Ok Google: please publish your DKIM secret keys
blog.cryptographyengineering.com
blog.cryptographyengineering.com
It seems to me that especially when an elected official has something they don't want others to know about that it should be public knowledge.
After all an efficient marketplace only is efficient if all actors have access to as much information as possible.
EDIT: As a follow up, several people point out that it could happen to me or a family member, but this seems even further reason to have DKIM so that if someone attempts to blackmail me based on the contents of my email, checking the DKIM signature makes it even easier to disprove a bad blackmail attempt.
... for what they actually did.
You think the solution is allowing people to be blackmailed or otherwise publicly embarrassed for things they didn't do, while removing their ability to verify that they didn't do them?
You can't be blackmailed by someone who has no plausible evidence.
Some google employees have direct and indirect access to signing keys or writing emails. Not many, and they have good controls, but still many people with the ability to sign messages.
Not to mention a Trojan infiltration or account takeover, of which thousands (if not millions) a day occur.
The DKIM evidence is, for legal purposes, a good hint but far from proof.
I fail to see how admissibility or lack of it, in a court of law or of public opinion, has anything to do with DKIM+Hunter Biden. Can you elaborate?
I am not sure why the DKIM for all emails were not released, or why this did not catch more media coverage by other news organizations I consider more reliable (like NYT).
From your link:
> The only way the email could have been faked is if someone hacked into Google's servers, found the private key, and used it to reverse engineer the email's DKIM signature, Graham, said.
https://www.zdnet.com/article/google-fixes-major-gmail-bug-s... is from Aug 2020 and discusses an SPF/DMARC vulnerability that was in Google since forever (and though reported 4 months before public disclosure, was fixed only 7 hours after public disclosure). The last google DKIM bug I'm aware of was in 2012, so I can't counter the specific claim about DKIM with evidence, but the assertion that "the only way to spoof x is to hack and get the private key" is not any absolute truth.
(P.S: I have seen no denial nor confirmation about the authenticity of the Hunter Biden data - only claims of Russian involvement. Make of that what you will. The DKIM is circumstantial data until there is confirmation or denial - especially, as you say, it's not all released).
I am not insinuating any wrongdoing from anyone, just bringing it to your attention, as you claimed to not know about it.
But it does support my thesis that DKIM or no DKIM is not what gives (or doesn't give) any credence to the authenticity (or lack of it) -- here we have a high profile case, with DKIM validation (which a lot of people on this thread cleim "is considered proof by people who don't understand it") and it seems to make no difference even in the court of public opinion - those who accepted it, accpeted it without DKIM, and those who rejected it as russian disinformation, rejected it even with DKIM.
You really couldn't find any? Come on. Did you Google "DKIM Biden"?
I've read literally hundreds of pieces on the hunter biden laptop, about half of them from republican leaning outlets, (I try to keep a balanced diet....) and none of them mentioned DKIM validation.
(For the record: I don't live in the US, I don't watch television, but I do try to keep a balanced news diet)
Evidence was destroyed.
Edit: Removed the word "literally" because it was incorrect and caused distraction from the actual argument.
Which is very distinctly different from a passive act of not maintaining evidence of the origin of every single thing. Keep in mind that no data is altered - the equivalent of all collected samples remaining intact.
It's still just as possible to collect email logs, their contents do not magically dissappear. They would have to be actively manipulated by the party which holds the copy that would be provided to the police (either reported to them or confiscated, etc). That same party could already decide to delete the emails or strip signatures and then alter them.
People get blackmailed, shamed, hurt and even killed over mere rumors, speculations and suspicions. As long as people believe in something (because something merely look plausible), there's no need for a fancy crypto to prove some machine sent some email. I'd dare to say most people don't even understand what cryptography is and what digital signatures really are (who signs what and what exactly this means).
I'm yet to hear a story of, let's say, a brave dissident who got out of jail because of cryptographic plausible deniability property making their oppressors unable to prove authenticity of some leaked or intercepted correspondence.
Being gay is not a crime, and yet people can be blackmailed with it. It is very easy to open yourself up to blackmail by perfectly legitimate activities.
We shouldn’t be building technical systems that “trap” people, just because they might be doing something bad and might want to prove that one day.
Additionally you’re also ignoring the whole “people have the right, to not have their emails stolen” argument. DKIM signatures are only useful if the emails are stolen, are you trying to suggest that it’s ok to steal emails from people if they’re bad?
No, just the opposite, that is an excellent argument and I think that the privacy should be the real focus when we discuss the freedom, and not the accountability. Because freedom is not to be able to get away for the lack of evidence, freedom is not to put innocent people in that kind of situation in the first place.
Police state doesn't come from the ability to track citizens, it comes from the lack of transparency and government's misuse of the information. Now, reality is that having more data collecting increases the chances of misuse, but I think we're attacking the problem from the wrong side. Rather than killing the option to track emails, there should be much more control and transparency on when and how that data can be collected and used.
Option 1: DKIM keys stay private... "That email was just a joke, I'm not really gay" Option 2: DKIM keys go public... "That email was just someone else's joke, I'm not really gay"
Not really a difference, and with option 2 you can't prove you didn't send it (as far as you can prove someone didn't crack 2048 bit RSA and use that power to concern themselves with your sex life).
Being able to prove a fascist dictator who was killing people for being gay, was secretly engaging in gay acts themselves, might help your cause of protecting gay people.
How?
If the keys were public, they could claim forgery. Regardless they could claim their account was hacked, but they couldn't deny the message was sent from their account.
All blackmail involves things a person actually did... otherwise it would be libel or slander.
You seem to be arguing that blackmail shouldn't be illegal.
He mentions the politicians because those were high profile cases. This could be used against anybody, not just politicians.
> It seems to me that especially when an elected official has something they don't want others to know about that it should be public knowledge.
Is this true of everybody else as well? Should anybody be able to deny an email they sent in the past? If so, we have to take this step.
Dear Ivanhoe,
I regret to inform you that your HIV test came back positive. Please contact my office at your earliest convenience to arrange a follow up.
Sincerely, Your doctor
Even if this example is imperfect, it's really not that hard to imagine a scenario where some type of compromising information is sent to you. Perhaps even accidentally.
"Hey Ivanhoe, your buddy from government here. That thing that we discussed, no problem I arranged everything, T says it's cool, just wire us the money and the project is yours."
In my view, if someone is going to blackmail me for some sensitive topic like being HIV positive or dox me in revenge, solution is not that I have to go public and lie that it's not real (and risk to be counter-proven it is) - but to have police put their blackmailing asses in the jail. That's the type of protection of my freedom and privacy that I hope for.
And in the end, who has ever believed people doing public denials? Once the word gets out, by the time you publish the rebuttal majority of folks will already have an opinion on it and that will stick with you for long time no matter what you say later.
Email is global. You and I are in privileged positions regarding access to capable law enforcement. We're also privileged with what our societies deems acceptable. We are the exception, not the rule.
If you're only thinking about how it affects you and what remedies you would have, then you clearly aren't looking at the big picture.
>the solution is [...] to have police put their blackmailing asses in the jail.
But now, you're saying you don't have meaningful access to law enforcement (in this context). So, why did you suggest a solution you know isn't viable? I don't get it.
To my mind, you've just made a strong argument for publishing DKIM keys since you readily admit law enforcement cannot tackle the blackmail problem. Indeed, even in countries with "good" law enforcement, they can't reasonably tackle it since the blackmailers almost always come from overseas (or are un-traceable).
B) Even though it's not viable for me to do anything to someone in Russia or China or even US for leaking my data, I see that as the only proper way to address this type of situations. If it's not possible now, then we should concentrate on fixing it and making it possible, instead of trying to lessen the impact, but at the same time helping those same blackmailers to easier hide their own steps (and a bunch of other shady characters who'd rather not be linked to their emails, from pedophiles to corrupted politicians). And also I don't see denying as a reasonable move here, as it comes down to basically lying publicly about the origin of your data and can just get you deeper in the trouble, especially if you're in any sensitive position and there're people out there actively looking to dig your dirt. AFAIK all PR handbooks on damage control say the same.
People change over time and normal human communications have a natural sunset built in as people forget exactly who said what.
It's true, but I'm not sure it's as good thing as you believe. I was born in communism, and then later I lived through the transition and have seen many people use this exact mechanism that you mention to whitewash their biographies. People just don't remember long, and thanks to that all of the sudden everyone was a victim of the regime who fought for democracy, while in fact they were exactly the opposite. Many bad people not just got away, but also gain significant benefits thanks to "people forget exactly who said what" and it did a lot of damage to my country and the society. So, while people do change over time, and we all sometimes have said something stupid that we didn't really mean, IMHO as adults we all should stand behind the things that we say and hold accountable to at least some level for it.
And to protect people from other's misusing their past, perhaps it would be more beneficial to educate the crowd not to be overly judgmental and not to jump to conclusions like everyone on soc. medias just loves to do - rather than forcing individuals to lie about their past to defend of blackmailers.
Stuff like revenge porn already exists. Let's not make the problem worse.
For example, I have servers that DKIM sign emails. If a person uses my servers to send a death threat, the FBI is going to want web access logs and smtp logs.
Or factored - Debian had a bug 12 years ago that caused weak SSH keys, a similar thing could happen to DKIM key generation (or has happened, but not yet discovered).
Some study showed many RSA keys in the wild had a common factor. A weakness of this family might be discovered with DKIM keys.
It is supporting circumstantial evidence, not proof of identity.
I think his point is that the DKIM signatures could be used to verify that you did, in fact, send something worth being blackmailed over, rather than having the plausable deniability of saying that your DKIM private key from that period is already public and thus could be forged.
Which, to me, sounds similar to the classic XKCD "Theoretically, I use 2048bit RSA encryption and the hackers can't get my data. In Reality, they just beat me with a hammer until I give up the password." Maybe a public DKIM argument would hold up in court, but if we're just talking reputation blackmail among family and friends, it aint it chief.
I don't think Matthew Green is arguing against transparency. What he's observing is that non-repudiation is an unintentional byproduct of DKIM's design. Because it's a byproduct, DKIM's users have made implementation decisions that make it susceptible to weaknesses in the unintentional non-repudiation property.
By 2030, a motivated nation state will probably have the ability to crack the 2048-bit RSA keys that Google is currently using for DKIM. Do you really want someone in 2031 to be able to contrive fake signatures for the emails of politicians in 2021?
Except that we're talking about leaks of emails that date back by years: the earliest Podesta emails are from 2010, back when Google was using 512-bit (!) keys for DKIM. Those were leaked in 2016, at which point 1024-bit keys were already considered crackable by a motivated attacker.
This isn't to say that those emails were faked, only that "an email written in 2020 that's verifiable in 2020" is not the target of interest.
The DKIM signature is proof only that whoever signed the email possessed the key, nothing more, nothing less. This, in turn, is a suggestion about the identity of the signer and possibly the author - but not proof.
Did DKIM change anything about the podesta emails? Or were they basically acknowledged as authentic regardless, and had a lot of other verifyable info in them?
Both journalists and investigative groups (and conspiracy theorists) treat DKIM as a sign of authenticity, even when the key material is long past its prime. Wikileaks still prominently displays a "verified" marker next to their archives.
> Did DKIM change anything about the podesta emails? Or were they basically acknowledged as authentic regardless, and had a lot of other verifyable info in them?
That's hard to say, but it's also not the point. The point with being able to crack the key is that a motivated party could intersperse false information with otherwise verifiable information. And, well, what's a conspiracy theorist to do? Only believe the non-juicy parts?
Yes, journalists verified it. But they consider it supporting data, just as they wouldn’t automatically ignore any email that had no DKIM signature.
Phone calls are never authenticated. Does anyone automatically believe or disbelieve recorded phone calls?
I mean, “conspiracy theorists” (in the common usage of that terms) already believe only what they want to believe.
