4 ms·
> but here in Germany I pay a couple of Euros every month to a well-known and respected company whose server is set up in such a way that my emails can be used
by devmunchies 4y ago
> but here in Germany I pay a couple of Euros every month to a well-known and respected company whose server is set up in such a way that my emails can be used in court without any issue (like claims that I altered the emails after receiving them)
That's already cryptographically built into email with DKIM. An email message is signed with a private key, and can be verified as authentic by the receiver using the public key in the sender's DNS records.
Click on "Show Original" in a Gmail mail to see the meta data.
https://en.wikipedia.org/wiki/DomainKeys_Identified_Mail https://en.wikipedia.org/wiki/DomainKeys_Identified_Mail
- woodruffw 4y agoWhile this is technically true, it's not a correct use of DKIM: DKIM is meant to provide authenticity for the receiving mail server (by verifying the message against a key associated with the sending server), not nonrepudiation for the sending user. Many email providers historically used short keys (RSA <512, and later 1024) for DKIM, meaning that lots of emails circa 2012 and older appear to be nonrepudiable but in fact are. Long-term authenticity of emails is very difficult and is arguably an anti-feature; Matt Green correctly observes[1] that Google should be rotating and publishing its DKIM keys regularly to prevent people from falsely concluding that a DKIM signature is "proof" of a message's authenticity. [1]: https://blog.cryptographyengineering.com/2020/11/16/ok-google-please-publish-your-dkim-secret-keys/ https://blog.cryptographyengineering.com/2020/11/16/ok-googl...