cracking. It's not like they can just scale their operations ten times all else staying equal. The proposed change in key rotation and publication makes fresh mails only more valuable relative to old messages, not more valuable in general. If we're looking at cracking-activities from an economic point of view, publishing DKIM keys makes the cracking harder: 1. More accounts need to be cracked fast 2. Timestamped signatures must be published in a timely way 3. Results must be stored until they become useful These things not only increase cracking expenses, they also increase the threat of detection.
- nisuni 6y agoDKIM might have non-repudiation as unintended side effect, but I am totally fine with it!
- morpheuskafka 6y agoIt seems like this would also be useful for proving contracts/statements over email in business law. While it may not have been designed for this purpose (and there could still be claims that the sending account was hacked, unlike a personal GPG key which identifies the individual rather than the infrastructure), it seems to be a pretty good thing to have.
- nevinera 6y agoIf you have nothing to hide, you have nothing to fear! Privacy schmivacy.
- nevinera 6y agoI personally am absolutely confident that every email I sent during college and my adolescence would merely shine brighter light on the perfection of my soul. It sounds like the rest of you should probably have behaved better.
- RcouF1uZ4gsC 6y agoOne thing that Google publishing their DKIM rotated keys is take fake news to a new level. Basically anybody could use those signing keys to fake email from a politician or celebrity. Imagine the headlines “Celebrity X account hacked, here are the emails, cryptographically verified by Google” Of course, informed people will know that anybody could have faked them, but I would guess normal people would be fooled. In addition, there is no way to say the emails are definitely fake. At least now, we can tell between actual leaked emails and fake emails.
- woodruffw 6y ago> Of course, informed people will know that anybody could have faked them, but I would guess normal people would be fooled. In addition, there is no way to say the emails are definitely fake. At least now, we can tell between actual leaked emails and fake emails. No, you can't. Google used to use 512- and 1024-bit RSA keys for DKIM signatures, both of which are comfortably within the means of small-to-medium-sized nation states. They currently use 2048-bit keys, which will probably be crackable within the next decade. DKIM is providing a false sense of non-repudiation here, one that it was never designed (much less correctly implemented) to provide.
- devit 6y agoThis seems like a feature, not a bug.
- nullc 6y agoMeanwhile, the IETF is speccing more messaging protocols with non-repudiation and HN users seem to be cheering that shortcoming along: https://news.ycombinator.com/item?id=25100316 https://news.ycombinator.com/item?id=25100316 I think it's kind of unfortunate that there are many people that suddenly care when its powerful people or their families that are getting caught out by DKIM, these aren't the people who need protection from it the most. No one would even care if the Hunter Biden related emails passed DKIM except for the widespread allegation that they were fake, and no one still cares because conversation about them passing DKIM is widely suppressed (including on HN, unfortunately, where a post about it was immediately flagged). Oh well, I suppose it's like when the ACLU used to defend awful speech for the sake of defending free speech because those were the cases available which could make an impact. Unfortunately publishing DKIM secret keys only goes so far towards avoiding accidental non-repudiation: Recipients can cryptographically timestamp the signatures before the keys are published. ... and doing so already makes sense independent of DKIM. In fact, one of the ways that the public was able to prove that the outdated google DKIM key was a real key was that we were able to find cryptographically timestampped google signed emails from back when that key was still in use. Better than key publication is to avoid having a non-repudiateable stamp to begin with. This is much easier in the context of end-to-end two-party interactive protocols, but I believe is still possible for multiparty protocols. The analog for DKIM wouldn't work so well unfortunately, because DKIM isn't end to end. E.g. DKIM could be changed so that the signature demonstrated that either the sending server or the recipient server signed the message-- this would be just as good for anti-spam, but really wouldn't improve the non-repudiation in most cases. Contrast that with applying the same approach to end-to-end messaging, where it gives you pretty strong non-repudiation.
- stefan_ 6y agoI think you are missing part of the irony here. A good number of those Hillary emails should have been on a government server in the first place, signed for entirety by the government for archival. Non-repudiation is an explicit design goal for the communication of public officials.
- newacct583 6y ago
- 7ewis 6y agoRepudation - "denial of the truth or validity of something."