I think the point boils down to expectation management: journalists (and ...) barely understand non-repudiation, much less why each of the following scenarios pans out:
* 2006 email + 512-bit RSA, leaked in 2006: probably authentic
* 2008 email + 512-bit RSA, leaked in 2012: potentially inauthentic
* 2008 email + 1024-bit RSA, leaked in 2008: probably authentic
* 2008 email + 1024-bit RSA, leaked in 2016: potentially inauthentic
...and so on. In sum: we're making life harder for the people doing real investigative work (since they're not technical), and we're giving fodder to the people who want to conspiracize. All because we're using a spam mitigation technique to provide properties that it was never intended to provide.
The wrong solution is to make previously private keys public to make any reasoning about past data impossible in the name of “hut journalists might get a wrong impression”
And yet, the deepfake equivalent to the suggested solution is one of "start showing deepfake as news" or "stop showing any video as news", neither of which anyone would consider a reasonable response to deepfakes. I just don't understand how DKIM is suddenly so revered as truth when almost no one knows what it is.
The point is that DKIM can be abused to lend undue credibility to falsified data... not that it can credibly attest true data.
These is absolutely no way you're going be able to educate the general public on the nuances of this. I mean, there are lots and lots of people who doubt the efficacy of vaccines and masks...
So can deep fakes. What makes deep fakes explainable and DKIM unexplainable?
If the journalists interests do not align about DKIM, how come they align about deepfakes?
I'm not saying journalists have any integrity. I'm just wondering why specifically for DKIM a "throw the baby out with the bathwater" solution is advocated, whereas for things like deep fake it isn't -- where the underlying truth is the same: "You can't trust what you see/hear".
Regardless, the fact that deep-fakes exist has absolutely no impact on whether DKIM has problems or not.
I have pointed out that in a similar case (potentially fake evidence), same actors (journalists) seem to have completely different incentives than those you hold so self-evident and I ask for an explanation of the difference - why is it so self evident that journalists have an incentive to not understand DKIM and not inform about it, but the same is not true of another concurrent challenge to evidence authenticity.
To me it sounds like you’re saying “journalists eat cotton candy because they like sweets, but they don’t like chocolate because they care about their teeth”. They might have this preference among cotton candy and chocolate, but the explanation is inconsistent and likely wrong.
I don't want a nation-state to be able to contrive fake historical signatures for my own emails.
DKIM without rotation and disclosure provides the capacity to do so with cryptographically provable integrity. Green's paper lists instances in which this has happened (as a proof-of-concept demmostration of the risk), and may have happened.
DKIM key rotation and public key disclosure at least denies adversaries this.
How could it be used for that purpose then if it’s proven to be unreliable?
It would seem that there’s more to gain in the short-term by those that have hacked Gmail accounts by exposing this, so it seems disingenuous, which you have to know, so it seems like people are fake-goading Google, causing others to actually goad Google, maybe to try to expose those that have hacked Gmail...
Pretty sneaky sis!
The distinction is in removing any doubt as to reliability.
By this logic, what the article is arguing for is to bring that same truth today: if DKIM no longer offers the same guarantees, but people think that it does, than it can trivially be used to forge emails that people will then wrongly trust, which is obviously worse than the status quo.
Of course, the more likely result is what the article suggests - if the scheme can be defeated, people will stop trusting it, and there will be no chance of forgery (at least not for very much longer).
In fact, it does not authenticate any emails without a corresponding public key currently published to DNS. It provides specifically for "empty" or revoked keys to avoid such retro-validation.
Seems the central thesis is that because these messages are patently no longer authenticated by DKIM, we should eliminate any remaining hope of them being construed as authenticated by DKIM.
The way to have transparency into politician’s communications is to require them by law to be made public, and to use law enforcement to make sure that this actually happens. It seems that relying on information going over email (as opposed to eg signal), and getting hacked (perhaps you want it all hacked, perhaps you are more happy while it is the side you don’t like getting hacked, either way I think one must acknowledge that by focusing on what is hacked, one is granting those hackers great control of the narrative) is not really very useful.
For local politics this would expose the haggling/threats/backdowns not good for image making very hard to make deals
For international, how do you expect this to work when a politician is getting briefing Or guidances or heads up about dealing with an dictatorship or a unfriendly global power or an foreign company ?
Perhaps have a classification system ? Then everything will be secret classification
What I think is most shocking in this age of political hacks and leaks is the fact that people are outraged by it when it’s their side. Sure, the timing can be unfortunate when it harms their chances of re-election, but I’m surprised that I hear more about that, and calling it election interference, than I do about the actual contents of the leaks. Don’t like it when your side’s dirty laundry hurts their campaign? Solution: nominate candidates with less dirty laundry.
This has nothing to do with “blackmailing public officials” and for you to imply that I have such a desire is both uncivil of you to say here and says a lot about your world view. Blackmail is when you use evidence of illegal activity in order to coerce someone to do something against their will. Transparency and audit ability of our public servants is not blackmail.
One key flaw in your argument is that you seek a system that works, "even if they have gone rogue and used non-government-approved communication channels", which, it should be plain to see, absolutely does not apply to DKIM.
I perhaps read a bit too much into your statement, "Blackmail related to embarrassing sexual proclivities or anything like that is unfortunate, but kindly asking politicians to be transparent isn’t a realistic answer."
Email and associated protocols apply to everyone, public-individual or private. The same technology works whether you're a politician or an ex-girlfriend.
I also agree with your parent, if there is something we need politicians to do, it needs to be a law that makes explicit what the intended outcome is, rather than hold up an unintended consequence of a protocol feature as "good enough", especially when there's potential for collateral damage.
In fact, none of the examples in the article were from people up for election.
"Everybody who uses Gmail" includes a lot more private citizens than public officials.
The purpose of DKIM is to help prevent spam, not to verify the authenticity of the sender.
No matter what you think about politicians, it is a failure of cryptography, or perhaps our common application of it, that the signatures we use to assure our conversation partner of our identity can also be used for our conversation partner (or divers third parties) to prove what we said.
Compare https://en.wikipedia.org/wiki/Off-the-Record_Messaging which solved this problem quite a few years ago. Off-the-Record Messaging allows your conversation partner to know that they are talking to the real you, but does not empower them to prove that to anyone else.
> This is an amazing resource for journalists (...) But it doesn’t benefit you.
If it's an amazing resource for journalists it benefits me.
Even google didn't bother to rotate their DKIM keys as recommended by the standard, so one wonders if the google keys are stored in a cage guarded by lasers and dogs or if there are copies on someones laptop somewhere and any sysadmin with a gambling problem or a secret affair could have leaked them to an unscrupulous journalist or a spy.
That specific e-mail does not have DKIM signature (maybe because it was sent his own gmail address? or to an gmail address in general?).
I am aware that even if they publish the DKIM secrets, these e-mail will not lose any value since these e-mails was posted before the secrets.
But I think using e-mails as evidence should be a thing in general. As you could receive them to your personal e-mail server and want to authenticate and use it on a court, even years after. If they publish the keys, it would not be possible as you could be the one who forged the e-mail as it were received from somebody else and has been put to your IMAP server manually.
At least these e-mails are believed to be true in other countries. So does Authenticity of thes e-mails can easily help you when you seek asylum in country from a country where they declared you as a terrorist - internationally.
In messaging cryptography, non-repudiability has for almost 2 decades been considered a vulnerability, not a feature. The OTR protocol[1] takes the step of publishing its used MAC keys --- it releases private key material! --- to ensure that random people can forge messages once participants have authenticated them. Signal came up with a novel deniable AKE[1] that is one of the more famous parts of the protocol; by design, you can forge a Signal conversation from someone's private key even if you've never talked to them before.†
When you think about it in the abstract, it's easy to understand what's going on, even if you don't take the time to read the OTR paper. Once counterparties have authenticated each others messages, authentication has served its purpose. To allow a stranger to authenticate a messages is to concede information to them, and avoiding concessions is the point of messaging cryptography.
If you believe non-repudiable messages are necessary for public policy, it's hard for me to understand how you'd support the rest of secure messaging. Most secure messengers also have "disappearing messages", which have an even more powerful impact on the public's ability to read your (or some disfavored other's) messages. In fact, keeping the public from reading stuff is... kind of the obvious point?
Maybe it's just email, and the belief that email should not just be insecure, but be deliberately insecure? But, you all get how weird it is for me to read that after getting yelled at for writing a blog post about avoiding secure email, right? 547 comments[3]! Many of them very angry!
[1]: https://otr.cypherpunks.ca/otr-wpes.pdf
[2]: https://signal.org/blog/simplifying-otr-deniability/
[3]: https://news.ycombinator.com/item?id=22368888
† I'm always looking for this triple-DH blog post and never able to find it, because it doesn't contai the word "triple", and it never occurs to me to search for "deniable", only "repudiability" (which also doesn't occur in the blog post) so I guess I can thank this thread for fixing my bookmark.
They're more likely to ask their expert witness to testify about the evidence, and the deniability of the DKIM signature could be brought up by the expert witness as a reason to distrust the evidence. I wouldn't expect lawyers to discover this argument from first principles.
Has it ever happened? Not that I know.
https://en.wikipedia.org/wiki/Trojan_horse_defense#Cases_inv...
I'm sure defense lawyers would love it :)
A serious argument against deniable messaging would start by acknowledging deniability as one of the shibboleths of the field of messaging cryptography, and then tackle the idea. Nobody on this thread has done that, and I think the reason why is that they're simply not aware that there is such a field.
And not being a politician, and certainly not the one currently trying to hold the White House hostage, I don't see the public interest anyway.
If you think White House emails should be signed and archived indefinitely, that is one thing. That is not what we are talking about.
All private conversations shouldn't be published. That isn't necessary to hold people accountable for dangerous or violent speech.
Publication and repudiation aren't the same thing.
Yes, it might make it harder to punish death threats, but privacy is too important to sacrifice.
Mail being secure from surveillance is a foundational freedom.
I have no idea where you are getting the idea that we all should have to answer for what we send in private correspondence.
This discussion about DKIM is about non-repudiation and the ability to prove that a certain person sent the email.
If you send me a letter, I (or someone else who gains possession of that letter) should be able to prove that you sent the letter and hold you accountable for the contents. DKIM does that for emails.
Too, it's easy to imagine not knowing you need proof until some time after you receive an email.
If it isn't usable and enabled by default, it won't be used in practice - for the same reason almost nobody uses PGP.
In fact, it's quite common that the issue over unsigned documents in court is the interpretation, not authencity.
I think the issue of having to teach users how to opt in to signing emails in potentially controversial cases is preferable to having to teach them how to handle email communications that are permanently provable (for starters, never ever again leave out a quote and never ever write ambiguously).
If you got an email that warrants "holding someone accountable", you would have plenty of time before the keys are released. So if you receive an email and call the police, nothing would change.
What you couldn't do it save it for years and keep it as blackmail material / until it's politically opportune to use. Of course it's not as clear cut as that, and an email may look harmless at the time, and only later, with more context, you might realize it contains evidence of misdeeds. So even a good faith actor might unknowingly sit on evidence.
Whilst I agree with you that email messages should be repudiable , I have a feeling you're trying to pass something off as axiomatic that isn't. For example isn't a confidential business agreement basically exactly, by design, an authenticated non-repudiable message that can be authenticated by third parties (such as courts)?
And they have much better mechanisms than DKIM available which they should use instead.
In fact, with reliance on DKIM you create the distorted incentive that one company might want to fake getting hacked to claim an email they sent is not authentic.
As a matter of fact, they might even be so sneaky as to send individual emails without DKIM signatures, with a policy set for the recipients to not reject those emails. Since most email clients do not display this discrepancy in a lack of a DKIM signature, the recipient might not notice and then the sender can later claim forgery.
So then let's not rely on something so unreliable if you need reliable authentication.
