6 ms·
> The threat is not limited to politicians. Anyone (including you and your family members) could be blackmailed or otherwise publicly embarrassed. ... for wha
by hashtagmarkup 6y ago
> The threat is not limited to politicians. Anyone (including you and your family members) could be blackmailed or otherwise publicly embarrassed.
... for what they actually did.
You think the solution is allowing people to be blackmailed or otherwise publicly embarrassed for things they didn't do, while removing their ability to verify that they didn't do them?
- blendergeek 6y agoNo. Once DKIM keys are published, one can simply deny all emails published "from their account". We currently have a way for an attacker to prove an email's origin years after the fact.
- hashtagmarkup 6y agoYes. We are saying the same thing.
- daveFNbuck 6y agoYou're assuming no one has compromised the old keys. If that has happened, a blackmailer can forge old emails with proof of things you didn't do.
- mthoms 6y agoYou're misunderstanding how this works. You can't be blackmailed by someone who has no plausible evidence.
- beagle3 6y agoThey don’t have plausible evidence anyway. Gmail has had bugs before with SPF/DKIM and will have some again for sure. Some google employees have direct and indirect access to signing keys or writing emails. Not many, and they have good controls, but still many people with the ability to sign messages. Not to mention a Trojan infiltration or account takeover, of which thousands (if not millions) a day occur. The DKIM evidence is, for legal purposes, a good hint but far from proof.
- mthoms 6y agoIn the court of public opinion, the standard is not "100% proven beyond any reasonable doubt". Hence, blackmail can still be very effective if an accusation is highly plausible.
- beagle3 6y agoYes, but it’s not DKIM or not DKIM that will make it plausible in the court of public opinion.
- mthoms 6y agoCurrent events prove otherwise. See Hunter Biden.
- beagle3 6y agoI have not seen a single mention of DKIM w.r.t to Hunter Biden. Did you? Was any evidence presented? I couldn’t find any. I fail to see how admissibility or lack of it, in a court of law or of public opinion, has anything to do with DKIM+Hunter Biden. Can you elaborate?
- legolas2412 6y agoI saw this news (https://www.washingtonexaminer.com/news/cybersecurity-expert-says-hunter-biden-email-about-former-vp-meeting-burisma-official-is-authentic https://www.washingtonexaminer.com/news/cybersecurity-expert...) a few days before the election. There is also a github repo. I am not sure why the DKIM for all emails were not released, or why this did not catch more media coverage by other news organizations I consider more reliable (like NYT).
- beagle3 6y agoThank you for this link, this did not come across my radar. From your link: > The only way the email could have been faked is if someone hacked into Google's servers, found the private key, and used it to reverse engineer the email's DKIM signature, Graham, said. https://www.zdnet.com/article/google-fixes-major-gmail-bug-seven-hours-after-exploit-details-go-public/ https://www.zdnet.com/article/google-fixes-major-gmail-bug-s... is from Aug 2020 and discusses an SPF/DMARC vulnerability that was in Google since forever (and though reported 4 months before public disclosure, was fixed only 7 hours after public disclosure). The last google DKIM bug I'm aware of was in 2012, so I can't counter the specific claim about DKIM with evidence, but the assertion that "the only way to spoof x is to hack and get the private key" is not any absolute truth. (P.S: I have seen no denial nor confirmation about the authenticity of the Hunter Biden data - only claims of Russian involvement. Make of that what you will. The DKIM is circumstantial data until there is confirmation or denial - especially, as you say, it's not all released).
- hashtagmarkup 6y agoYou're misunderstanding how destruction of evidence works.
- mthoms 6y agoHuh? No one (including yourself), have mentioned anything about "destruction of evidence" so far. If you care to enlighten me about how it's relevant I'm happy to listen.
- hashtagmarkup 6y agoBy making the DKIM keys public, you are converting solid evidence of something that was said into something that was either really said, or someone else pretended that they said. Evidence was destroyed.
- mthoms 6y agoThis describes all encrypted and short lived messages. Edit: Removed the word "literally" because it was incorrect and caused distraction from the actual argument.
- hashtagmarkup 6y agoIt doesn't at all. You're misunderstanding. Or, are you using the word "literally" in the modern sense of "not literally"?
- mthoms 6y agoAre you just nitpicking my choice of words or are you going to explain how auto-disappearing messages aren't potentially destroying evidence in the exact same way you've described? As for encrypted messaging, yes it is not the same as "literally" destroying evidence. But it is hiding evidence (based on your logic). The end result is the same in the context of the claims you previously made. That is: justice is potentially being subverted.
- drdaeman 6y agoI'm afraid there's also a misunderstanding how the real world works. Cryptographic and real-world plausibility are two entirely different things. People get blackmailed, shamed, hurt and even killed over mere rumors, speculations and suspicions. As long as people believe in something (because something merely look plausible), there's no need for a fancy crypto to prove some machine sent some email. I'd dare to say most people don't even understand what cryptography is and what digital signatures really are (who signs what and what exactly this means). I'm yet to hear a story of, let's say, a brave dissident who got out of jail because of cryptographic plausible deniability property making their oppressors unable to prove authenticity of some leaked or intercepted correspondence.
- mthoms 6y agoRead up on the Hunter Biden emails. After a DKIM signature was verified, the perception of a large number of people (including right here on HN) went from "this cache of email is probably total fiction" to "they likely do have access to at least some of his emails".
- mschuster91 6y ago> ... for what they actually did. Being gay is not a crime, and yet people can be blackmailed with it. It is very easy to open yourself up to blackmail by perfectly legitimate activities.
- ivanhoe 6y agoTrue, there are things that might ruin someone's life even though there's nothing bad about them, but the list of actual crimes and bad things that people do is WAY longer, and being able to prove it is definitely useful...
- avianlyric 6y agoThe same argument can be used to build a police state. But I suspect that you’re not in favour that either. We shouldn’t be building technical systems that “trap” people, just because they might be doing something bad and might want to prove that one day. Additionally you’re also ignoring the whole “people have the right, to not have their emails stolen” argument. DKIM signatures are only useful if the emails are stolen, are you trying to suggest that it’s ok to steal emails from people if they’re bad?
- ivanhoe 6y ago> Additionally you’re also ignoring the whole “people have the right, to not have their emails stolen” argument No, just the opposite, that is an excellent argument and I think that the privacy should be the real focus when we discuss the freedom, and not the accountability. Because freedom is not to be able to get away for the lack of evidence, freedom is not to put innocent people in that kind of situation in the first place. Police state doesn't come from the ability to track citizens, it comes from the lack of transparency and government's misuse of the information. Now, reality is that having more data collecting increases the chances of misuse, but I think we're attacking the problem from the wrong side. Rather than killing the option to track emails, there should be much more control and transparency on when and how that data can be collected and used.
- bee_rider 6y agoPeople change over time, and normal human communications have a natural sunset as most people don't remember every conversation in exacting detail. It is worth at least considering the fact that we've signed up to have basically all our communications preserved and cryptographically signed in perpetuity. Most people using these services didn't fully weigh the options.
- cortesoft 6y ago> for what they actually did All blackmail involves things a person actually did... otherwise it would be libel or slander. You seem to be arguing that blackmail shouldn't be illegal.