- 013a 6y agoI think there's an angle to the plausible deniability that many people are missing. Email servers get hacked all the time, right? A disgusting amount. Its almost like security is really difficult; in fact, its difficult to secure both the emails and the DKIM private keys. They're usually on the same server, after all. If a DKIM private key gets hacked, and the world relies on DKIM to provide non-repudiation in the verification of email leaks, then a hacker who obtains someone's DKIM private key could forge an email to contain any content they want, sign it with that private key, then leak that. The world says "its DKIM validated, Trump really did kill a litter of puppies twelve years ago", Trump tries to say "no, my email server was hacked, i never did that but they got my DKIM key" and who the hell would believe him? The headlines have already been written, and the argument against it is some crazy technical terminology a hundredth a percent of the population actually understands? Ok, well, maybe you should rotate DKIM keys. Not necessarily make the private portion public, but at least rotate them and totally destroy the old private keys. But, again, if an email server is misconfigured enough to leak data, then its likely the admin is incompetent enough to also not be rotating keys. Moreover, unauthorized access to a server could happen over a period of years, during which hackers collect the rotated DKIM private keys while letting the admins think they're being deleted correctly. The problem here isn't really DKIM; its the public's perception of what it was designed for. Technologists invented something, journalists discovered it, read a wikipedia article, and thought "woah we could use X for Y". So, I think it makes sense that we need a big name like Google to come out and say "Stop, this is not what this was designed for, it has major limitations in being used for that, and we're talking about real-world consequences like ruining potentially innocent peoples' lives."
- busterarm 6y agoIf everyone had a proper understanding of email and was not dumb enough to send out secrets via email, or to at least encrypt the content of those emails...then nobody would believe such a leak to be plausible. Sadly that's not the case.
- mattbeckman 6y agoAs we head into the post-truth era, we already know videos are going to become far less trusted due to deep fake tech. Finding grains of truth through cryptography, like DKIM, is so refreshing that it hurts to think some people want to cripple it. The Hunter Biden email is a good example. I initially thought it was a garbage tabloid drop, but once I read Rob Graham's analysis, it felt very refreshing to have a real nugget of truth based on math. While the context of that content is up for debate, the truth was essentially undeniable (unless you subscribe to the 2016 private key being stolen). We need nuggets of truth.
- davewritescode 6y agoThe Hunter Biden email is a terrible example. It's very likely that what's been found on "Hunter Biden's" laptop is just hacked material which has been stuffed on a laptop to disguise the original source of the breach. In this case the DKIM signatures are being used to lend credibility to the story that the laptop was mysteriously left in repair shop, never to be reclaimed. DKIM is not meant to validate conversations, it's meant to validate single messages for the purposes of spam prevention. Just because I can cryptographically validate selectively chosen messages from someone's mailbox, I don't have any proof that the conversation happened as presented. There's a good reason why eliminating non-repudiation has been a goal of messaging protocols since OTR in 2004.
- deleted 6y ago[deleted]
- rabuse 6y agoIt's not farfetched to believe a crack-addicted wealthy individual who seemed to live a very "promiscuous" lifestyle, would have forgotten some cheap laptop at a repair shop. These people are humans, at the end of the day.
- gitweb 6y agoYes, it is far-fetched given that the story doesn't add up. Also, cocaine isn't known to cause people to suddenly become poor thinkers. I've seen this narrative pushed multiple times that somehow him doing cocaine made him fly across country and drop off his laptop to a blind computer repair shop owner and leave it there with sensitive information on it which was verified by a blind man with his signature, which was then turned over to Rudy Gulliani because he was concerned about the material.