On one hand we have the Utilitarianist view of security. If increased security results in "more good" than evil, it is inherently ethical and thus acceptable. In this view, the idea that a good person may be blackmailed is perfectly acceptable, as long as it exposes political malfeasance.
On the other hand there's the Kantian view. If you have to lie, it it hurts someone, or it wouldn't work if it applied to everyone, then it's unethical. This doesn't seem to work at all, because we have to allow lying (non-repudiation). But non-repudiation could prevent someone from being hurt. And applying it to everyone would allow for the least harm, rather than the most good.
In the end Utilitarianism usually reigns because it's easier. But it does ignore the edge cases, which we should consider. Perhaps the way forward is not to pick one or the other, but actually re-make the world to embrace the good and avoid the bad. Sadly, that's probably the most difficult choice of all; when's the last time we replaced a working standard just because it had crappy outcomes?
Non-repudiation is of course a needed property for many systems, but it is not a property a system, especially an everyday messaging system like email, should have by accident - even "weak" non-repudiation such as DKIM. It is a violation of privacy. The suggestion the author makes of course doesn't completely get rid of it, but at least makes it time-limited.
Obviously the conflation of a bunch of different use-cases into this one protocol is a problem, but I don't know that just making email more secure is a solution.
>DKIM provides a life-long guarantee of email authenticity that anyone can use to cryptographically verify the authenticity of stolen emails, even years after they were sent.
No, it doesn't. It simply offers an assurance that, at around the time of sending, a given email was mostly likely sent from the server that signed it. It can't prove _anything_ about who actually sent it, because it can't guarantee the ownership of the email account.
>For better or for worse, the DKIM authenticity stamp has been widely used by the press, primarily in the context of political email hacks. It’s real, it’s important, and it’s meaningful.
There's no _better_ there -- only for worse. It would be better to dispute the validity of using DKIM for non-repudiation of emails than to propagate the lie and ask server operators to publish their expired secret keys.
When a potentially important email dump is leaked individuals will use any reasonable means to gain information about it's authenticity.
Knowing that DKIM headers are on those emails and that the service provider hasn't published those keys changes the question from:
"Did you send this email" to "Was your email address compromised at this time?"
How would the accused sender be able to prove it was or was not? And is it his or her burden?
Yes, individuals will use any reasonable to prove its authenticity. My point is that DKIM is not a reasonable means.
Willfully admitting that control was lost could be a story in and of it's self.
Email is not a reasonable means to conduct business, qwerty is a terrible keyboard layout, different countries driving on different sides of the road seems like a really silly thing to do.
Just because something isn't reasonable doesn't really hold much sway when it comes to will people use it.
It is not difficult for me to believe a Judge could find it "unlikely" that a 2013 email was forged containing a valid Google signature, and I would not want to rely on you being on my jury. If Google were to publish their private keys, I could produce a forgery of my own in my defence.
Of course it would be great if people were smarter than they are, but they're not, and I wrote some perl today, so it is hard to tilt at this particular windmill.
Lets just say it. The emails that sparked all this are looking for something that simply isnt there. They see what they need to see to fit a world view
Not on it's own, but it's a critical step in this chain:
1. DKIM verifies that a message was sent by Gmail.
2. We assume Gmail is careful with its keys.
3. We assume Gmail doesn't forge addresses.
4. Find evidence that links me to that address.
Most people will readily grant #2 and #3. Now we just need #4, which can be easy.
No, it's not cryptographically verified end-to-end, but it's good enough to convince a court or to convince a respectable news organization to run a story.
1) it seems unlikely this cryptographic proof is needed (he acknowledges this criticism in the post), and
2) what seems more likely to me is that politicians would intentionally _not_ opt in to any alternate solution and use that deniability for their own advantage. (Also as an alternate he proposes GPG, which I know Matt knows is laughable).
Regardless of if your emails are valid or not, blackmail is still a crime. Not being able to have your emails validated doesn't protect you from blackmail. The power of blackmail is often in the social cost of the accusation itself. The thing that protects you from blackmail is not getting involved in things you can be blackmailed for.
This is like saying don't lock your doors so that nobody can break and enter into your house.
This is incorrect, because the things that someone can be blackmailed for is not the same as the set of immoral or unethical acts. You can be blackmailed for being gay, or for having a serious medical condition that's undisclosed. Neither of those situations is a "well just don't do that" kind of thing.
The defense against blackmail is to make blackmail difficult (eg release DKIM keys), severely punish people who engage in blackmail, and guard your secrets effectively.
> This is like saying don't lock your doors so that nobody can break and enter into your house.
This is like saying the latch on your fence is a security mechanism. Nobody intended that fence latch to keep your safe or secure and hiding behind it won't make you safer. Rip away the false pretense.
Shouldn't we privilege protecting people from lies vs protecting people from the truth?
Publishing the DKIM keys makes both cases harder because you no longer have authenticity claims. Neither claim has authenticity value and instead is just a "their word versus yours" situation.
Humans are terrible moral adjudicators, and acting off of universals leads to repugnant ends. The truth can absolutely do terrible damage and still be the truth, but being the truth doesn't remove value from privacy. Put another way - would it be moral to publish your full medical records in the public? After all, they are the truth...
If you live in one of those countries and secretly a homosexual, do not send emails indicating that you're a homosexual.
You wouldn't tape your key to your front door.
So far as I can tell this has never happened in history and logically neither blackmail nor public harm via exposure of sexual orientation particularly requires dkim verification.
It looks like you are asking us to give up DKIM verification which could and has aided us to verify politicians leaked emails in search of a purely hypothetical gain that may never materialize by suggesting that we both must and must not make moral determinations.
Indeed! I couldn't have put it better myself.
Do you send your social security number to people in emails?
Email has never been privileged communication and the problem isn't one of validation but one of not understanding one's level of privacy and risk. It uses relays without end-to-end encryption and there's no guarantee that what you sent is not totally out in the open.
If your doctor slips up and emails you about your AZT prescription, it doesn't matter how careful you were about not disclosing your HIV status over email you sent.
with criminal repercussions
Or better: don't use email and don't give an email address out to people who hold your secrets.
Not everyone is tech savvy. Not everyone understands encryption. Not everyone makes rational choices all the time.
Does that mean everybody should suffer the consequences of an arguably unintentional side effect of the technical implementation of DKIM?
> Does that mean everybody should suffer the consequences of an arguably unintentional side effect of the technical implementation of law?
Thankfully this is not law, but people should understand the things that can get them in serious trouble. A lot of legal concepts follow from basic principles and history.
Privacy concepts are the same way. It's simply not sufficient that we don't educate everyone about these things anymore. Ignorance isn't going to protect anyone from the fallout of misuse of technology.
The solution isn't to coddle people, it's to provide better technology that does the thing the way people intend to use it.
Being able to say "no I didn't say that" is far more powerful than the reverse because the reverse has existed for thousands of years.
But being able to definitively prove that you did not say something is brand new and very powerful.
The problem is that what is socially and legally acceptable changes over time. Just 30 years ago, the standard for social acceptable commentary was wildly different in the areas of gender identity, sexuality, and race for instance.
Yes, you might be totally fine now. You might be hanging out and get photographed with this creepy billionaire named Jeffrey Epstein who is just another creepy billionaire at your creepy billionaire parties. Then 20 years from now we find out he's running pedophile island and people start looking into your associations.
We are not teaching people to be cautious about their public data and in fact there's an entire industry out there encouraging everyone to detail their whole lives in public record.
Get off of social media _today_. Yes, it's probably too late. The other option is to be such a big celebrity that your entire life is public and you have the defense of scrutiny.
Side note: Somebody from my high school class is a famous criminal. I regularly receive requests for interviews on the basis of that association alone despite having nothing to do with the person for decades.
Why not use more neutral examples? Like being gay or supporting certain political causes? What if those later become controversial or illegal? What then?
Do you want to live in a world where you have to guard everything you say in semi-private conversations, just in case it one day becomes controversial? That sounds like an oppressive nightmare.
The social media argument is tangential but I do agree with you there.
I'm illustrating the severity of the identifiable public record. When the Nazis started rounding up people to put in camps, they looked at the _extremely detailed_ Christian Parish records saying who was what and where they lived.
They were thought to be innocuous and important records to keep at the time. Actually I think in the Scandinavian countries the state Church is still responsible for recording all marriage & death records. They stopped tracking births for the previously mentioned reasons. (Hey, we just learned the importance of separation of Church and State, too!)
Nobody knows how important privacy is. Until they do.
This is an argument in favor of emails being non-verifiable, so now I'm confused.
Previously you seem to be supporting the idea that email should be verifiable. Now you seem to be arguing the opposite. Everything you wrote above correlates with the opinions I've expressed so far.
You also wrote:
> If you live in a [country where homosexuality is illegal] and secretly a homosexual, do not send emails indicating that you're a homosexual.
As if that's an acceptable state of affairs and a reasonable compromise for the purpose of catching the occasional bad actor. It isn't.
a) email being verifiable is fine b) nobody should be so stupid as to use email for anything personal. it is not privileged communication and potentially permanent public record. c) if you want to use email, you'd better encrypt it and only for recipients that you trust.
So far, you've just been repeating disparaging comments on less technically minded ("stupid") people. You've not presented an argument for why this change would be detrimental.
We can continue educating people about the inherit insecurity of email while still improving it for those that (a) will never get it and (b) simply don't have access to alternatives.
What we should be doing is making end-to-end encryption easier to use.
PGP & S/MIME failed at this completely.
I have to say you've failed to articulate why making email better (while we work to come up with a better solution) is an inherently bad thing. Especially when we can make it better for free.
The corporate world is mired in zero-sum competition, and some of your colleagues are willing to do things that will shock and appall you if it increases their chance of "winning".
Try working in defense, finance, or security as a closet anarchist. Have a few Chomsky books in your Amazon purchase history? Good luck climbing the Amazon corporate ladder.
Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?
what about a _telegram_ message?
But bad things happen to good people too. If you build a mechanism that incentivizes crime, sooner or later you will get crimed on."
Also there's an argument that "good people" can be blackmailed for INVENTED misconduct, but wouldn't such fake emails be more convincing without the ability to verify their origins? Making real emails and fake emails more similar protects people who have their incriminating emails leaked, but it also harms the defence of people who have fake emails targeting them "leaked".
There's a high bar for obfuscating truth and I don't believe this argument meets it.
Providers like Google reacted to the whole “Larry and Sergey” embarassment in the way you’d expect. Without giving the implications any serious thought, they quickly ramped up their keys to 1024-bit or 2048-bit RSA. This stopped the forgeries, but inadvertently turned a harmless anti-spam protocol into a life-long cryptographic authenticity stamp — one that can be used to verify the provenance of any email dump, regardless of how it reaches the verifier."
Note that the "few hours" attack here is only relevant if they were using easily crackable 512-bit keys. The author of this article suggests (and I agree) that the 1024 or 2048 bit RSA keys are not easily crackable. (see https://crypto.stackexchange.com/a/42830)
Maybe you are suggesting that someone could sign emails using the old crackable 512-bit keys. And they could, although we should disregard this as "not verification" given the weak keys. The article links to https://github.com/robertdavidgraham/hunter-dkim#short-dkim-... - which verifies an email using a since-rotated 2015 key (which was 2048 bits), although that github erroneously states that Google was using 1024 bit before that (they were using 512).
I would concede that the notion of "sometimes we should disregard some DKIM verifications based on the key length" is not easy to grasp and that email verification stories in the media could become muddier and harder to present. I would hope that interviewing experts gets you a reasonable estimation of how likely an email is to be legitimate.
I guess you’re the type of person that would happily hand over all your personal files to the police on a regular basis as you have nothing to hide.
