Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?
Calling for the ability to remove it during the years 2016-2020 in order to "protect politicians from blackmail" is not only of deeply questionable value but of suspect motivation. Who is the author interested in protecting?
Here, have a link, from 2004:
As you know, there are many legitimate needs to authenticate messages of strangers.
For example, when you order products over the internet, an e-mail of your purchase is often the only proof of what was agreed in the purchase. If there is later a dispute between the buyer and the seller, the email can be used to repudiate lies. In particular, if a third party (like a court) can authenticate the message, the honest party can convince the third party that the dishonest party is being fraudulent.
You are exaggerating when you claim that there is no legitimate need to authenticate messages as a third party.
What makes this hard is that email is responsible for too much crap. No single user interface should carry:
1. Party invites
2. Private messages to your spouse, therapist, pastor, etc.
3. Marketing messages
4. Password recovery requests
5. Financial transactions
We've just shoved them all into email because it's there.
In the real world it doesn't matter which cryptographic protocols are theoretically available for use. What matters is which protocols everyone else is using. For example, in the case of receipts for purchases on the web, literally everyone is using email. You will not be able to get amazon to sign a receipt with gnupg.
If you want to embark on a path of convincing the world to move away from email, that's great, good for you. Just don't pretend like removing non-repudiation from e-mails is a quest on that path. It's not.
Please explain how I can make amazon sign my purchase receipt with GnuPG?
I agree with you here. However, EMail was never designed to do this. Eg if you order products over the internet, how do you know that your opposing party keeps their DKIM key safe?
I get that email and DKIM was never designed for this, it's a side effect. Fingers were not designed for finger print evidence, but it's still nice to have evidence from finger prints, as a side effect from touching things. And the problem of key storage / keys leaking will not disappear even if you change to some different protocol.
I gave an example of a legitimate need to do X.
Your rebuttal is that... I'm confused? Yeah, you're gonna have to be more specific than that if you want to convince anybody.
I don't understand enough about all the issue to really know how I feel about it, but clearly there are trade-offs here that at least argue against expanding the scope.
First, thank you for the clarification.
Second, to answer tptacek's point, I understand that authenticating emails as a third party is an unintended side effect of the DKIM protocol. I understand that cryptographers would like people to move onto using other protocols for purposes like this. However, the suggestion that Google should periodically publish and rotate their secret keys, does not achieve this goal in any way. If Google were to do this, the webstore that you purchase items from, would not suddenly start using different protocols to authenticate purchase receipts, they would continue to send regular email... but those emails could no longer be authenticated. Or if we go back to the example in OP, the politician that's admitting to crimes over email, they're certainly not going to switch over to another method of documenting their crimes.
Edit: I was incorrectly using GPG as an example. I removed the incorrect example and let the point stand without it.
Edit: Hacker News doesn't allow me to post replies to the posts under this post, so I will answer by editing this comment. I'm addressing the following comment:
> Which counterexample is that exactly? Your counterexample involving a store is incorrect -- the store's email would still be authenticated for a smaller amount of time which would allow your server to verify that it is a valid email that came from the store's servers.
If you actually read my counter example, you will see that I wrote: "if a third party (like a court) can authenticate the message".
Yes, my email server can authenticate the email when it arrives, but that will be of little help later when I try to dispute claims in court. If the court can authenticate the email, that will be helpful to the honest party in the dispute.
Which counterexample is that exactly? Your counterexample involving a store is incorrect -- the store's email would still be authenticated for a smaller amount of time which would allow your server to verify that it is a valid email that came from the store's servers.
EDIT: Since you responded with an edit, I suppose I should as well. Btw, you can reply to comments below, but you have to click on the comment's permalink/timestamp (the thing that says "1 hour ago") first.
I didn't see the comment you are referring to because it was a very high up ancestor. I only saw the comment I replied to which doesn't mention courts nor third-parties, which is why I asked you for an explanation. Please don't jump immediately to the conclusion that I did not read your comment.
Regarding the content, hamburglar's sibling comment is spot on. Non-repudiability shouldn't just be an afterthought. Accidental non-repudiability can have negative consequences itself. For one, relying on the kind of poor man's non-repudiability that DKIM gives you leaves powerful central entities with the ability to forge email while convincing almost everyone that it is legitimate.
From reading everything that you wrote, I think that your thesis is that email, specifically, ought to be non-repudiable. That might be a worthwhile idea, but it should be presented as such at the forefront. If others agree that this is a valid and useful concept, then a non-repudiability mechanism could be added to email explicitly, just as DKIM was added. But don't use DKIM for this, since it is a poor substitute.