- buraktamturk 6y agoHey Google. Please never do this. This would throw thousands of evidence about how Erdogan regime worked with terror organisations, including the e-mails that tried to ban social media to stop these evidences be available to public. And also how they declared innocent people as terror organisations with some companies that offered law support. For example, this one https://wikileaks.org/berats-box/emailid/35540 https://wikileaks.org/berats-box/emailid/35540 especially verifies a crime - Turkish Airlines Nigeria Weapon transfer as it marks the event as "Government Secret"; The evidence that they talk on this e-mail involves a call where the ministers talk "I don't know if they will use it to kill Muslims or Christians". That specific e-mail does not have DKIM signature (maybe because it was sent his own gmail address? or to an gmail address in general?). I am aware that even if they publish the DKIM secrets, these e-mail will not lose any value since these e-mails was posted before the secrets. But I think using e-mails as evidence should be a thing in general. As you could receive them to your personal e-mail server and want to authenticate and use it on a court, even years after. If they publish the keys, it would not be possible as you could be the one who forged the e-mail as it were received from somebody else and has been put to your IMAP server manually.
- yholio 6y agoIn reality, that would throw forgery of such evidence in the hands of regular people, as opposed to those politically connected, the secret services, and nation-state hacker squads. While I sympathize with your political plight, I don't really understand why you would think that is a good thing in general. For all intents and purposes, it seems even worse, leaving the ability to weaponize public opinion in the hands of those who should most fear it.
- buraktamturk 6y agoExcept if you are the actual victim of these e-mails and the politicans who control 95% of the media are able to trick people either making them belive it was fake or it had "national interests" and they did it because of "country". At least these e-mails are believed to be true in other countries. So does Authenticity of thes e-mails can easily help you when you seek asylum in country from a country where they declared you as a terrorist - internationally.
- tptacek 6y agoI know threads change over time, and it's dangerous to write a comment in response to the perceived gestalt of an HN thread, but, I have to say, it's pretty wild reading a thread on this site arguing so strenuously against the premise of secure messaging. In messaging cryptography, non-repudiability has for almost 2 decades been considered a vulnerability, not a feature. The OTR protocol[1] takes the step of publishing its used MAC keys --- it releases private key material! --- to ensure that random people can forge messages once participants have authenticated them. Signal came up with a novel deniable AKE[1] that is one of the more famous parts of the protocol; by design, you can forge a Signal conversation from someone's private key even if you've never talked to them before.† When you think about it in the abstract, it's easy to understand what's going on, even if you don't take the time to read the OTR paper. Once counterparties have authenticated each others messages, authentication has served its purpose. To allow a stranger to authenticate a messages is to concede information to them, and avoiding concessions is the point of messaging cryptography. If you believe non-repudiable messages are necessary for public policy, it's hard for me to understand how you'd support the rest of secure messaging. Most secure messengers also have "disappearing messages", which have an even more powerful impact on the public's ability to read your (or some disfavored other's) messages. In fact, keeping the public from reading stuff is... kind of the obvious point? Maybe it's just email, and the belief that email should not just be insecure, but be deliberately insecure? But, you all get how weird it is for me to read that after getting yelled at for writing a blog post about avoiding secure email, right? 547 comments[3]! Many of them very angry! [1]: https://otr.cypherpunks.ca/otr-wpes.pdf https://otr.cypherpunks.ca/otr-wpes.pdf [2]: https://signal.org/blog/simplifying-otr-deniability/ https://signal.org/blog/simplifying-otr-deniability/ [3]: https://news.ycombinator.com/item?id=22368888 https://news.ycombinator.com/item?id=22368888 † I'm always looking for this triple-DH blog post and never able to find it, because it doesn't contai the word "triple", and it never occurs to me to search for "deniable", only "repudiability" (which also doesn't occur in the blog post) so I guess I can thank this thread for fixing my bookmark.
- deleted 6y ago[deleted]
- sethgecko 6y agoExcuse my ignorance but how does someone else signing my message prove that I sent the message? Moreso if the body of the message is not being signed at all?
- speedgoose 6y agoI doubt Google will publish old private keys that were not designed to become public later. I would guess that it's too dangerous or cumbersome to do the security analysis. What if someone realizes that Google uses a broken cryptographically secure pseudorandom number generator (CSPRNG) à la Debian ? Unlikely but the risks exists, so not going to happen in my opinion.
- toast0 6y agoIt's also quite possible that they simply deleted the private keys after cycling to new keys.
