3 ms·
that's it. I'd think that if one attacks the sender, one could even do it without the purported senders cooperation could also cause it to happen. Now, especi
by compsciphd 3y ago
that's it.
I'd think that if one attacks the sender, one could even do it without the purported senders cooperation could also cause it to happen.
Now, especially because google rotates DKIM keys this would be such a long game attack that in my view, it's very improbable to be such a scenario.
- logifail 3y ago> [without] the purported senders cooperation Thinking about forging mail, in the case of senders who control their DKIM signing keys (me, for instance), if you have the sender's cooperation then you have access to their private DKIM key, can't you just sign any message you like? No need for the messages you're forging and signing to go anywhere near any email clients or mailservers at all.
- compsciphd 3y agoyes, for example, an insider at google could conceptually have forged a mail. just don't consider that probable. I think its more important to understand the limitations of what DKIM is telling us.