I fully agree.
> From reading everything that you wrote, I think that your thesis is that email, specifically, ought to be non-repudiable. That might be a worthwhile idea, but it should be presented as such at the forefront. If others agree that this is a valid and useful concept, then a non-repudiability mechanism could be added to email explicitly, just as DKIM was added. But don't use DKIM for this, since it is a poor substitute.
If the choice was between "DKIM for non-repudiability" and "a better mechanism for non-repudiability", of course I would support the better mechanism. But that's not the choice here. The proposal here is to remove this accidental, partial non-repudiability mechanism that currently exists, and replace it with nothing. That would leave the world worse off, not better. DKIM protects innocent people from being framed for saying horrible things, and DKIM protects innocent people from guilty people who do horrible things. And sure, sometimes DKIM might be used against innocent people in some way, but the balance seems heavily in favor of DKIM (from the perspective of innocent people).
I think the person you're talking to thinks this is very obvious and thus isn't stating it explicitly, but in the special case where you want an email to include non-repudiation, such as for a purchase receipt, the sender should just add non-repudiation to it in the form of a signature that's intended for that. Simple.
Ok, but this does not magically happen if Google publishes and rotates their DKIM keys. People will continue to use email for everything, but now emails can no longer be authenticated by third parties.
Let's not pretend that the world would move away from email if Google made this change. We both know that's not going to happen. Given that, can you explain why you think the world would be a better place when emails can be repudiated? When emails can be not be repudiated, innocent people can be framed for saying/doing things that they didn't do. DKIM protects innocent people from being framed. DKIM also protects innocent people against guilty people who commit frauds or other crime.
Please explain to me how I can make Amazon (or any other webshop) add non-repudiable contracts to their order flow? That's right, I can't. And no, I don't think that Amazon "owes" me non-repudiable emails, but now that we have non-repudiation by accident, it's certainly nice to have, and the world would be worse off if we removed that feature and replaced it with nothing.
Without non-repudiation, you don't automatically get to frame someone for whatever. You need to provide the usual (non-DKIM) evidence of whatever you're claiming.
And even with non-repudiation, you can still try and frame someone. Not having the DKIM signature might be suspicious in some circumstances, but it doesn't eliminate the possibility.
Second, "innocent" is not that simple.
I don't want my private communication to become public, or publicly verifiable. That doesn't mean I'm not "innocent". This is not a fringe concept: https://en.wikipedia.org/wiki/Nothing_to_hide_argument
"Give me six lines written by the most honest man in the world, and I will find enough in them to hang him." - Cardinal Richelieu
Yes, I agree we should have secure private messengers. But that has nothing to do with this discussion. First off, email is not a secure private messenger. Second, email would not become "more secure" by removing the accidental, partial non-repudiation that DKIM provides. Third, this comment chain that you are replying in right now, is about whether there exists any legitimate need for a third party to authenticate emails with DKIM after the emails have been sent. tptacek claimed that no such legitimate need exists. I've been arguing against this with a specific counter-example.
That's because we aren't discussing a proposal to switch from DKIM authentication to a different method of authentication. We're discussing a proposal to abandon the partial non-repudiation property that's accidentally provided by DKIM, and replacing it with nothing.
If you want concrete examples of how the partial non-repudiation property provided by DKIM is not "nothing", you have to look no further than the examples provided in OP.
Let me give you a scenario to consider. At my old company, there was a mail server that would DKIM-sign everything that was passed through it. Anybody who wanted to on the internal network could write an email with tampered headers (say, backdated, or "From:" someone else) and send it through this server. This was acceptable because the SOLE PURPOSE of this signing was improving SMTP deliverability. It tells other mail servers "yes, this SMTP payload actually originated from this company. Please do not treat it as spam." So given one of these signed messages, what can you argue about the contents? Nothing, other than "these did not come from a random spammer posing as this company."
You run risks when you assume a signature means something that the signer does not actually intend it to mean.
The example was that two parties are disputing a contract, the court is attempting to resolve the dispute, and the court has a need to authenticate the contract. Can you explain why you think that this is not a legitimate need to authenticate a document?
> I'm not sure (and decline to speculate) whether you're confused or malicious or some other problem entirely, but you are wrong.
You "decline to speculate", and then proceed to speculate anyway? Ok. Well, it's certainly easier to resort to calling me names, than actually defending your position with arguments.