- __david__ 6y ago> What if someone realizes that Google uses a broken cryptographically secure pseudorandom number generator (CSPRNG) à la Debian ? 1. Someone with bad intentions figuring that out could start spamming other domains using gmail.com From Addresses. 2. Someone with good intentions would contact google security for a bug bounty or maybe just publish a zero-day report. Google would correct the issue and the world would be a slightly more secure place. #2 would almost certainly happen, I suspect. And if #1 happened _before_ #2 then there'd be more spam in the world, temporarily. To me the risk seems low.
- bjornedstrom 6y agoAs a security professional I 100% agree with the author. The comments here on Hacker News seem to have tripped on the examples given (keywords: politicians, journalists) and turned this into the more generic and politically loaded discussion whether it's desirable to "cryptographically verify" what politicians write. But that's not the point! The point is that DKIM is technically not designed for this use case and the way people misuse DKIM for this unintended purpose is highly problematic from a cryptographic and engineering perspective. I think the best way to think of DKIM is that it's a "cryptographic protocol" in the sense that git is a "cryptographic protocol" because it uses SHA1. If you think "PGP" (not the best example :-)) or "Telegram" you have the wrong idea: DKIM is a bunch of cryptographic primitives haphazardly bolted on email to solve a specific problem. It's not good cryptographic design because good cryptographic design anticipates unintended usecases and deal with them appropriately. 1) Read the DKIM RFC. First of all the only field that it's required to sign is the From: header (see RFC, section 5.4). So you could still forge an email but have it pass a DKIM signature check. If people believe that DKIM "cryptographically signs" e-mails in the sense of PGP, then that's a problem, because that's not true. A DKIM signed email doesn't actually say anything: you have to look at the signature which part of the message are signed, which is not standardized. So you could have this situation when people, like journalists or even people on Hacker News, think a forged email is valid because it has a valid DKIM signature (but the signature is over the From: header only). E-mail is complicated as it is without having to explain to people who have binary classified an email as "forgery" or "not forgery" based on a specific combination of email-headers and DKIM signature specification. Let's not do that. 2) Look at what mail providers actually do with their DKIM keys. For legacy reasons due to DNS providers and length of TXT records, many large internet providers use DKIM keys that are 1024 bit RSA. Already 10 years ago, most standard bodies started to recommend against the use of 1024 bit RSA. It's deprecated. Like MD5-deprecated. The fact that many service providers use the same key for all emails for all customers and reuse that key for years, increasing the likelihood of the key being leaked, is another case against trusting DKIM for this purpose.
- garaetjjte 6y agoTechnically, DKIM probably shouldn't take away deniability. But to be fair, this discussion doesn't exist in vacuum. Requesting that Google publish private keys is inherently politically loaded, given recent events. (and it's was neither goal or anti-goal in DKIM design, so it's not that there is mistake in protocol or something). If some provider decides to implement this proposal, I don't think they should do it retroactively and publish old keys. It would be just inviting additional political shitstorm.
- epaulson 6y agoThis would break a cool indieweb "hack" with DKIM - webfistbump, which lets folks participate in webfinger even if their email provider doesn't support webfinger, like gmail: https://www.onebigfluke.com/2013/06/bootstrapping-webfinger-with-webfist.html https://www.onebigfluke.com/2013/06/bootstrapping-webfinger-... (I suppose you could just re-opt into webfistbump every time your email provider is about to publish their DKIM key)
- upofadown 6y agoThis relies on the problematic approach to deniability of making forgeries possible. To make this work you need to claim a forgery when you know that no such forgery occurred. So you explicitly or implicitly have to accuse someone of a serious crime/offence they did not commit. Most people have a greater sense of honour than that. Those that don't would still have to fear getting caught. If someone actually does forge a message using the old private keys provided by Google then you would have to fight the assumption that you were using the system as it was designed. Everyone would just assume you said it and are now using the possibility of forgery to lie about having said it. You can always claim a forgery anyway should you decide to do that. Perhaps someone got access to Google's relatively poorly guarded DKIM private key. How would you know? You are probably not making a specific claim anyway.
