3 ms·
Good point, I had forgotten that Rob of Errata Security was given an email to verify and it was proven to be legitimate: > So as I blogged before, the emails c
by Nacdor 6y ago
Good point, I had forgotten that Rob of Errata Security was given an email to verify and it was proven to be legitimate:
> So as I blogged before, the emails contained DKIM information, which the original reporters could and should have verified. So I eventually got a copy of the email and run DKIM verification on it. It passed:
https://twitter.com/erratarob/status/1322007153415200768 https://twitter.com/erratarob/status/1322007153415200768
I think he's pretty active (and well-respected) on HN.
- chalst 6y agoStrange that Rob doesn't mention the possibility that the private key was compromised. What the DKIM signature really proves is the date the message was sent, not who composed the message.
- edbob 6y agoI agree that is a possibility, but he probably didn't mention it because it's so remote. When you have someone's laptop with a bunch of private sexual photos, reams of PII and emails, and you can verify with witnesses and crypto that the emails check out, the rational explanation is "maybe the laptop is real" rather than "maybe Google got hacked six years ago and the extremely valuable private keys were saved for this". That is, I do agree with you and your technical analysis, but don't see the point of nitpicking his Twitter reporting. I think if you're on Twitter, you already know that you're not getting every little detail of a story.