At this point, I'm more inclined to believe that "democratic" and "noble" governments and agents are the ones maliciously pushing for "privacy" because it suits their power-maintaining agenda. I'm struggling to find compelling and valid reasons why we can't pursue a general solution that involves us giving all this "private" data to a government entity for legitimate investigations, fraud prevention and crime-solving whilst keeping that data free from abuse.
Because that's not logically possible. It would be nice if it were, but just think about it: if you give data to the government, humans can look at it. Can we ensure that the humans who look at it are good humans? No. Is there some mathematical way of signing and encrypting such that only good humans can look at it? No.
Okay, so it's logically impossible to keep bad people out mathematically, but maybe it's a practical problem and it doesn't matter in practice? Except no, there are tons of evil governments (CCP being the most obvious, but pick your poison), and even good governments are subject to the problem that people can bribed and secrets can be stolen if there is sufficient motivation. It's just not compatible with human nature to say "collect all this information on people, but only use it For Good Purposes."
While I understand the problem of evil governments, I broadly trust mine. I want them to have the power to investigate me, and my fellow citizens, for crimes. I don't want to love in a lawless country.
Germany 1933, Donald Trump today, far right extremism in Europe are all examples of how trustworthy governments become evil governments.
Democracy doesn’t offer a defence against “evil” governments. Only that you need a majority (and frequently not even a majority) to vote for one.
If a government turns full evil, they don't need evidence against you, they can just lock you up without charge.
Why would we want to give up more?
Previously if someone, government or otherwise, wanted to learn about you, they would need to physically follow you, tap your phones, intercept your post etc. Warrants for searches were built around this.
Online, you can dig into the private life of someone on the other side of the plant who you’ve never met. With the application of computers you can dig into the lives of hundreds of people you’ve never met. All without leaving the comfort of your desk.
The opportunity for fishing expedition is unprecedented at the moment, and it always easy to justify a fishing expedition if you pick a horrific enough crime (child pornography seems to be the favourite right now).
Finally privacy is the strongest bulwark we have against government overreach. That doesn’t mean some top down conspiracy of a totalitarian-elect government. It can be normal everyday government administrators who decide to step outside their bounds for personal reasons, or belief of moral superiority.
Simply put, there’s no better deterrent for bad behaviour than hard work. Privacy makes bad actors work hard for their lunch. It makes the good actors work hard as well, but the solution to that isn’t less privacy, it’s more funding and resources for good actors.
(One could imagine a police force that is effective enough to stop murderers, but not effective enough to stop dissidents. Such a police force would be more useful for a society that wants no murder than for one that wants no dissent.)
First of all, tax information in the United States was in fact abused by Richard Nixon, so it's not just a hypothetical possibility. It's a thing that already happened and requires safeguarding to prevent recurring. If there were a way of collecting taxes without the possibility of abuse, we would use it, but there's not, so we do what we can to balance things. FWIW, I think actually a lot of government records should be stored on paper and not in computers because hackers can steal 300m records overnight, but even very enterprising thieves can only steal one or two truckloads of physical records per hour.
Second of all, this information is just on another level. My tax information is basically not interesting to anyone except that it has my SSN on it, and SSNs are only interesting because the US has bad laws around "identity theft" and we don't properly punish corporations for giving out loans based on nothing but an unverified SSN. Could someone embarrass me by releasing my tax info? I guess if they really dug into my charitable deductions and found an embarrassing cause (a la Brendan Eich?) or that I was giving too little? For me, an average American, there is little or no reason to fear having my taxes used against me.
Email is just not like that. There are certainly emails I have send and received which I hope no one else will see. It's just not comparable at all. It's the difference between having $100 in your wallet (might be stolen but probably not) and $6m in your wallet (will absolutely be stolen if people know about it).
Should the government be able to investigate me? Of course! But investigations have happened for centuries before emails existed. Investigation does not require pre-surveillance of emails or covert surveillance. The simplest thing the government can do is arrest me on suspicion of X charges and then go through all my computers. That is 100% the government should be able to do! If they catch me destroying evidence, I should be charged with destruction of evidence. But that is different from empowering the government to secretly look at email. The part where the government collects my email should be public action that I am well aware, not a secret action done passively by breaking encryption.
> in an encrypted manner that has guarantees in place that only valid criminal investigations can decrypt
What constitutes a valid criminal investigation, who decides? Do you, does a prosecutor, a judge, the police?
Is it a valid to decrypt your data just see if you were at a specific location at a specific time? What about so the police can check a theory? How about to see if you joined an unsanctioned protest, smoked a joint, speed while driving, downloaded a movie?
Speeding and copyright theft are both criminal, are you saying that your happy to make it trivial to investigate you for these crimes an prosecute you for them?
It used to be criminal to engage in homosexual behaviour, and in some parts of the world. Once upon a time that would be a valid criminal investigation in the US. For a short while it was looking like abortions might become criminal in the not too distant future.
Privacy is a fundamental tool for allowing society to progress and change, and for avoiding totalitarianism.
Some sort of formal process with reasonable oversight the necessity of multiple points of compromise and/or collusion in order for the data to be abused for non-governmental use. Bottom line, I can't say I've "solved" the problem and have the perfect answer to your question. But I'm sure we, collectively as a society filled with smart people that want to move us forward, could put down some (fundamental?) tools/rules/processes that would negate the potential for abuse up until a certain point. Maybe we can't do 100%, but we could do 95 or 98%?
>"Is it a valid to decrypt your data just see if you were at a specific location at a specific time? What about so the police can check a theory? How about to see if you joined an unsanctioned protest, smoked a joint, speed while driving, downloaded a movie?"
Yes, very much so Yes! Especially the location based stuff as it's perfect for investigations without revealing details. "List all people that were within 50m of this crime location during this timespan." <-- that is so unbelievably powerful as a crime-solving tool, that I am baffled that we're avoiding it out of privacy concerns. As for the speeding example: That's probably another example of us already giving the data (car's black-box) to government (and private insurance companies) in order to facilitate an investigation.
But to your point about drug-use, speeding and copyright infringement. If we don't want something prosecuted then we shouldn't have it as a crime. But as it stands now, a bunch of what you mentioned is a crime. That represents an implicit agreement by all of us in society that says we deem those things punishable. We can't hide behind lack of capability to police said crimes, but still label them as such. That is ripe for offical-power abuse. For all we know, if we lived in a society where we had such strict enforcement of laws as I suggest, we'd potentially have greater churn and change in our laws to match the opinions of society as it changed and evolved.
> "Privacy is a fundamental tool for allowing society to progress and change, and for avoiding totalitarianism."
I disagree. I'm not seeing it. There is just way too much going wrong today in 1-st world countries whilst we have really good privacy for it to be the case. We're downright descending into totalitarianism and thought/opinion control territory, all whilst our "privacy" is mostly maintained and respected. Are you saying we need more of it? What would that look like to you?
> We can't hide behind lack of capability to police said crimes, but still label them as such.
Most laws are written with the implicit assumption it’s not possible to perfectly enforce them. That provides some natural wriggle room to interpret the laws, avoids the need to write a long list of when it’s ok to speed for example.
Perfect enforcement breaks all of that. A knowledgable police officer could almost certainly stop you on any day the week and find you guilt of some obscure and ancient crime that’s no longer relevant.
> For all we know, if we lived in a society where we had such strict enforcement of laws as I suggest, we'd potentially have greater churn and change in our laws to match the opinions of society as it changed and evolved.
How do you imagine society would evolve its opinions and change them in a world of perfect enforcement? How the gay community show the world there nothing wrong with their way of life, if they simply couldn’t live it?
How would society change its views on smoking weed, if it was impossible to smoke it?
It’s impossible for a society to change its view on existing laws, if it’s completely unable to experiment with ignoring, or re-interpreting them.
It would be like expecting a child to ask for food they had never eaten, and never seen anyone else eat. How could they possibly know it existed, much less if it was good or bad for them?
> I disagree. I'm not seeing it. There is just way too much going wrong today in 1-st world countries whilst we have really good privacy for it to be the case. We're downright descending into totalitarianism and thought/opinion control territory, all whilst our "privacy" is mostly maintained and respected
Hahahaha, seriously. You complain of thought control, but advocate for world where the government can watch your every move, and perfectly enforce every law. Have you read 1984? I see little difference between world in that book, and the one your advocating for.
> Are you saying we need more of it? What would that look like to you?
Yes I am. How can you control someone’s though and opinions if you don’t know what they are? How can a totalitarian government rule with an iron fist if they don’t know where their citizens are, or what they’re doing?
Totalitarian governments come into existence because people want control and order, and they’re great if you fit into that governments view of what control and order look like. If you don’t, we’ll there are plenty of genocides that can be studied.
[0] https://www.google.com/amp/s/www.theverge.com/platform/amp/2...
Personally I am fine with the idea (as represented in this comment https://news.ycombinator.com/item?id=25115654) that email is providing something similar to a "paper trail", and when you send an email you can expect that people can prove you sent it, should they get their hands on the email. However, I totally understand the position that private secure messaging is important and that email should default to that.
In the authoritarian argument, "you've got nothing to hide", is followed by "you are now forced to reveal all", in my execution it would be "you are accountable for all emails you send, forever, should they be released". I am ok with that specific lack of privacy in that context, but I can understand the position that non-repudiability should be opt-in, and privacy the default.
> that email is providing something similar to a "paper trail"
because paper doesn’t provide non-repudiation and never has done.
The whole point of a “paper trail” is the “trail” bit, as it provides providence of a sequence of actions or communications that logically fit together. Hopefully providing evidence for your side of a dispute.
There’s no need for email to be non-repudiatable to achieve this. In fact I serious doubt a court would care if an email is DKIM signed. Very rarely are disputes so simple and straightforward that proving a single email was sent is enough to produce an outcome.
In short DKIM non-repudiation by default gives up everyones privacy, to protect a tiny group of individuals engaged in extra edge case disputes, where the entire outcome of the disputes hangs on the validity of a single email.
For the people who lack imagination: suppose I'm a public official, and a photograph comes out depicting me doing some kind of "dirty" sexual act. Maybe it's real; maybe it's a deepfake; but if confirmed to be real it certainly would do reputational damage. Non-repudiation by definition prevents me from disavowing it, to no social benefit, and it's an anti-feature, in the sense that the large majority of users would prefer to have the ability to repudiate certain message contents than not.
Non-repudiation should be opt-in.
Here, have a link, from 2004:
As you know, there are many legitimate needs to authenticate messages of strangers.
For example, when you order products over the internet, an e-mail of your purchase is often the only proof of what was agreed in the purchase. If there is later a dispute between the buyer and the seller, the email can be used to repudiate lies. In particular, if a third party (like a court) can authenticate the message, the honest party can convince the third party that the dishonest party is being fraudulent.
You are exaggerating when you claim that there is no legitimate need to authenticate messages as a third party.
I gave an example of a legitimate need to do X.
Your rebuttal is that... I'm confused? Yeah, you're gonna have to be more specific than that if you want to convince anybody.
I don't understand enough about all the issue to really know how I feel about it, but clearly there are trade-offs here that at least argue against expanding the scope.
First, thank you for the clarification.
Second, to answer tptacek's point, I understand that authenticating emails as a third party is an unintended side effect of the DKIM protocol. I understand that cryptographers would like people to move onto using other protocols for purposes like this. However, the suggestion that Google should periodically publish and rotate their secret keys, does not achieve this goal in any way. If Google were to do this, the webstore that you purchase items from, would not suddenly start using different protocols to authenticate purchase receipts, they would continue to send regular email... but those emails could no longer be authenticated. Or if we go back to the example in OP, the politician that's admitting to crimes over email, they're certainly not going to switch over to another method of documenting their crimes.
Edit: I was incorrectly using GPG as an example. I removed the incorrect example and let the point stand without it.
Edit: Hacker News doesn't allow me to post replies to the posts under this post, so I will answer by editing this comment. I'm addressing the following comment:
> Which counterexample is that exactly? Your counterexample involving a store is incorrect -- the store's email would still be authenticated for a smaller amount of time which would allow your server to verify that it is a valid email that came from the store's servers.