- avianlyric 6y agoThere should be no need to make claims of forgery. The mere fact that an email can be forged will substantially reduce the likelihood of email being used, unless clear providence can be provided. At the moment that providence can be proved with DKIM. Remove DKIM and now bad actors need to prove that they actually broke into someone’s emails and stole them. A much high bar to pass, especially as it may mean incriminating yourself of a crime. Emails become just as useful as find a pile of top secret papers on the floor. Unless you can prove the source of those papers everyone is going to ignore you.
- tarkin2 6y agoI'm torn. But someone could threaten to speak to your insurer about a medical condition mentioned in an email.
- egberts1 6y agoOne could always add a “CC:” before the DKIM-start “From:” and still pass DKIM, no?
- jedberg 6y agoIt's interesting that he asks for this solution but not the more easy to implement solution to the other side of the problem (which you can do if you run your own server): remove the DKIM signatures upon delivery to your inbox. Google can just add in a tag in their database that says "this message was verified". Or at least make it an option for users if they want that ability. In the case of Podesta, the emails were stolen from his gmail account. If the headers weren't there, the messages would have been unverifiable.
- landryraccoon 6y agoWow. This blog post is appalling. I completely disagree with it. Consider this excerpt from the blog post: > But DKIM authenticity is great! Don’t we want to be able to authenticate politicians’ leaked emails? > Modern DKIM deployments are problematic because they incentivize a specific kind of crime: theft of private emails for use in public blackmail and extortion campaigns. An accident of the past few years is that this feature has been used primarily by political actors working in a manner that many people find agreeable — either because it suits a partisan preference, or because the people who got “caught” sort of deserved it. > But bad things happen to good people too. If you build a mechanism that incentivizes crime, sooner or later you will get crimed on. The author seems to be arguing that if after a certain point it becomes impossible to verify whether an email was genuine or not, that would somehow be a good thing. This reasoning seems harmful to me. It's incredible that the author treats this moral argument as self evident. Let me state my objections clearly. 1. The truthfulness and reliability of the historical record is important. The fact that politicians are protected from blackmail when they write incriminating emails is utterly insignificant by comparison. Is the principle being defended that protecting politicians from blackmail is stronger than a public interest in having a historical record? 2. Making historical emails impossible to authenticate after a certain period of time makes it more difficult to prosecute crimes. It helps criminals, the very thing the author claims to be trying to avoid. If a politician, or anyone for that matter, sends an incriminating email which is evidence of the intent to commit a crime, why on earth would you want to make it easier to cover your tracks? Seriously, can someone present a moral argument for why this should be adopted? It seems only harmful to me.
- fhrow4484 6y ago> 1. The truthfulness and reliability of the historical record is important. [...] Everybody agrees here, but how does one gets to decide that Google, a private corporation, is the one to decide that a given email is an accurate historical email? An email provider is a defacto certificate authority? Are these dkim keys subject to the same standard of care as private keys that CAs manage? For your regular-person scenario, having a way for a 3rd party private company "certify" an email sent from another private company (example: your online order) may be good enough, but is it good enough in every scenario?
- jmnicolas 6y agoI treat emails as postcards: I assume anybody can read them.
- gojomo 6y agoWe've backed into a particular default, more via path-dependencies than conscious choice, that: * emails between major email providers have this lingering semi-authenticity indicator that authors didn't explicitly choose * to the extent the providers keep their DKIM keys non-public, only those providers (or those who exfiltrate such keys) can forge old emails Both of these have problems if considered from 1st principles: * Users should be able to control if they're creating non-repudiable messages. * No one, not even Google, should have the power to create authentic-seeming forgeries. This article's author, Matthew Green, suggests rapid expiration & disclosure of DKIM keys to narrow the window of time the user is subject to a non-repudiation they didn't choose. (Green here only specifically requests disclosure of years-old keys to invalidate older message archives, but conceivably a rigorous expiration-and-disclosure schedule could be chosen to limit the risk to weeks or days.) And via public disclosure, Green intends to indirectly address the risk of privileged parties forging emails, by giving everyone the same power-to-forge older emails - so no particular forgery can be too convincing. But these new defaults are nearly as ad-hoc – reactive without conscious design – as the DKIM problem they purport to solve. Many would prefer that their emails, or at least some of them, be non-repudiable for a while or indefinitely. Many recipients would like to maintain their own private authenticity records – which as Green notes, can be bootstrapped into existence (even with rapid-expiring DKIM keys) by secure-timestamping messages & current DKIM keys at the time they're received. (To the extent Google & other providers have internally-trusted tamper-proof logs, they may already have de facto secure timestamping happening on all inbound/outbound email. Thus any amount of DKIM key fouling wouldn't stop their unique internal ability to authenticate older messages, for their own forensic or political purposes.) I'd prefer users be given some visibility into, and choice over, how much durable authentication is added to their email messages – before adopting either Green's quick fix (publish old keys ASAP), or defaulting all users to his potential longer-term solution of explicitly "non-attributable email" (per his KeyForge paper or other schemes).