Because it is not legitimate for a court to treat something that was not intentionally (ie, with something other than DKIM) signed as a signed contract. If one party did not sign that contract, a DKIM 'signature' doesn't change that. Conversely, if you have a argument that the document should be treated as a valid contract despite not having been signed, the lack of DKIM 'signature' is obviously irrelevant.
Not legitimate where? In Finland, where I live, there is no restriction on the form that a contract must take. A contract can be scribbled on a napkin, a contract can be oral, and yes, a contract can be written in email. You're claiming that a document should not be treated as a valid contract if it has not been signed, but Finnish law is pretty clear that a signature is not required for a contract to be valid. Furthermore, you claim that if a signature is not a requirement for a contract to be valid, then the lack of signature is "obviously" irrelevant. This is not obvious at all, and in fact is not true at all. As you surely know, sometimes the parties to a contract dispute what was agreed upon. Having a written contract is superior to an oral contract, because it is harder to dispute what was written, than it is to dispute what was said orally. In the same vein, it is harder to dispute a written contract with signatures, than a written contract lacking signatures. And in the same vein, it is harder to dispute an email that is DKIM validated, than an email that is lacking any sender validation.
No, I'm claiming that a document should not be treated as signed if it has not been signed. And drawing attention to (not "claiming") the fact that attaching^Whaving some third party such as Google attach a piece of networking metadata to it, does not constitute signing.
It sounds like you think that a "signed document" carries some sort of significance that an "unsigned document" does not carry, other than the value of the signature as evidence of a contract. I'm not aware of any such significance, at least not in the context of Finnish legislation. Perhaps if we are emailing a draft of a contract back and forth, the signature on a document can be used to specify which version is the agreed-upon contract as opposed to draft. But a similar proof could be attained without a signature, for example by recording audio of a verbal agreement which specifies the agreed-upon version of the contract. The signature does not carry any special significance.
In any case, no, I do not think that a DKIM signature is comparable to a handwritten signature. I would rather compare DKIM signature to fingerprints on a physical document. You might say "I've never seen this piece of paper in my life!" to dispute the validity of a paper contract, but your fingerprints on that paper would constitute significant evidence against your statement. DKIM signature of an email could be used in the same fashion.
No, he didn't, and to use quotes to claim someone said something that they didn't say is extremely disingenuous.
This sentence? "Serious secure messengers have been designed to avoid non-repudiation since OTR." I don't see how this sentence supposedly alters the meaning of the sentence that comes after it? At this point it seems like you just want to sow confusion. If I had misinterpreted your words in some way, you could have clarified the misunderstanding like 10 times by now. Instead, you choose to reply in snarks like saying I'm confused, or asking me to read your comment again. I don't think there's any misunderstanding. You took an extreme position that didn't hold up to scrutiny, and you don't want to defend your position or back down, so you just reply in snarks instead. If there is some kind of misunderstanding, please do go ahead and explain what the misunderstanding is.
No, it doesn't. The dispute isn't about the need for counterparties to authenticate each other. Yes, we all agree that it's good if email receivers can validate the authenticity of the sender. That's not at dispute. The question is, is it good if third parties also have the ability to authenticate the sender of an email at a later point in time (using DKIM specifically). tptacek claimed that there is no legitimate need for such a thing, and I provided a counter-example to that.
Absolutely, but this should be an opt-in feature (and not provided server-side, at that).
Why?
Legal signatures are heavily ritualized (blue/black ink only, initial here and sign there etc.) in most societies for good reason – it makes the signer stop for a moment and reconsider what they are doing, if the document they are signing is truly aligned with their intentions and so on.
As another analogy/food for thought: We have the technical means to record every conversation we ever have, digital or analog, public or private. Should we? If not, why not?
Why do you feel like email "makes no explicit claims" about the authenticity of emails? Laypeople are not even aware of the possibility of spoofing the sender field in emails. Technical people can check the "explicit claims" of a protocol like e-mail, SPF, DKIM, etc. to understand what it claims to do. In other words, email makes both implicit claims, and explicit claims about the verifiability of the sender field.
Introducing non-repudiation would violate everyone's expectations and create a total mess.
I'm saying this as someone who often and deliberately uses deniable messengers.
If the "man-off-the-street" expects email to have non-repudiation property, then how exactly would "introducing non-repudiation" violate their expectations?
(b) Thanks for the link!
(c) The IETF is such a shitshow for cryptography.
If you don’t like that status quo, get involved. They would love to have you @tptacek.