If you actually read my counter example, you will see that I wrote: "if a third party (like a court) can authenticate the message".
Yes, my email server can authenticate the email when it arrives, but that will be of little help later when I try to dispute claims in court. If the court can authenticate the email, that will be helpful to the honest party in the dispute.
Which counterexample is that exactly? Your counterexample involving a store is incorrect -- the store's email would still be authenticated for a smaller amount of time which would allow your server to verify that it is a valid email that came from the store's servers.
EDIT: Since you responded with an edit, I suppose I should as well. Btw, you can reply to comments below, but you have to click on the comment's permalink/timestamp (the thing that says "1 hour ago") first.
I didn't see the comment you are referring to because it was a very high up ancestor. I only saw the comment I replied to which doesn't mention courts nor third-parties, which is why I asked you for an explanation. Please don't jump immediately to the conclusion that I did not read your comment.
Regarding the content, hamburglar's sibling comment is spot on. Non-repudiability shouldn't just be an afterthought. Accidental non-repudiability can have negative consequences itself. For one, relying on the kind of poor man's non-repudiability that DKIM gives you leaves powerful central entities with the ability to forge email while convincing almost everyone that it is legitimate.
From reading everything that you wrote, I think that your thesis is that email, specifically, ought to be non-repudiable. That might be a worthwhile idea, but it should be presented as such at the forefront. If others agree that this is a valid and useful concept, then a non-repudiability mechanism could be added to email explicitly, just as DKIM was added. But don't use DKIM for this, since it is a poor substitute.
I fully agree.
> From reading everything that you wrote, I think that your thesis is that email, specifically, ought to be non-repudiable. That might be a worthwhile idea, but it should be presented as such at the forefront. If others agree that this is a valid and useful concept, then a non-repudiability mechanism could be added to email explicitly, just as DKIM was added. But don't use DKIM for this, since it is a poor substitute.
If the choice was between "DKIM for non-repudiability" and "a better mechanism for non-repudiability", of course I would support the better mechanism. But that's not the choice here. The proposal here is to remove this accidental, partial non-repudiability mechanism that currently exists, and replace it with nothing. That would leave the world worse off, not better. DKIM protects innocent people from being framed for saying horrible things, and DKIM protects innocent people from guilty people who do horrible things. And sure, sometimes DKIM might be used against innocent people in some way, but the balance seems heavily in favor of DKIM (from the perspective of innocent people).
I think the person you're talking to thinks this is very obvious and thus isn't stating it explicitly, but in the special case where you want an email to include non-repudiation, such as for a purchase receipt, the sender should just add non-repudiation to it in the form of a signature that's intended for that. Simple.
Ok, but this does not magically happen if Google publishes and rotates their DKIM keys. People will continue to use email for everything, but now emails can no longer be authenticated by third parties.
Let's not pretend that the world would move away from email if Google made this change. We both know that's not going to happen. Given that, can you explain why you think the world would be a better place when emails can be repudiated? When emails can be not be repudiated, innocent people can be framed for saying/doing things that they didn't do. DKIM protects innocent people from being framed. DKIM also protects innocent people against guilty people who commit frauds or other crime.
Without non-repudiation, you don't automatically get to frame someone for whatever. You need to provide the usual (non-DKIM) evidence of whatever you're claiming.
And even with non-repudiation, you can still try and frame someone. Not having the DKIM signature might be suspicious in some circumstances, but it doesn't eliminate the possibility.
Second, "innocent" is not that simple.
I don't want my private communication to become public, or publicly verifiable. That doesn't mean I'm not "innocent". This is not a fringe concept: https://en.wikipedia.org/wiki/Nothing_to_hide_argument
"Give me six lines written by the most honest man in the world, and I will find enough in them to hang him." - Cardinal Richelieu
Yes, I agree we should have secure private messengers. But that has nothing to do with this discussion. First off, email is not a secure private messenger. Second, email would not become "more secure" by removing the accidental, partial non-repudiation that DKIM provides. Third, this comment chain that you are replying in right now, is about whether there exists any legitimate need for a third party to authenticate emails with DKIM after the emails have been sent. tptacek claimed that no such legitimate need exists. I've been arguing against this with a specific counter-example.
That's because we aren't discussing a proposal to switch from DKIM authentication to a different method of authentication. We're discussing a proposal to abandon the partial non-repudiation property that's accidentally provided by DKIM, and replacing it with nothing.
If you want concrete examples of how the partial non-repudiation property provided by DKIM is not "nothing", you have to look no further than the examples provided in OP.
Let me give you a scenario to consider. At my old company, there was a mail server that would DKIM-sign everything that was passed through it. Anybody who wanted to on the internal network could write an email with tampered headers (say, backdated, or "From:" someone else) and send it through this server. This was acceptable because the SOLE PURPOSE of this signing was improving SMTP deliverability. It tells other mail servers "yes, this SMTP payload actually originated from this company. Please do not treat it as spam." So given one of these signed messages, what can you argue about the contents? Nothing, other than "these did not come from a random spammer posing as this company."
You run risks when you assume a signature means something that the signer does not actually intend it to mean.
Please explain to me how I can make Amazon (or any other webshop) add non-repudiable contracts to their order flow? That's right, I can't. And no, I don't think that Amazon "owes" me non-repudiable emails, but now that we have non-repudiation by accident, it's certainly nice to have, and the world would be worse off if we removed that feature and replaced it with nothing.
No, he didn't, and to use quotes to claim someone said something that they didn't say is extremely disingenuous.
This sentence? "Serious secure messengers have been designed to avoid non-repudiation since OTR." I don't see how this sentence supposedly alters the meaning of the sentence that comes after it? At this point it seems like you just want to sow confusion. If I had misinterpreted your words in some way, you could have clarified the misunderstanding like 10 times by now. Instead, you choose to reply in snarks like saying I'm confused, or asking me to read your comment again. I don't think there's any misunderstanding. You took an extreme position that didn't hold up to scrutiny, and you don't want to defend your position or back down, so you just reply in snarks instead. If there is some kind of misunderstanding, please do go ahead and explain what the misunderstanding is.
No, it doesn't. The dispute isn't about the need for counterparties to authenticate each other. Yes, we all agree that it's good if email receivers can validate the authenticity of the sender. That's not at dispute. The question is, is it good if third parties also have the ability to authenticate the sender of an email at a later point in time (using DKIM specifically). tptacek claimed that there is no legitimate need for such a thing, and I provided a counter-example to that.
The example was that two parties are disputing a contract, the court is attempting to resolve the dispute, and the court has a need to authenticate the contract. Can you explain why you think that this is not a legitimate need to authenticate a document?
> I'm not sure (and decline to speculate) whether you're confused or malicious or some other problem entirely, but you are wrong.
You "decline to speculate", and then proceed to speculate anyway? Ok. Well, it's certainly easier to resort to calling me names, than actually defending your position with arguments.
Because it is not legitimate for a court to treat something that was not intentionally (ie, with something other than DKIM) signed as a signed contract. If one party did not sign that contract, a DKIM 'signature' doesn't change that. Conversely, if you have a argument that the document should be treated as a valid contract despite not having been signed, the lack of DKIM 'signature' is obviously irrelevant.
Not legitimate where? In Finland, where I live, there is no restriction on the form that a contract must take. A contract can be scribbled on a napkin, a contract can be oral, and yes, a contract can be written in email. You're claiming that a document should not be treated as a valid contract if it has not been signed, but Finnish law is pretty clear that a signature is not required for a contract to be valid. Furthermore, you claim that if a signature is not a requirement for a contract to be valid, then the lack of signature is "obviously" irrelevant. This is not obvious at all, and in fact is not true at all. As you surely know, sometimes the parties to a contract dispute what was agreed upon. Having a written contract is superior to an oral contract, because it is harder to dispute what was written, than it is to dispute what was said orally. In the same vein, it is harder to dispute a written contract with signatures, than a written contract lacking signatures. And in the same vein, it is harder to dispute an email that is DKIM validated, than an email that is lacking any sender validation.
No, I'm claiming that a document should not be treated as signed if it has not been signed. And drawing attention to (not "claiming") the fact that attaching^Whaving some third party such as Google attach a piece of networking metadata to it, does not constitute signing.
It sounds like you think that a "signed document" carries some sort of significance that an "unsigned document" does not carry, other than the value of the signature as evidence of a contract. I'm not aware of any such significance, at least not in the context of Finnish legislation. Perhaps if we are emailing a draft of a contract back and forth, the signature on a document can be used to specify which version is the agreed-upon contract as opposed to draft. But a similar proof could be attained without a signature, for example by recording audio of a verbal agreement which specifies the agreed-upon version of the contract. The signature does not carry any special significance.
In any case, no, I do not think that a DKIM signature is comparable to a handwritten signature. I would rather compare DKIM signature to fingerprints on a physical document. You might say "I've never seen this piece of paper in my life!" to dispute the validity of a paper contract, but your fingerprints on that paper would constitute significant evidence against your statement. DKIM signature of an email could be used in the same fashion.
I agree with you here. However, EMail was never designed to do this. Eg if you order products over the internet, how do you know that your opposing party keeps their DKIM key safe?
I get that email and DKIM was never designed for this, it's a side effect. Fingers were not designed for finger print evidence, but it's still nice to have evidence from finger prints, as a side effect from touching things. And the problem of key storage / keys leaking will not disappear even if you change to some different protocol.
What makes this hard is that email is responsible for too much crap. No single user interface should carry:
1. Party invites
2. Private messages to your spouse, therapist, pastor, etc.
3. Marketing messages
4. Password recovery requests
5. Financial transactions
We've just shoved them all into email because it's there.
In the real world it doesn't matter which cryptographic protocols are theoretically available for use. What matters is which protocols everyone else is using. For example, in the case of receipts for purchases on the web, literally everyone is using email. You will not be able to get amazon to sign a receipt with gnupg.
If you want to embark on a path of convincing the world to move away from email, that's great, good for you. Just don't pretend like removing non-repudiation from e-mails is a quest on that path. It's not.
Please explain how I can make amazon sign my purchase receipt with GnuPG?
Absolutely, but this should be an opt-in feature (and not provided server-side, at that).
Why?
Legal signatures are heavily ritualized (blue/black ink only, initial here and sign there etc.) in most societies for good reason – it makes the signer stop for a moment and reconsider what they are doing, if the document they are signing is truly aligned with their intentions and so on.
As another analogy/food for thought: We have the technical means to record every conversation we ever have, digital or analog, public or private. Should we? If not, why not?
Why do you feel like email "makes no explicit claims" about the authenticity of emails? Laypeople are not even aware of the possibility of spoofing the sender field in emails. Technical people can check the "explicit claims" of a protocol like e-mail, SPF, DKIM, etc. to understand what it claims to do. In other words, email makes both implicit claims, and explicit claims about the verifiability of the sender field.
Introducing non-repudiation would violate everyone's expectations and create a total mess.
I'm saying this as someone who often and deliberately uses deniable messengers.
If the "man-off-the-street" expects email to have non-repudiation property, then how exactly would "introducing non-repudiation" violate their expectations?
(b) Thanks for the link!
(c) The IETF is such a shitshow for cryptography.
If you don’t like that status quo, get involved. They would love to have you @tptacek.
Suppose you are in an organization, and it needs to figure our whether an employee was saying a Bad Thing such as giving out company secrets or cursing people out “off the record”.
Yes, even with end to end encryption, Facebook and others can still let you prove the other person sent the messages when you need. The question is whether that is a good thing:
https://facebook.com/help/messenger-app/1165699260192280
My personal feeling is yes, yes it is. I make a more extensive analysis here:
ProtonMail makes you setup 3 CNAMEs for DKIM just so they can frequently rotate without your intervention or disruption. Sendgrid uses 2 for the same thing.