- Paul-ish 6y agoThe piece seems to be arguing from a general principle. Repudiation is a feature of most secure messaging applications and it is a feature that should be introduced to GMail. This argument doesn't fully address how technologies are actually used today. As far as I can tell, people who need repudiation are already using apps that have repudiation (eg Signal), because they know they are in a vulnerable position. The people who need repudiation already have it. So far we have seen DKIM authentication used against individuals in positions of power. With things as they are, cryptography is leveling the playing field by empowering the vulnerable while holding those in power responsible. If this situation or balance were to change perhaps it would make sense to rethink DKIM non-repudiation. I understand this is an opinionated/political take on cryptography that not everyone would share.
- 867-5309 6y agoeven after spending countless hours configuring SMTP, SSL, TLS, SPF, DMARC, DKIM, IP address pools, white/blacklists, etc. there is still a 99% chance secure, authorised, authenticated, "signed", sealed email will be delivered to a spam folder so what's the point?
- 1vuio0pswjnm7 6y ago"The problem with DKIM is that no customers asked for this feature as a default in their commercial mail account." Two questions: Have there ever been any Gmail design decisions, e.g., default settings, where users were consulted first? I was recenty informed by another HN commenter that "99% of users" are "not qualified to have opinions" on something like MacOS behaviour,[FN1] or in this case Gmail behaviour. If this is true, should "99%" of users be given the choice not to use DKIM if they are "not qualified" to have an opinion on DKIM? 1. https://news.ycombinator.com/item?id=25100342 https://news.ycombinator.com/item?id=25100342
- creeble 6y agoThe problem with the author's paper is that his assumption (and that of, apparently, media organizations, Wikileaks, and others) of DKIM "ensuring non-repudiation of emails" is simply wrong. >DKIM provides a life-long guarantee of email authenticity that anyone can use to cryptographically verify the authenticity of stolen emails, even years after they were sent. No, it doesn't. It simply offers an assurance that, at around the time of sending, a given email was mostly likely sent from the server that signed it. It can't prove _anything_ about who actually sent it, because it can't guarantee the ownership of the email account. >For better or for worse, the DKIM authenticity stamp has been widely used by the press, primarily in the context of political email hacks. It’s real, it’s important, and it’s meaningful. There's no _better_ there -- only for worse. It would be better to dispute the validity of using DKIM for non-repudiation of emails than to propagate the lie and ask server operators to publish their expired secret keys.
- X6S1x6Okd1st 6y agoYour conceptions of what is good and bad are not everyone's. When a potentially important email dump is leaked individuals will use any reasonable means to gain information about it's authenticity. Knowing that DKIM headers are on those emails and that the service provider hasn't published those keys changes the question from: "Did you send this email" to "Was your email address compromised at this time?"
- creeble 6y ago> “Was your email address compromised at this time?" How would the accused sender be able to prove it was or was not? And is it his or her burden? Yes, individuals will use any reasonable to prove its authenticity. My point is that DKIM is not a reasonable means.
- X6S1x6Okd1st 6y agoFor certain scandals just losing control of an email address is enough to cause serious concern. Willfully admitting that control was lost could be a story in and of it's self. Email is not a reasonable means to conduct business, qwerty is a terrible keyboard layout, different countries driving on different sides of the road seems like a really silly thing to do. Just because something isn't reasonable doesn't really hold much sway when it comes to will people use it.