Suppose you are in an organization, and it needs to figure our whether an employee was saying a Bad Thing such as giving out company secrets or cursing people out “off the record”.
Yes, even with end to end encryption, Facebook and others can still let you prove the other person sent the messages when you need. The question is whether that is a good thing:
https://facebook.com/help/messenger-app/1165699260192280
My personal feeling is yes, yes it is. I make a more extensive analysis here:
ProtonMail makes you setup 3 CNAMEs for DKIM just so they can frequently rotate without your intervention or disruption. Sendgrid uses 2 for the same thing.
But bad things happen to good people too. If you build a mechanism that incentivizes crime, sooner or later you will get crimed on."
Also there's an argument that "good people" can be blackmailed for INVENTED misconduct, but wouldn't such fake emails be more convincing without the ability to verify their origins? Making real emails and fake emails more similar protects people who have their incriminating emails leaked, but it also harms the defence of people who have fake emails targeting them "leaked".
There's a high bar for obfuscating truth and I don't believe this argument meets it.
I guess you’re the type of person that would happily hand over all your personal files to the police on a regular basis as you have nothing to hide.
Personally I am fine with the idea (as represented in this comment https://news.ycombinator.com/item?id=25115654) that email is providing something similar to a "paper trail", and when you send an email you can expect that people can prove you sent it, should they get their hands on the email. However, I totally understand the position that private secure messaging is important and that email should default to that.
In the authoritarian argument, "you've got nothing to hide", is followed by "you are now forced to reveal all", in my execution it would be "you are accountable for all emails you send, forever, should they be released". I am ok with that specific lack of privacy in that context, but I can understand the position that non-repudiability should be opt-in, and privacy the default.
> that email is providing something similar to a "paper trail"
because paper doesn’t provide non-repudiation and never has done.
The whole point of a “paper trail” is the “trail” bit, as it provides providence of a sequence of actions or communications that logically fit together. Hopefully providing evidence for your side of a dispute.
There’s no need for email to be non-repudiatable to achieve this. In fact I serious doubt a court would care if an email is DKIM signed. Very rarely are disputes so simple and straightforward that proving a single email was sent is enough to produce an outcome.
In short DKIM non-repudiation by default gives up everyones privacy, to protect a tiny group of individuals engaged in extra edge case disputes, where the entire outcome of the disputes hangs on the validity of a single email.
At this point, I'm more inclined to believe that "democratic" and "noble" governments and agents are the ones maliciously pushing for "privacy" because it suits their power-maintaining agenda. I'm struggling to find compelling and valid reasons why we can't pursue a general solution that involves us giving all this "private" data to a government entity for legitimate investigations, fraud prevention and crime-solving whilst keeping that data free from abuse.
Because that's not logically possible. It would be nice if it were, but just think about it: if you give data to the government, humans can look at it. Can we ensure that the humans who look at it are good humans? No. Is there some mathematical way of signing and encrypting such that only good humans can look at it? No.
Okay, so it's logically impossible to keep bad people out mathematically, but maybe it's a practical problem and it doesn't matter in practice? Except no, there are tons of evil governments (CCP being the most obvious, but pick your poison), and even good governments are subject to the problem that people can bribed and secrets can be stolen if there is sufficient motivation. It's just not compatible with human nature to say "collect all this information on people, but only use it For Good Purposes."
While I understand the problem of evil governments, I broadly trust mine. I want them to have the power to investigate me, and my fellow citizens, for crimes. I don't want to love in a lawless country.
First of all, tax information in the United States was in fact abused by Richard Nixon, so it's not just a hypothetical possibility. It's a thing that already happened and requires safeguarding to prevent recurring. If there were a way of collecting taxes without the possibility of abuse, we would use it, but there's not, so we do what we can to balance things. FWIW, I think actually a lot of government records should be stored on paper and not in computers because hackers can steal 300m records overnight, but even very enterprising thieves can only steal one or two truckloads of physical records per hour.
Second of all, this information is just on another level. My tax information is basically not interesting to anyone except that it has my SSN on it, and SSNs are only interesting because the US has bad laws around "identity theft" and we don't properly punish corporations for giving out loans based on nothing but an unverified SSN. Could someone embarrass me by releasing my tax info? I guess if they really dug into my charitable deductions and found an embarrassing cause (a la Brendan Eich?) or that I was giving too little? For me, an average American, there is little or no reason to fear having my taxes used against me.