This. Publishing the DKIM keys would be a huge loss for email archivists and historians in general. E.g. a couple weeks ago Donald Knuth published all of the emails he's sent and received over the last 20+ years of his career[1], without DKIM how would we know that they are authentic?
[1] https://library.stanford.edu/blogs/special-collections-unbou...
I mean I try to publish most of my interesting email conversations on the web, because every time you have a good email conversation that isn't public it's like taking a $100 bill and lighting it on fire. So I wouldn't ever personally use disappearing messages.
Literally the first rule of email is that if you wouldn't want it on the front page of the NYT then you shouldn't send it. The first national scandal involving email was Iran Contra in 1986. People should know by now not to put anything into an email that they wouldn't be comfortable with the entire world knowing. And while privacy is hugely important to individuals and essential for a healthy society, to me rotating DKIM keys feels like it's incentivizing people to use email incorrectly.
There is not a popular email system in existence that says
"To: myfriend@mailserver.com CC: Everyone [NON-EDITABLE]"
Quite the opposite is true. Gmail, for example, says "Google.com Mail protects your message during delivery As you add people to this message, this icon will let you know your message is secure."
I get my head around them by thinking they are bad? As in, not good. An undesirable property.
As for authenticity, you could contact him, or his correspondents?
Yes.
> As for authenticity, you could contact him, or his correspondents?
Correspondents aren't necessarily going to tell the truth about the authenticity of their own email. And that's assuming they're alive, reachable, and willing to talk, all of which may not be the case now and will be the case with 100% certainty in the future.
If you want transparency from your politicians, then you should demand unconditional archival and publication of campaign e-mails. Build transparency into the system. Leakers are not archivists, nor are they journalists. They are leakers, with an entirely different set of motivations and incentives which only sometimes align with journalistic or archival motivations. You as a member of the public will not hear about leaks if the person in possession of those leaked files has successfully extorted or ransomed the politician they came from. In this particular threat model, DKIM does not provide a social benefit to you as a citizen, it provides a monetary benefit to the leaker.
Exactly. If one enters into an contract using an e-mail, then DKIM can be used as a proof to the court of law that the contract was accepted by both sides.
It would make a good TV drama plot, but courts don't work this way in real life. If that were the case, courts wouldn't be able to enforce contracts with wet signatures (which are straightforward to forge), or verbal contracts (which are valid contracts and regularly enforced).
In practice, you don't need to check DKIM in order to use an email as evidence of a contract, because the courts would more likely just use the many other threats and tools at their disposal to ensure that the email is not fabricated.
This is why, even though most contracts are not executed in a cryptographically secure manner, most contract disputes that land before the courts hinge on matters like breach of contract ("we agree on the original terms, but disagree on whether our actions upheld them") or disputes over the intended vs. actual meaning of the contract ("we agree on the text we both signed to, but disagree on the correct interpretation of that text").
Disputes over whether the text of the executed contract is authentic are rare in real life.
I'm pretty confident that I could sign an email with a DKIM key if that were published, however, there's nothing that would give me the confidence that I could forge a pen signature in such a way that not even an expert could detect the forgery.
> or verbal contracts (which are valid contracts and regularly enforced).
I'm not a a lawyer, but according to the first google result "the Uniform Commercial Code [...] requires that contracts for the sale of goods over $500 to be in writing".[1]
> Disputes over whether the text of the executed contract is authentic are rare in real life.
Maybe they are rare precisely because it's hard and risky to forge signatures.
[1] https://www.hg.org/legal-articles/are-verbal-agreements-bind...
Yes, but not all contracts do that. For example, any contract for services is not covered by the UCC.
In practice, this doesn't seem to mean that every time you buy an iPhone, Apple provides you a paper contract authenticated with an actual verifiable hand-signed signature of an authorised officer.
It shouldn’t be sprung on people without consent. It would be like saying it’s fine to keep a recording from someone else’s webcam because it might prove a crime later.
There’s a reason why justice systems have statues of limitations. People should need to look over their shoulders for the rest of their lives because of one poorly written email.
Are ppl who don't even know DKIM exists but know they have shady emails saved in the cloud or on their personal really just banking on repudiation and thats why they take no other action like deleting the email or putting more thought into emails they send? Seriously doubt it.
Exactly bc of statute of limitations, they would not have to look over their shoulders for the rest of their lives because of one poorly written email.
I certainly didn’t realise that DKIM can be used as a non-repudiation signature, I’m sure most people using email don’t.
Thus there’s no consent and I would say that non-repudiation has been sprung on me.
The duration has nothing to do with it. Just because you can keep a camera hidden in someones room for an extended period of time doesn’t mean it’s ethical or consensual to record them.
Finally statues of limitations don’t protect people from a trial in social media. Social media is just as capable as the justice system of destroying a persons life. Unfortunately Twitter doesn’t have a statue of limitations.
Actually, you are free to enter a contract in any way possible. It is vormvrij (translated: form-free). Excluded is the purchase of a house, as far as I know. But for the rest, you are free to come to an agreement via WhatsApp, Facebook, email, or a scrawl on a piece of paper.
https://smallbusiness.findlaw.com/business-contracts-forms/w...
And that's how a new contract gets signed! No need to fly someone 1500km just for that.
You want a specific scenario of a dispute between a vendor and a customer? Ok. Let's say I email Amazon's customer support to ask them if a specific order is going to incur customs fees, and the Amazon representative emails me back that the order is not going to incur customs fees. Then I make the order, and to my surprise, I do have to pay custom fees. I contact Amazon to ask them to compensate me for the fees, but Amazon now claims that they are not responsible for custom fees. At this point I would be protected by a copy of the email where they claimed that I would incur no customs fees. If I can demonstrate to Amazon that I have proof of their false claims, prior to the purchase, they will be inclined to compensate. If they refuse to compensate, I can (depending on jurisdiction) take my claim to small claims court and present my evidence there. In this case it's unlikely for anyone to actually validate the DKIM signatures, but it does matter whether email is generally considered to be non-repudiable. If you run a campaign to make email repudiable, and make sure people should know email is repudiable, then this email will be less convincing as evidence.
How many disputes like that have been resolved with DKIM?
Again: How many disputes like that have been resolved with DKIM?
The original email spec doesn't provide any security against forgeries. The "sent from" field in email is about as secure as the "sent from" field in physical letters. The only reason why laypersons consider email to be non-repudiable is because of additional protocols like SPF and DKIM that were implemented after the original spec. Without these protocols email would be considered repudiable, which OP considers to be a preferrable outcome.
> And that commerce existed before emails?
Yes, and? I'm not claiming that all commerce would come to a halt immediately if this campaign for email repudiability was successful. Of course commerce would continue to exist. But the world would be worse off, not better. There would be slightly more disputes, and dishonest parties would increase their chances of defrauding honest parties.
> You don't need DKIM to solve the issues you've pointed out.
Are you alluding to hypothetical alternative protocols for authenticating contracts? If you can make the world move off from email, that's great! Email is horrible! But if you can't make people move away from email, you won't make the world a better place by making email less secure.
> Again: How many disputes like that have been resolved with DKIM?
How many? As in, you expect me to have statistics on it? Are we pretending that when people resolve disputes, they mark their disputes in some kind of global database that we can query for statistics? You're not making any sense.
You really think that laypersons have any idea of what DKIM is?
> But the world would be worse off, not better.
That's the whole point of this discussion. You seem to be arguing that the world would be better with non-repudiable email. But then I ask how many disputes have been resolved with DKIM and you have no idea. So basically your argument has zero basis in reality.
You're asking for every email user to have non-repudiation enforced unwillingly to them in every email they send so that someone maybe someday may solve some imaginary dispute with Amazon by using DKIM.
The layperson doesn't have to understand the intricacies of email protocols, it's enough that they consider email to be non-repudiable. This is why a copy of an email typically suffices as "proof" of a contract. If you successfully run a campaign to make email repudiable, then laypersons will no longer consider email to be non-repudiable, and emails no longer suffice as "proof" of a contract. If you disagree with something I said here, can you specify which part it is exactly that you disagree with?
> You seem to be arguing that the world would be better with non-repudiable email.
Yes, the world is better off now, at a time when laypersons consider e-mail to be non-repudiable, compared to a hypothetical future where this is no longer the case.
> But then I ask how many disputes have been resolved with DKIM and you have no idea. So basically your argument has zero basis in reality.
So if I can't give the exact number of times that DKIM has helped in dispute resolution, then my argument "has zero basis in reality"? This doesn't make any sense. If I said that "the existence of courts prevents vigilantes", you could say the same thing: "well what's the exact number of times that the existence of courts has prevented vigilanteeism? ha! you don't know the exact number! your argument has zero basis in reality then." We could apply your logic to many other scenarios: what's the number of times that existence of guards has prevented prison breaks? What's the number of infections prevented by vaccines? We don't know the exact numbers for any of these things, and yet we can logicly deduce that courts prevent vigilantes, guards prevent prison breaks, vaccines prevent infections, and DKIM prevents breaking contracts.
> You're asking for every email user to have non-repudiation enforced unwillingly to them in every email they send so that someone maybe someday may solve some imaginary dispute with Amazon by using DKIM.
Laypersons already believe that emails have non-repudiation property. People are free to use secure messengers to communicate privately. When people choose to communicate with email, they are choosing non-repudiation over privacy. You are the one who is asking to change e-mail protocols so that they would work differently than people currently expect. I'm the one saying e-mail should work like people expect e-mail to work.
They consider it non-repudiable not because of DKIM, it's just a common misconception. People believed that before DKIM. They will still believe it if Google discloses its DKIM keys.
They totally should not believe it, though.
> So if I can't give the exact number of times that DKIM has helped in dispute resolution, then my argument "has zero basis in reality"?
Of course that's not what I meant, I don't care about exact numbers. Just give me some evidence that DKIM is relevant to solve disputes anywhere else other than in the minds of HN commenters. Otherwise your claim that the world is better off now with non-repudiable email has no basis in reality.
> they are choosing non-repudiation over privacy
They totally are not. They have no idea what are the properties of email. As an example, a non-tech friend of mine was once surprised that email does not provide any confidentiality.
I don't have a strong opinion on the chances of success that this campaign has. What I am saying is that if the campaign was successful in increasing the repudiability of email, that would make it easier for people to repudiate emails that they've sent, and that would be a bad thing in the context of resolving disputes. Do you agree?
I've raised VC money based on emailed contracts, bought businesses based on them, bought domain names.
It is incredibly standard and legal (in almost all of the jurisdictions I've worked in, which is a lot).)
The 3rd party tried to say other company fell for a phishing email and it was their fault but because of DKIM it was immediately provable that instead 3rd party was compromised and email legit sent from their o365 and they were pretending like they didn't know this. This all got disputed maybe a year after email sent.
Love Matthew Green but I personally am not a fan of this proposal. It doesn't fully achieve what he wants bc its only gmail and timing of compromise would be key. Most of the email hacks have actually been very much in the public interest despite being unethical. Breaches also lead to more productive work by companies in better securing accounts and better protecting sensitive information which google has been doing with account security and adding expiring messages.
Like do we really want companies to just continue sloppily sending customer info in email bc they can deny its legit or should they focus on not getting this info compromised to begin with?
Also, for ransomeware groups that now post data when not paid, it is not really seeming like too big of a disincentive that there is repudiation regarding the files they post.
The argument here is more that customers of gmail and other email services are not offered repudiation as a feature.
The more I think about it the more I inch towards agreeing with TFA. If I need my email to be authenticated I can sign them with GPG. If the law enforcement needs to see if I did or did not send an email they can subpoena Google.
>Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail.
Can you expand on this? I can't really come up with a use case that wouldn't be about associating somebody with an email they may want to distantiate themselves from.
https://www.washingtonexaminer.com/opinion/the-hunter-biden-...