- deleted 6y ago[deleted]
- prvc 6y ago>it makes us all more vulnerable to extortion and blackmail This is true with the added proviso that, by "us", he means "the guilty". The rest are protected, on the contrary, to this very particular form of these crimes.
- zach_garwood 6y agoAdding a proviso to your proviso, "the guilty" here could include those guilty of being transexual, associating with undesirables, holding unpopular opinions, having mental health issues, or, ya know, having anything private they prefer not to be disclosed.
- flerchin 6y agoRepudiation doesn't seem to be desired by email users. Whether it's a valid encryption principle or not. The example crimes were not facilitated by this, but were merely verified. Had the DKIM keys been rotated, Podesta's emails would still have been stolen and leaked.
- ryanmarsh 6y agoThe persons used as examples for justification for publishing and rolling DKIM are exactly the kind of people whom I do not want to have the benefit of repudiation. If they did something bad, it's in the public interest to prove so.
- XCSme 6y agoIf anyone is interested, I recently wrote a short article about email verifying (DKIM, DMARC, SPF) after someone else used my domain name to send some not-so-nice emails: https://www.usertrack.net/blog/stop-others-use-your-domain-emails https://www.usertrack.net/blog/stop-others-use-your-domain-e...
- AntiImperialist 6y agoI agree with the author but would Google have reasons to keep a copy of the private key? Is it possible that they have deliberately destroyed it? P.S. This brought back memories. To anyone unaware of this, read about Pizzagate. You'll find that it has supposedly been debunked as a "conspiracy theory"... except for the emails which we know are legit.
- exabrial 6y agoI PREFER my politicians email to be unmasked. I don't care if it's Hillary or Donald. All of this should be publicly available in a democracy. Keeping the keys secret preserves history
- humanfromearth9 6y agoAm I the only one thinking that the issue comes from the fact that DKIM stuff is (I assume) inserted into the email's headers? DKIM is used for transfer of email, to make sure that the originating server is who it pretends to be. Shouldn't that be part of an envelope of the email, which would be discarded once the email has been received and its sending server verified and authenticated? Like for paper mail, one does _usually_ not keep the envelope (though I admit that there may be exceptional situations where it may be preferable to keep the envelope). -- In the interest of users (will most probably never happen), all incoming emails should be ignored and dismissed unless the recipient has explicitly specified that it accepts email sent from a given email address. Wouldn't this give the power back to the users?
- whatgoodisaroad 6y agoSo, if the old key is public, we can't use DKIM to verify any leaked emails that were acquired after the publication date? Sounds suspiciously like somebody's thinking ahead on how to plausibly deny some yet-to-be-leaked emails.
- hrishi 6y agoI've responded to a subcomment below explaining why "emails from politicians must be leakable" is not a good argument against the author's case. That said, I think this would be problematic on some levels not being considered. A good part of the world's email infrastructure is decentralized, and doesn't run on providers who update software well and often. If Google were to publish their keys after rotation, a new class of attacks could emerge where attackers could successfully forge authentic emails from Google that would look secure to an outdated provider. Nigerian prince 2.0 if you will. Decentralization is one of email's biggest strengths. I agree with the premise here, but I don't think the solution is to publish keys. Perhaps moving to a protocol that explicitly provides non-repudiation while keeping backwards compatibility would work.
- couchand 6y agoCan you point to any specific examples of systems that report DKIM signing status but fail to check the validity state of a DKIM signing key? That seems like an extraordinarily unlikely set of circumstances.
- zelly 6y agoHe should be complaining to the standards bodies. DKIM keys should expire like most other asymmetric cryptosystems. There will always need to be backward compatibility, but then it's your fault if you're using outdated software or not using a major mail provider (who would very certainly support the new standard). Directing this complaint to one company seems bizarre because most people who care about this kind of thing aren't using Gmail to begin with.
