4 ms·
This came up with the hunter biden laptop, DKIM doesn't really validate that you sent an email, but that an email was sent through that server at some point in
by compsciphd 3y ago
This came up with the hunter biden laptop, DKIM doesn't really validate that you sent an email, but that an email was sent through that server at some point in time when said signing key was still being used.
i.e. I demonstrated to others that I could have a DKIM signed email sent through gmail that was from a spoofed from: and it passed all DKIM tests (i.e. telnet gmail smtp server 25 (well with ssl, so openssl connect or something). smtp auth and do the standard MAIL FROM "SoSo <so@so> RCPT TO so@so data...... and it will look like a legit mail sent from SoSo.
DKIM's job isn't to protect against that.
- sschueller 3y agoWasn't it also Hillary Clinton's emails that had DKIM and they denied that they wrote any of them? If that were the case it would mean someone has full access to that email system for years and sent all those emails through it.
- viraptor 3y agoLink? From what I remember, the details in that case where handed over in cooperation. Was there anything actually denied? There was only the issue around retention/deletion of emails, but even that didn't include a tech proof AFAIK.
- talent_deprived 3y agoAgreed, they may be recalling the Podesta emails: https://en.wikipedia.org/wiki/Podesta_emails https://en.wikipedia.org/wiki/Podesta_emails
- logifail 3y agoQ: If 2FA is enabled on a Google account, does SMTP AUTH still work? I've just tested this, I generated a new app password in my Google Account and used that to send Gmail from Python. Works fine when sending "from: <me@gmail>" with the app password, yet I can't change the sender since the SMTP auth then fails "5.7.8 Username and Password not accepted. Learn more at https://support.google.com/mail/?p=BadCredentials https://support.google.com/mail/?p=BadCredentials"
- dizhn 3y agoYou can set identities in gmail from which you can send emails. If it weren't gmail but a mail server you hosted, it would be even more trivial. Neither of these have to do with SMTP authentication. Without significant other configuration the mail server does not care what Mail From: address you enter. This is how my classmates were able to get emails from the US president back in the day.
- logifail 3y ago> You can set identities in gmail from which you can send emails Right, and there's a verification step in which you confirm you own (or at least control) the additional email address[es]: https://support.google.com/mail/answer/22370?hl=en-GB https://support.google.com/mail/answer/22370?hl=en-GB The OP appeared to be talking about somehow persuading Gmail into DKIM-signing an email from an address that wasn't theirs, though?
- dizhn 3y agoThe immediate parent?
- logifail 3y agoThe post (https://news.ycombinator.com/item?id=37723688 https://news.ycombinator.com/item?id=37723688) to which I replied, although perhaps I'm misunderstanding this bit: "I demonstrated to others that I could have a DKIM signed email sent through gmail that was from a spoofed from: and it passed all DKIM tests (i.e. telnet gmail smtp server 25 (well with ssl, so openssl connect or something). smtp auth and do the standard MAIL FROM "SoSo <so@so> RCPT TO so@so data...... and it will look like a legit mail sent from SoSo" I've tried several times to do what I think is being claimed here and I'm struggling. For instance, telnet to a public mailserver I control, SMTP AUTH with an account with relay permissions, MAIL FROM so@so, RCPT TO my own Gmail, refused by GMail due to so@so's DMARC policy...
- 3y ago