Email is just not like that. There are certainly emails I have send and received which I hope no one else will see. It's just not comparable at all. It's the difference between having $100 in your wallet (might be stolen but probably not) and $6m in your wallet (will absolutely be stolen if people know about it).
Should the government be able to investigate me? Of course! But investigations have happened for centuries before emails existed. Investigation does not require pre-surveillance of emails or covert surveillance. The simplest thing the government can do is arrest me on suspicion of X charges and then go through all my computers. That is 100% the government should be able to do! If they catch me destroying evidence, I should be charged with destruction of evidence. But that is different from empowering the government to secretly look at email. The part where the government collects my email should be public action that I am well aware, not a secret action done passively by breaking encryption.
Germany 1933, Donald Trump today, far right extremism in Europe are all examples of how trustworthy governments become evil governments.
Democracy doesn’t offer a defence against “evil” governments. Only that you need a majority (and frequently not even a majority) to vote for one.
If a government turns full evil, they don't need evidence against you, they can just lock you up without charge.
(One could imagine a police force that is effective enough to stop murderers, but not effective enough to stop dissidents. Such a police force would be more useful for a society that wants no murder than for one that wants no dissent.)
Why would we want to give up more?
Previously if someone, government or otherwise, wanted to learn about you, they would need to physically follow you, tap your phones, intercept your post etc. Warrants for searches were built around this.
Online, you can dig into the private life of someone on the other side of the plant who you’ve never met. With the application of computers you can dig into the lives of hundreds of people you’ve never met. All without leaving the comfort of your desk.
The opportunity for fishing expedition is unprecedented at the moment, and it always easy to justify a fishing expedition if you pick a horrific enough crime (child pornography seems to be the favourite right now).
Finally privacy is the strongest bulwark we have against government overreach. That doesn’t mean some top down conspiracy of a totalitarian-elect government. It can be normal everyday government administrators who decide to step outside their bounds for personal reasons, or belief of moral superiority.
Simply put, there’s no better deterrent for bad behaviour than hard work. Privacy makes bad actors work hard for their lunch. It makes the good actors work hard as well, but the solution to that isn’t less privacy, it’s more funding and resources for good actors.
> in an encrypted manner that has guarantees in place that only valid criminal investigations can decrypt
What constitutes a valid criminal investigation, who decides? Do you, does a prosecutor, a judge, the police?
Is it a valid to decrypt your data just see if you were at a specific location at a specific time? What about so the police can check a theory? How about to see if you joined an unsanctioned protest, smoked a joint, speed while driving, downloaded a movie?
Speeding and copyright theft are both criminal, are you saying that your happy to make it trivial to investigate you for these crimes an prosecute you for them?
It used to be criminal to engage in homosexual behaviour, and in some parts of the world. Once upon a time that would be a valid criminal investigation in the US. For a short while it was looking like abortions might become criminal in the not too distant future.
Privacy is a fundamental tool for allowing society to progress and change, and for avoiding totalitarianism.
Some sort of formal process with reasonable oversight the necessity of multiple points of compromise and/or collusion in order for the data to be abused for non-governmental use. Bottom line, I can't say I've "solved" the problem and have the perfect answer to your question. But I'm sure we, collectively as a society filled with smart people that want to move us forward, could put down some (fundamental?) tools/rules/processes that would negate the potential for abuse up until a certain point. Maybe we can't do 100%, but we could do 95 or 98%?
>"Is it a valid to decrypt your data just see if you were at a specific location at a specific time? What about so the police can check a theory? How about to see if you joined an unsanctioned protest, smoked a joint, speed while driving, downloaded a movie?"
Yes, very much so Yes! Especially the location based stuff as it's perfect for investigations without revealing details. "List all people that were within 50m of this crime location during this timespan." <-- that is so unbelievably powerful as a crime-solving tool, that I am baffled that we're avoiding it out of privacy concerns. As for the speeding example: That's probably another example of us already giving the data (car's black-box) to government (and private insurance companies) in order to facilitate an investigation.
But to your point about drug-use, speeding and copyright infringement. If we don't want something prosecuted then we shouldn't have it as a crime. But as it stands now, a bunch of what you mentioned is a crime. That represents an implicit agreement by all of us in society that says we deem those things punishable. We can't hide behind lack of capability to police said crimes, but still label them as such. That is ripe for offical-power abuse. For all we know, if we lived in a society where we had such strict enforcement of laws as I suggest, we'd potentially have greater churn and change in our laws to match the opinions of society as it changed and evolved.