- oh_sigh 6y agoMeta: HN should enforce post size minimums on contentious topics like this. Basically every long post is a sincere perspective from the author trying to convey their viewpoint, and 9/10 of the short posts is reddit/twitter level snark like "Translation: You're a dictator-wannabe"
- 4bpp 6y agoI understand that the arguments both for and against the current DKIM regime are fairly nontrivial (should we analyse it as a loss of rights to the public (your past emails can be attributed to you) or a gain (you can hold the powerful to account)?), but either way, it seems that the only position that is consistent with the author's would be one that is enthusiastically in favour of improvement and proliferation of DeepFake technology. After all, we already live in a world where technology has created a novel form of attribution that could be used for blackmail: slightly over 100 years ago, nobody could prove or disprove that you said or did something in the past, whereas nowadays a video (given some pixel-level forensics) works as irrevokable proof positive.
- nanoscopic 6y agoWhat motivation would Google have to pay any attention to this request? The only one I can imagine is that Google wants to get some positive PR out of it. Other than that it seems to me like Google will just ignore this as they ignore anything else they don't see as in their benefit to exert effort on.
- h_anna_h 6y ago> And it happened again this year, when the recipients of an alleged “Hunter Biden laptop” provided a single 2015 email to Rob Graham for DKIM verification I contacted Bruce Schneier a few days back and he claimed that Robert Graham is lying and that this was fabricated, in addition that one is unable to establish the integrity and authenticity of a message by using DKIM. I personally think that if Bruce Schneier is wrong and one is indeed able to establish the integrity and authenticity of a message by using DKIM then it is useful for the one receiving the message to prove to others that the mail indeed came the one who sent them the message. Consider a harassing email or a promise for example.
- aaron695 6y agoHave most people here lost there mind? We are pro-fascism now? What right does Google have to force this onto us. If I want it, I'll chose it. The idea I consented because the information was there somewhere and I should have know the complexities is as BS as hidden terms and conditions. What annoys me is if you're pro fascism and want to force tracking onto people, just say it. But stupidity about how this isn't totalitarian is unforgivable. I have a right not to be tracked.
- compsciphd 6y agoDKIM's protection aren't as strong as people say they are (though fairly strong) 1) DKIM doesn't protect the To: header in any reasonable way (its not really designed to). i.e. it protects it in the sense that the original email had that as the To: header, but this is easy to forge as the To: header is not used by SMTP in delivery (think Bcc). i.e. its easy to write emails that are To: <some address> that are never attempted to be delivered to said address. 2) DKIM (even on gmail) doesn't quite protect the From: header as one would expect. Yes, gmail in general makes it difficult to spoof the email in the From header (it will replace it with your own if you try in the general case), but there's a huge but, if you gave gmail itself access to use that e-mail. i.e. I can be compsciphd@gmail.com but if billgates@gmail.com was convinced to allow me access to send emails as billgates@gmail.com (either via cooperation or a technical or sociological hack) then i can do that without having access to the account. and this permission is permanent. as far as I can tell, it irrevocable and to other gmail users there is no indication that other accounts have this permission for your email. so what do we learn 1) can't 100% trust DKIM to believe who an email was sent to unless you actually retrieved it out of said user's email spool 2) can't 100% trust DKIM to believe who actually sent an email (even on gmail) now, do I think DKIM gives anywhere close to 0% trust. No, I think its much closer to 100 than 0, but one has to understand the limitations and most people who discuss it, don't seem to understand them. the threat is a hack playing a very long game. If one doesn't view that long game hack threat as serious, then its close enough to 100% (especially if gmail rotates their keys even without making the private part public), but if a long game hack threat is a serious thing, then it drops.
- throwawayffffas 6y agoThe author underestimates how ready people are to believe slander. Publishing of DKIM keys will only allow people to produce more convincing faked emails. If a bunch of faked emails about a political leader signed with DKIM keys were released securities experts are going to say these keys are leaked and anyone could fake those emails but by the time they do the damage will have already happened and no one would be listening to them. The solution is not to release DKIM keys, but to make sure mails are not leaked. Throwing away signatures a few days after the email is delivered would not be a bad plan either, given they have actually served their purpose at that point.
- AntiImperialist 6y agoSo, when one sees a photograph, do people automatically believe it? Why aren't there photoshopped images of high profile people being published everywhere as slander? Because people know that photoshop exists. Similarly, if everyone knows that these keys have been released, people wouldn't believe slanderous email dumps. As I said in my other comment, I fear that Google may have securely destroyed the keys because of fear of it getting stolen.