The comments here on Hacker News seem to have tripped on the examples given (keywords: politicians, journalists) and turned this into the more generic and politically loaded discussion whether it's desirable to "cryptographically verify" what politicians write.
But that's not the point! The point is that DKIM is technically not designed for this use case and the way people misuse DKIM for this unintended purpose is highly problematic from a cryptographic and engineering perspective.
I think the best way to think of DKIM is that it's a "cryptographic protocol" in the sense that git is a "cryptographic protocol" because it uses SHA1. If you think "PGP" (not the best example :-)) or "Telegram" you have the wrong idea: DKIM is a bunch of cryptographic primitives haphazardly bolted on email to solve a specific problem. It's not good cryptographic design because good cryptographic design anticipates unintended usecases and deal with them appropriately.
1) Read the DKIM RFC.
First of all the only field that it's required to sign is the From: header (see RFC, section 5.4). So you could still forge an email but have it pass a DKIM signature check.
If people believe that DKIM "cryptographically signs" e-mails in the sense of PGP, then that's a problem, because that's not true. A DKIM signed email doesn't actually say anything: you have to look at the signature which part of the message are signed, which is not standardized.
So you could have this situation when people, like journalists or even people on Hacker News, think a forged email is valid because it has a valid DKIM signature (but the signature is over the From: header only). E-mail is complicated as it is without having to explain to people who have binary classified an email as "forgery" or "not forgery" based on a specific combination of email-headers and DKIM signature specification. Let's not do that.
2) Look at what mail providers actually do with their DKIM keys.
For legacy reasons due to DNS providers and length of TXT records, many large internet providers use DKIM keys that are 1024 bit RSA.
Already 10 years ago, most standard bodies started to recommend against the use of 1024 bit RSA. It's deprecated. Like MD5-deprecated.
The fact that many service providers use the same key for all emails for all customers and reuse that key for years, increasing the likelihood of the key being leaked, is another case against trusting DKIM for this purpose.
> First of all the only field that it's required to sign is the From: header
OK, I've never looked into DKIM before, but 6376 looks fairly recent, and it reports the message body must be hashed. Now sure, there may be issues with the hash to allow arbitrary collisions, and of course the key may have been leaked or broken, and in any case today's key is unlikely to be secure against nation states now, let alone in 10 years time.
I agree in general the idea that having "DKIM signed" mails means they are authentic is an issue -- in 20 years time it will be easy enough for anyone to forge a DKIM signature for any email they want that they claim was sent today, but from what I can see the message body is signed.
If some provider decides to implement this proposal, I don't think they should do it retroactively and publish old keys. It would be just inviting additional political shitstorm.
As far as I can tell, people who need repudiation are already using apps that have repudiation (eg Signal), because they know they are in a vulnerable position. The people who need repudiation already have it. So far we have seen DKIM authentication used against individuals in positions of power. With things as they are, cryptography is leveling the playing field by empowering the vulnerable while holding those in power responsible. If this situation or balance were to change perhaps it would make sense to rethink DKIM non-repudiation. I understand this is an opinionated/political take on cryptography that not everyone would share.
Can you really not think of a scenario where non-repudiation could be important even to people "not in power"?
I've used Google's DKIM signatures to timestamp call recordings for years by putting a sha256 of the attached recording in the subject, so "literally no security purpose" isn't true!
(though I should probably go through and timestamp those signatures right now them using another method, just in case this guy's idea gains any traction)
1) DKIM doesn't protect the To: header in any reasonable way (its not really designed to). i.e. it protects it in the sense that the original email had that as the To: header, but this is easy to forge as the To: header is not used by SMTP in delivery (think Bcc). i.e. its easy to write emails that are To: <some address> that are never attempted to be delivered to said address.
2) DKIM (even on gmail) doesn't quite protect the From: header as one would expect. Yes, gmail in general makes it difficult to spoof the email in the From header (it will replace it with your own if you try in the general case), but there's a huge but, if you gave gmail itself access to use that e-mail. i.e. I can be compsciphd@gmail.com but if billgates@gmail.com was convinced to allow me access to send emails as billgates@gmail.com (either via cooperation or a technical or sociological hack) then i can do that without having access to the account. and this permission is permanent. as far as I can tell, it irrevocable and to other gmail users there is no indication that other accounts have this permission for your email.
so what do we learn
1) can't 100% trust DKIM to believe who an email was sent to unless you actually retrieved it out of said user's email spool 2) can't 100% trust DKIM to believe who actually sent an email (even on gmail)
now, do I think DKIM gives anywhere close to 0% trust. No, I think its much closer to 100 than 0, but one has to understand the limitations and most people who discuss it, don't seem to understand them.
the threat is a hack playing a very long game. If one doesn't view that long game hack threat as serious, then its close enough to 100% (especially if gmail rotates their keys even without making the private part public), but if a long game hack threat is a serious thing, then it drops.
Two questions:
Have there ever been any Gmail design decisions, e.g., default settings, where users were consulted first?
I was recenty informed by another HN commenter that "99% of users" are "not qualified to have opinions" on something like MacOS behaviour,[FN1] or in this case Gmail behaviour. If this is true, should "99%" of users be given the choice not to use DKIM if they are "not qualified" to have an opinion on DKIM?
What about a public plea for justice? Accountability?
This is true with the added proviso that, by "us", he means "the guilty". The rest are protected, on the contrary, to this very particular form of these crimes.
What if someone realizes that Google uses a broken cryptographically secure pseudorandom number generator (CSPRNG) à la Debian ? Unlikely but the risks exists, so not going to happen in my opinion.
1. Someone with bad intentions figuring that out could start spamming other domains using gmail.com From Addresses.
2. Someone with good intentions would contact google security for a bug bounty or maybe just publish a zero-day report. Google would correct the issue and the world would be a slightly more secure place.
#2 would almost certainly happen, I suspect. And if #1 happened _before_ #2 then there'd be more spam in the world, temporarily.
To me the risk seems low.
Consider this excerpt from the blog post:
> But DKIM authenticity is great! Don’t we want to be able to authenticate politicians’ leaked emails?
> Modern DKIM deployments are problematic because they incentivize a specific kind of crime: theft of private emails for use in public blackmail and extortion campaigns. An accident of the past few years is that this feature has been used primarily by political actors working in a manner that many people find agreeable — either because it suits a partisan preference, or because the people who got “caught” sort of deserved it.
> But bad things happen to good people too. If you build a mechanism that incentivizes crime, sooner or later you will get crimed on.
The author seems to be arguing that if after a certain point it becomes impossible to verify whether an email was genuine or not, that would somehow be a good thing.
This reasoning seems harmful to me. It's incredible that the author treats this moral argument as self evident. Let me state my objections clearly.
1. The truthfulness and reliability of the historical record is important. The fact that politicians are protected from blackmail when they write incriminating emails is utterly insignificant by comparison. Is the principle being defended that protecting politicians from blackmail is stronger than a public interest in having a historical record?
2. Making historical emails impossible to authenticate after a certain period of time makes it more difficult to prosecute crimes. It helps criminals, the very thing the author claims to be trying to avoid. If a politician, or anyone for that matter, sends an incriminating email which is evidence of the intent to commit a crime, why on earth would you want to make it easier to cover your tracks?
Seriously, can someone present a moral argument for why this should be adopted? It seems only harmful to me.
Because this isn't just about politicians, or holding politicians accountable. It affects the rest of us too!
Instead, imagine what would happen if a hacker accessed the email of a closeted LGBTQIA+ person living in a country where being outed is practically a death sentence, and the DKIM signatures were sufficient proof of guilt.
In the particular case of Google releasing its DKIM keys, I think I would need more context. What kind of repudiation property do users expect when sending emails over GMail? Is non-repudiability currently used by users for legal or business purposes? Probably the way to do it would be to announce a particular date maybe a year into the future that the private keys would be released.
1. DKIM provides neither truthfulness nor objectivity. It's a signature mechanism used between mail servers to reduce spam. For implementation reasons, most DKIM users sign with RSA keys that are either currently crackable or will be crackable in a matter of years. Consequently, "signed" emails that are leaked years after their alleged transmission provide a false sense of non-repudiation.
2. Per 1, these emails are already impossible to authenticate after a period of time. This just makes the expectation more explicit. More generally, however, this just isn't a fruitful (or intended) application of DKIM: if the government wants to obtain evidence of a crime, they're going to subpoena the email provider and retrieve the originals. If the suspected criminal is sufficiently important, they'll use pointier methods. The outcomes of our criminal justice system intentionally doesn't hinge on the validity of a few DNS-published RSA keys.
DKIM signatures, by your argument, are useless in blackmail, since they don’t verify the message. So why did the author resort to that as an example?
Second: That's not how blackmail works. It's contingent on what the extorted party thinks, not the cryptographic integrity of the blackmail material. That's why mass blackmail spam campaigns (that DKIM fails to prevent, ironically enough) are remarkably effective. Publishing DKIM secret keys after their expiry doesn't magically prevent blackmail; it just removes one more tool from the blackmailer's toolbelt for instilling fear in the target.
To be surprised at a cryptographer advocating for deniable messaging is to suggest that you're unacquainted with the field of messaging cryptography, in which deniable messaging has been a foundational goal for almost 2 decades, going back to Ian Goldberg and Nikita Borisov, who once yelled at me on Twitter for giving OTR short shrift and thus ensured I'd always associate his name with OTR and thus, I'm sure to his delight, his name being dropped on this thread.
I'd again like to point out how clear it is, the epistemic approach being taken in this thread. You can disagree with deniable messaging as a valid goal (it'd set you apart from cryptography engineers, but that's fine). But you can't be appalled by it in 2020, because the idea is old enough to drink in a bar in Canada, and motivated at least two of the most famous protocols in all of cryptography.
Instead, what people are doing here is skimming this post, digging no further, and then calling to mind their understanding of current events. Then, from that tiny thread of information and a bunch of axioms invented, I presume, in the span of just a minute or two, they're deriving an entire first-principles explanation of how messaging security is supposed to work.
You can do that, but I think it's more than fair to point out that there are people that have dedicated their entire career to studying this subject and publishing on it, and if commenters are going to make it clear that they haven't even tried to engage with that material, it's unclear why they should be taken seriously.
Also, Google should publish DKIM keys.
If you or the author are presenting an argument why repudiation is necessary on technical grounds, I will admit ignorance and defer to the experts.
But my reading of the blog post was that it is not a technical argument. It's an argument about morality, and specifically the author used political examples. If the author did not want lay people to argue about the moral implications, why did they use non-technical arguments?
I didn’t see a more convincing argument in the blog post. If there is a technical reason why repudiation is beneficial, I would be grateful for an explanation.
Everybody agrees here, but how does one gets to decide that Google, a private corporation, is the one to decide that a given email is an accurate historical email? An email provider is a defacto certificate authority? Are these dkim keys subject to the same standard of care as private keys that CAs manage?
For your regular-person scenario, having a way for a 3rd party private company "certify" an email sent from another private company (example: your online order) may be good enough, but is it good enough in every scenario?
Similarly, if everyone knows that these keys have been released, people wouldn't believe slanderous email dumps.
As I said in my other comment, I fear that Google may have securely destroyed the keys because of fear of it getting stolen.
Unless you're debugging something those headers seem irrelevant anyway, and they bloat the messages very much. (often times they are 3-4x the size of actual email)
Matthew Green's ask isn't about protecting users that are tech-savvy enough to just set up their own mailserver and configure it a special way.
It's about protecting the billions of users that aren't.
After all, Green is proposing for them to change their servers anyway, so either way it requires some kind of server change.
The advantage of Green's approach is it gets results quickly because with one change they can protect a lot of emails. But, while quick results are nice, is this problem really so urgent that only the fastest solution should be considered?