> "Privacy is a fundamental tool for allowing society to progress and change, and for avoiding totalitarianism."
I disagree. I'm not seeing it. There is just way too much going wrong today in 1-st world countries whilst we have really good privacy for it to be the case. We're downright descending into totalitarianism and thought/opinion control territory, all whilst our "privacy" is mostly maintained and respected. Are you saying we need more of it? What would that look like to you?
> We can't hide behind lack of capability to police said crimes, but still label them as such.
Most laws are written with the implicit assumption it’s not possible to perfectly enforce them. That provides some natural wriggle room to interpret the laws, avoids the need to write a long list of when it’s ok to speed for example.
Perfect enforcement breaks all of that. A knowledgable police officer could almost certainly stop you on any day the week and find you guilt of some obscure and ancient crime that’s no longer relevant.
> For all we know, if we lived in a society where we had such strict enforcement of laws as I suggest, we'd potentially have greater churn and change in our laws to match the opinions of society as it changed and evolved.
How do you imagine society would evolve its opinions and change them in a world of perfect enforcement? How the gay community show the world there nothing wrong with their way of life, if they simply couldn’t live it?
How would society change its views on smoking weed, if it was impossible to smoke it?
It’s impossible for a society to change its view on existing laws, if it’s completely unable to experiment with ignoring, or re-interpreting them.
It would be like expecting a child to ask for food they had never eaten, and never seen anyone else eat. How could they possibly know it existed, much less if it was good or bad for them?
> I disagree. I'm not seeing it. There is just way too much going wrong today in 1-st world countries whilst we have really good privacy for it to be the case. We're downright descending into totalitarianism and thought/opinion control territory, all whilst our "privacy" is mostly maintained and respected
Hahahaha, seriously. You complain of thought control, but advocate for world where the government can watch your every move, and perfectly enforce every law. Have you read 1984? I see little difference between world in that book, and the one your advocating for.
> Are you saying we need more of it? What would that look like to you?
Yes I am. How can you control someone’s though and opinions if you don’t know what they are? How can a totalitarian government rule with an iron fist if they don’t know where their citizens are, or what they’re doing?
Totalitarian governments come into existence because people want control and order, and they’re great if you fit into that governments view of what control and order look like. If you don’t, we’ll there are plenty of genocides that can be studied.
[0] https://www.google.com/amp/s/www.theverge.com/platform/amp/2...
For the people who lack imagination: suppose I'm a public official, and a photograph comes out depicting me doing some kind of "dirty" sexual act. Maybe it's real; maybe it's a deepfake; but if confirmed to be real it certainly would do reputational damage. Non-repudiation by definition prevents me from disavowing it, to no social benefit, and it's an anti-feature, in the sense that the large majority of users would prefer to have the ability to repudiate certain message contents than not.
Non-repudiation should be opt-in.
Providers like Google reacted to the whole “Larry and Sergey” embarassment in the way you’d expect. Without giving the implications any serious thought, they quickly ramped up their keys to 1024-bit or 2048-bit RSA. This stopped the forgeries, but inadvertently turned a harmless anti-spam protocol into a life-long cryptographic authenticity stamp — one that can be used to verify the provenance of any email dump, regardless of how it reaches the verifier."
Note that the "few hours" attack here is only relevant if they were using easily crackable 512-bit keys. The author of this article suggests (and I agree) that the 1024 or 2048 bit RSA keys are not easily crackable. (see https://crypto.stackexchange.com/a/42830)
Maybe you are suggesting that someone could sign emails using the old crackable 512-bit keys. And they could, although we should disregard this as "not verification" given the weak keys. The article links to https://github.com/robertdavidgraham/hunter-dkim#short-dkim-... - which verifies an email using a since-rotated 2015 key (which was 2048 bits), although that github erroneously states that Google was using 1024 bit before that (they were using 512).
I would concede that the notion of "sometimes we should disregard some DKIM verifications based on the key length" is not easy to grasp and that email verification stories in the media could become muddier and harder to present. I would hope that interviewing experts gets you a reasonable estimation of how likely an email is to be legitimate.
The more I think about it the more I inch towards agreeing with TFA. If I need my email to be authenticated I can sign them with GPG. If the law enforcement needs to see if I did or did not send an email they can subpoena Google.
>Non-repudiation over time is a truly powerful property of DKIM'd email for a great many uses outside of blackmail.
Can you expand on this? I can't really come up with a use case that wouldn't be about associating somebody with an email they may want to distantiate themselves from.
