3 ms·
Subhed and archive link: “Methods included cryptographic analysis, metadata analysis and corroboration with external sources.” https://archive.is/ETo2I https:/
by danso 1y ago
Subhed and archive link:
“Methods included cryptographic analysis, metadata analysis and corroboration with external sources.”
https://archive.is/ETo2I https://archive.is/ETo2I
Relates to this main story about the contents of Epstein’s yahoo email account (which is less technical)
https://www.bloomberg.com/features/2025-jeffrey-epstein-emails-ghislaine-maxwell/?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc1NzU4MTg1MywiZXhwIjoxNzU4MTg2NjUzLCJhcnRpY2xlSWQiOiJUMkYyQ0tHUEZIUUUwMCIsImJjb25uZWN0SWQiOiJGOEM4RUQ0NDZENzU0QjY2QUUwMzY4QzkzQjE4OEFEQiJ9.-WI92AWhRNCK_GFn6Fk_Su-tzVa2RIU9pSwno562y_4 https://www.bloomberg.com/features/2025-jeffrey-epstein-emai...
Don’t often see mainstream articles refer to Python libraries by name:
> Whenever emails included cryptographic “DomainKeys Identified Mail” signatures, or DKIM, in their headers, we used Python’s dkimpy library to verify that signatures matched their messages. A valid signature match is strong evidence that the message is genuine and unaltered, but a failed DKIM check is not, by itself, evidence of fabrication. Our analysis of emails from the years when DKIM was widely seen in the inbox (2013-2022) validated roughly 45% of the messages, rising from about 20% in 2013 to nearly two-thirds by 2020 as DKIM adoption broadened. For these messages we also checked DKIM-based DMARC identifier alignment—whether the DKIM d= domain aligned with the visible “From:” domain—and 55% of messages were aligned. We manually inspected the emails that weren’t aligned and found all matched to known mailing list providers and other similar services.