Another difference is the set of users who are protected. If you rotate DKIM keys, you protect Gmail users against non-repudiation risks because their outgoing emails become more deniable. But if you strip headers from Gmail users' inboxes, you protect Gmail users against hacking, because now hacking a Gmail account gets you less-valuable data.
Also, publishing old DKIM secret keys will require some distribution method. Where do you actually put them? For a given email provider, where do you go look to find them? It's a solvable problem but it's one that doesn't exist with the header-stripping approach.
To make this work you need to claim a forgery when you know that no such forgery occurred. So you explicitly or implicitly have to accuse someone of a serious crime/offence they did not commit. Most people have a greater sense of honour than that. Those that don't would still have to fear getting caught.
If someone actually does forge a message using the old private keys provided by Google then you would have to fight the assumption that you were using the system as it was designed. Everyone would just assume you said it and are now using the possibility of forgery to lie about having said it.
You can always claim a forgery anyway should you decide to do that. Perhaps someone got access to Google's relatively poorly guarded DKIM private key. How would you know? You are probably not making a specific claim anyway.
At the moment that providence can be proved with DKIM. Remove DKIM and now bad actors need to prove that they actually broke into someone’s emails and stole them. A much high bar to pass, especially as it may mean incriminating yourself of a crime.
Emails become just as useful as find a pile of top secret papers on the floor. Unless you can prove the source of those papers everyone is going to ignore you.
-- In the interest of users (will most probably never happen), all incoming emails should be ignored and dismissed unless the recipient has explicitly specified that it accepts email sent from a given email address. Wouldn't this give the power back to the users?
* emails between major email providers have this lingering semi-authenticity indicator that authors didn't explicitly choose
* to the extent the providers keep their DKIM keys non-public, only those providers (or those who exfiltrate such keys) can forge old emails
Both of these have problems if considered from 1st principles:
* Users should be able to control if they're creating non-repudiable messages.
* No one, not even Google, should have the power to create authentic-seeming forgeries.
This article's author, Matthew Green, suggests rapid expiration & disclosure of DKIM keys to narrow the window of time the user is subject to a non-repudiation they didn't choose. (Green here only specifically requests disclosure of years-old keys to invalidate older message archives, but conceivably a rigorous expiration-and-disclosure schedule could be chosen to limit the risk to weeks or days.)
And via public disclosure, Green intends to indirectly address the risk of privileged parties forging emails, by giving everyone the same power-to-forge older emails - so no particular forgery can be too convincing.
But these new defaults are nearly as ad-hoc – reactive without conscious design – as the DKIM problem they purport to solve.
Many would prefer that their emails, or at least some of them, be non-repudiable for a while or indefinitely. Many recipients would like to maintain their own private authenticity records – which as Green notes, can be bootstrapped into existence (even with rapid-expiring DKIM keys) by secure-timestamping messages & current DKIM keys at the time they're received.
(To the extent Google & other providers have internally-trusted tamper-proof logs, they may already have de facto secure timestamping happening on all inbound/outbound email. Thus any amount of DKIM key fouling wouldn't stop their unique internal ability to authenticate older messages, for their own forensic or political purposes.)
I'd prefer users be given some visibility into, and choice over, how much durable authentication is added to their email messages – before adopting either Green's quick fix (publish old keys ASAP), or defaulting all users to his potential longer-term solution of explicitly "non-attributable email" (per his KeyForge paper or other schemes).
If a hacker were to retrieve some emails before the DKIM key was made public, they could then sign their hacked emails with their own timestamped signature, proving that they are in fact authentic (since the signed timestamp shows that they were retrieved before the DKIM key was released).
Therefore, by rotating the DKIM keys "every few weeks" you are giving the would-be hackers a deadline to retrieve the target emails - a few weeks - which could lead to hackers preemptively hacking as many possibly useful accounts as possible (not just the ones they know they want at a given moment), every few weeks.
(The merits of OP's argument notwithstanding)
Also worth noting that email clients typically tell you about new logins/clients (though I don't think their way of doing it is particularly robust).
If we're looking at cracking-activities from an economic point of view, publishing DKIM keys makes the cracking harder:
1. More accounts need to be cracked fast
2. Timestamped signatures must be published in a timely way
3. Results must be stored until they become useful
These things not only increase cracking expenses, they also increase the threat of detection.
In the case of Podesta, the emails were stolen from his gmail account. If the headers weren't there, the messages would have been unverifiable.
https://www.onebigfluke.com/2013/06/bootstrapping-webfinger-...
(I suppose you could just re-opt into webfistbump every time your email provider is about to publish their DKIM key)
That said, I think this would be problematic on some levels not being considered. A good part of the world's email infrastructure is decentralized, and doesn't run on providers who update software well and often. If Google were to publish their keys after rotation, a new class of attacks could emerge where attackers could successfully forge authentic emails from Google that would look secure to an outdated provider. Nigerian prince 2.0 if you will.
Decentralization is one of email's biggest strengths. I agree with the premise here, but I don't think the solution is to publish keys. Perhaps moving to a protocol that explicitly provides non-repudiation while keeping backwards compatibility would work.
Sounds suspiciously like somebody's thinking ahead on how to plausibly deny some yet-to-be-leaked emails.
I think it's kind of unfortunate that there are many people that suddenly care when its powerful people or their families that are getting caught out by DKIM, these aren't the people who need protection from it the most. No one would even care if the Hunter Biden related emails passed DKIM except for the widespread allegation that they were fake, and no one still cares because conversation about them passing DKIM is widely suppressed (including on HN, unfortunately, where a post about it was immediately flagged). Oh well, I suppose it's like when the ACLU used to defend awful speech for the sake of defending free speech because those were the cases available which could make an impact.
Unfortunately publishing DKIM secret keys only goes so far towards avoiding accidental non-repudiation: Recipients can cryptographically timestamp the signatures before the keys are published. ... and doing so already makes sense independent of DKIM. In fact, one of the ways that the public was able to prove that the outdated google DKIM key was a real key was that we were able to find cryptographically timestampped google signed emails from back when that key was still in use.
Better than key publication is to avoid having a non-repudiateable stamp to begin with. This is much easier in the context of end-to-end two-party interactive protocols, but I believe is still possible for multiparty protocols.
The analog for DKIM wouldn't work so well unfortunately, because DKIM isn't end to end. E.g. DKIM could be changed so that the signature demonstrated that either the sending server or the recipient server signed the message-- this would be just as good for anti-spam, but really wouldn't improve the non-repudiation in most cases. Contrast that with applying the same approach to end-to-end messaging, where it gives you pretty strong non-repudiation.
Uh... no RFC822 headers from the Hunter Biden emails were ever released, certainly none with a passing DKIM signature. I read that Post article with a microscope. This never happened.
And in fact, the transparent truth that these appeared to LACK the trivially producible authentication layer is one of the big reasons that the more right-leaning entities among the tech community stayed far away from this subject.
It's extremely rare for journalists in traditional media to publish email headers, even when people are accusing messages of being inauthentic and the DKIM would go a long way towards certifying them and when people are begging for them. I think I'm aware of only one other instance, though I've personally begged journalists for headers multiple times even in some cases where I was a subject of the article and not some random nobody.
From the perspective of protecting sources it's probably good advice to avoid publishing any kind of opaque header-stuff. But also, most readers wouldn't know what to do with the information and -- less charitably-- publishing evidence moves away from the framework where readers accept the reporters word on blind faith.
Your position was entirely understandable: I declined to link to the repo or the two flagged HN threads about it, though I considered it, because I thought it would increase the risk that my comment would get flagged. I think your reply had the surprising consequence of making a really good example at how effective the suppression of info like this is at distorting the public discourse.
so what's the point?
But someone could threaten to speak to your insurer about a medical condition mentioned in an email.
Perhaps a simple timestamped based appendage can be added for the sake of email client authentication. In other words reject the email if the signature is older than a few hours/minutes.
Email servers get hacked all the time, right? A disgusting amount. Its almost like security is really difficult; in fact, its difficult to secure both the emails and the DKIM private keys. They're usually on the same server, after all.
If a DKIM private key gets hacked, and the world relies on DKIM to provide non-repudiation in the verification of email leaks, then a hacker who obtains someone's DKIM private key could forge an email to contain any content they want, sign it with that private key, then leak that. The world says "its DKIM validated, Trump really did kill a litter of puppies twelve years ago", Trump tries to say "no, my email server was hacked, i never did that but they got my DKIM key" and who the hell would believe him? The headlines have already been written, and the argument against it is some crazy technical terminology a hundredth a percent of the population actually understands?
Ok, well, maybe you should rotate DKIM keys. Not necessarily make the private portion public, but at least rotate them and totally destroy the old private keys. But, again, if an email server is misconfigured enough to leak data, then its likely the admin is incompetent enough to also not be rotating keys. Moreover, unauthorized access to a server could happen over a period of years, during which hackers collect the rotated DKIM private keys while letting the admins think they're being deleted correctly.
The problem here isn't really DKIM; its the public's perception of what it was designed for. Technologists invented something, journalists discovered it, read a wikipedia article, and thought "woah we could use X for Y". So, I think it makes sense that we need a big name like Google to come out and say "Stop, this is not what this was designed for, it has major limitations in being used for that, and we're talking about real-world consequences like ruining potentially innocent peoples' lives."
Sadly that's not the case.
I contacted Bruce Schneier a few days back and he claimed that Robert Graham is lying and that this was fabricated, in addition that one is unable to establish the integrity and authenticity of a message by using DKIM.
I personally think that if Bruce Schneier is wrong and one is indeed able to establish the integrity and authenticity of a message by using DKIM then it is useful for the one receiving the message to prove to others that the mail indeed came the one who sent them the message. Consider a harassing email or a promise for example.
The Hunter Biden email is a good example.
I initially thought it was a garbage tabloid drop, but once I read Rob Graham's analysis, it felt very refreshing to have a real nugget of truth based on math. While the context of that content is up for debate, the truth was essentially undeniable (unless you subscribe to the 2016 private key being stolen).
We need nuggets of truth.
DKIM is not meant to validate conversations, it's meant to validate single messages for the purposes of spam prevention. Just because I can cryptographically validate selectively chosen messages from someone's mailbox, I don't have any proof that the conversation happened as presented.
There's a good reason why eliminating non-repudiation has been a goal of messaging protocols since OTR in 2004.
What right does Google have to force this onto us. If I want it, I'll chose it.
The idea I consented because the information was there somewhere and I should have know the complexities is as BS as hidden terms and conditions.
What annoys me is if you're pro fascism and want to force tracking onto people, just say it. But stupidity about how this isn't totalitarian is unforgivable. I have a right not to be tracked.
The only one I can imagine is that Google wants to get some positive PR out of it. Other than that it seems to me like Google will just ignore this as they ignore anything else they don't see as in their benefit to exert effort on.
P.S. This brought back memories. To anyone unaware of this, read about Pizzagate. You'll find that it has supposedly been debunked as a "conspiracy theory"... except for the emails which we know are legit.
Basically anybody could use those signing keys to fake email from a politician or celebrity. Imagine the headlines “Celebrity X account hacked, here are the emails, cryptographically verified by Google”
Of course, informed people will know that anybody could have faked them, but I would guess normal people would be fooled. In addition, there is no way to say the emails are definitely fake. At least now, we can tell between actual leaked emails and fake emails.
No, you can't. Google used to use 512- and 1024-bit RSA keys for DKIM signatures, both of which are comfortably within the means of small-to-medium-sized nation states. They currently use 2048-bit keys, which will probably be crackable within the next decade.
DKIM is providing a false sense of non-repudiation here, one that it was never designed (much less correctly implemented) to provide.
An alternative would be for email servers to strip the DKIM headers on inbound emails after recording that the email was validated. The email stored at rest then no longer provides non-repudation. Nothing is stopping you doing this today.
That's why he says Google also needs to publish the private keys.