Exactly. If one enters into an contract using an e-mail, then DKIM can be used as a proof to the court of law that the contract was accepted by both sides.
The 3rd party tried to say other company fell for a phishing email and it was their fault but because of DKIM it was immediately provable that instead 3rd party was compromised and email legit sent from their o365 and they were pretending like they didn't know this. This all got disputed maybe a year after email sent.
Love Matthew Green but I personally am not a fan of this proposal. It doesn't fully achieve what he wants bc its only gmail and timing of compromise would be key. Most of the email hacks have actually been very much in the public interest despite being unethical. Breaches also lead to more productive work by companies in better securing accounts and better protecting sensitive information which google has been doing with account security and adding expiring messages.
Like do we really want companies to just continue sloppily sending customer info in email bc they can deny its legit or should they focus on not getting this info compromised to begin with?
Also, for ransomeware groups that now post data when not paid, it is not really seeming like too big of a disincentive that there is repudiation regarding the files they post.
It shouldn’t be sprung on people without consent. It would be like saying it’s fine to keep a recording from someone else’s webcam because it might prove a crime later.
There’s a reason why justice systems have statues of limitations. People should need to look over their shoulders for the rest of their lives because of one poorly written email.
Are ppl who don't even know DKIM exists but know they have shady emails saved in the cloud or on their personal really just banking on repudiation and thats why they take no other action like deleting the email or putting more thought into emails they send? Seriously doubt it.
Exactly bc of statute of limitations, they would not have to look over their shoulders for the rest of their lives because of one poorly written email.
I certainly didn’t realise that DKIM can be used as a non-repudiation signature, I’m sure most people using email don’t.
Thus there’s no consent and I would say that non-repudiation has been sprung on me.
The duration has nothing to do with it. Just because you can keep a camera hidden in someones room for an extended period of time doesn’t mean it’s ethical or consensual to record them.
Finally statues of limitations don’t protect people from a trial in social media. Social media is just as capable as the justice system of destroying a persons life. Unfortunately Twitter doesn’t have a statue of limitations.
It would make a good TV drama plot, but courts don't work this way in real life. If that were the case, courts wouldn't be able to enforce contracts with wet signatures (which are straightforward to forge), or verbal contracts (which are valid contracts and regularly enforced).
In practice, you don't need to check DKIM in order to use an email as evidence of a contract, because the courts would more likely just use the many other threats and tools at their disposal to ensure that the email is not fabricated.
This is why, even though most contracts are not executed in a cryptographically secure manner, most contract disputes that land before the courts hinge on matters like breach of contract ("we agree on the original terms, but disagree on whether our actions upheld them") or disputes over the intended vs. actual meaning of the contract ("we agree on the text we both signed to, but disagree on the correct interpretation of that text").
Disputes over whether the text of the executed contract is authentic are rare in real life.
I'm pretty confident that I could sign an email with a DKIM key if that were published, however, there's nothing that would give me the confidence that I could forge a pen signature in such a way that not even an expert could detect the forgery.
> or verbal contracts (which are valid contracts and regularly enforced).
I'm not a a lawyer, but according to the first google result "the Uniform Commercial Code [...] requires that contracts for the sale of goods over $500 to be in writing".[1]
> Disputes over whether the text of the executed contract is authentic are rare in real life.
Maybe they are rare precisely because it's hard and risky to forge signatures.
[1] https://www.hg.org/legal-articles/are-verbal-agreements-bind...
Yes, but not all contracts do that. For example, any contract for services is not covered by the UCC.
In practice, this doesn't seem to mean that every time you buy an iPhone, Apple provides you a paper contract authenticated with an actual verifiable hand-signed signature of an authorised officer.
Actually, you are free to enter a contract in any way possible. It is vormvrij (translated: form-free). Excluded is the purchase of a house, as far as I know. But for the rest, you are free to come to an agreement via WhatsApp, Facebook, email, or a scrawl on a piece of paper.
https://smallbusiness.findlaw.com/business-contracts-forms/w...
And that's how a new contract gets signed! No need to fly someone 1500km just for that.
You want a specific scenario of a dispute between a vendor and a customer? Ok. Let's say I email Amazon's customer support to ask them if a specific order is going to incur customs fees, and the Amazon representative emails me back that the order is not going to incur customs fees. Then I make the order, and to my surprise, I do have to pay custom fees. I contact Amazon to ask them to compensate me for the fees, but Amazon now claims that they are not responsible for custom fees. At this point I would be protected by a copy of the email where they claimed that I would incur no customs fees. If I can demonstrate to Amazon that I have proof of their false claims, prior to the purchase, they will be inclined to compensate. If they refuse to compensate, I can (depending on jurisdiction) take my claim to small claims court and present my evidence there. In this case it's unlikely for anyone to actually validate the DKIM signatures, but it does matter whether email is generally considered to be non-repudiable. If you run a campaign to make email repudiable, and make sure people should know email is repudiable, then this email will be less convincing as evidence.
How many disputes like that have been resolved with DKIM?
Again: How many disputes like that have been resolved with DKIM?
The original email spec doesn't provide any security against forgeries. The "sent from" field in email is about as secure as the "sent from" field in physical letters. The only reason why laypersons consider email to be non-repudiable is because of additional protocols like SPF and DKIM that were implemented after the original spec. Without these protocols email would be considered repudiable, which OP considers to be a preferrable outcome.
> And that commerce existed before emails?
Yes, and? I'm not claiming that all commerce would come to a halt immediately if this campaign for email repudiability was successful. Of course commerce would continue to exist. But the world would be worse off, not better. There would be slightly more disputes, and dishonest parties would increase their chances of defrauding honest parties.
> You don't need DKIM to solve the issues you've pointed out.
Are you alluding to hypothetical alternative protocols for authenticating contracts? If you can make the world move off from email, that's great! Email is horrible! But if you can't make people move away from email, you won't make the world a better place by making email less secure.
> Again: How many disputes like that have been resolved with DKIM?
How many? As in, you expect me to have statistics on it? Are we pretending that when people resolve disputes, they mark their disputes in some kind of global database that we can query for statistics? You're not making any sense.
You really think that laypersons have any idea of what DKIM is?
> But the world would be worse off, not better.
That's the whole point of this discussion. You seem to be arguing that the world would be better with non-repudiable email. But then I ask how many disputes have been resolved with DKIM and you have no idea. So basically your argument has zero basis in reality.
You're asking for every email user to have non-repudiation enforced unwillingly to them in every email they send so that someone maybe someday may solve some imaginary dispute with Amazon by using DKIM.
The layperson doesn't have to understand the intricacies of email protocols, it's enough that they consider email to be non-repudiable. This is why a copy of an email typically suffices as "proof" of a contract. If you successfully run a campaign to make email repudiable, then laypersons will no longer consider email to be non-repudiable, and emails no longer suffice as "proof" of a contract. If you disagree with something I said here, can you specify which part it is exactly that you disagree with?
> You seem to be arguing that the world would be better with non-repudiable email.
Yes, the world is better off now, at a time when laypersons consider e-mail to be non-repudiable, compared to a hypothetical future where this is no longer the case.
> But then I ask how many disputes have been resolved with DKIM and you have no idea. So basically your argument has zero basis in reality.
So if I can't give the exact number of times that DKIM has helped in dispute resolution, then my argument "has zero basis in reality"? This doesn't make any sense. If I said that "the existence of courts prevents vigilantes", you could say the same thing: "well what's the exact number of times that the existence of courts has prevented vigilanteeism? ha! you don't know the exact number! your argument has zero basis in reality then." We could apply your logic to many other scenarios: what's the number of times that existence of guards has prevented prison breaks? What's the number of infections prevented by vaccines? We don't know the exact numbers for any of these things, and yet we can logicly deduce that courts prevent vigilantes, guards prevent prison breaks, vaccines prevent infections, and DKIM prevents breaking contracts.
> You're asking for every email user to have non-repudiation enforced unwillingly to them in every email they send so that someone maybe someday may solve some imaginary dispute with Amazon by using DKIM.
Laypersons already believe that emails have non-repudiation property. People are free to use secure messengers to communicate privately. When people choose to communicate with email, they are choosing non-repudiation over privacy. You are the one who is asking to change e-mail protocols so that they would work differently than people currently expect. I'm the one saying e-mail should work like people expect e-mail to work.
They consider it non-repudiable not because of DKIM, it's just a common misconception. People believed that before DKIM. They will still believe it if Google discloses its DKIM keys.
They totally should not believe it, though.
> So if I can't give the exact number of times that DKIM has helped in dispute resolution, then my argument "has zero basis in reality"?
Of course that's not what I meant, I don't care about exact numbers. Just give me some evidence that DKIM is relevant to solve disputes anywhere else other than in the minds of HN commenters. Otherwise your claim that the world is better off now with non-repudiable email has no basis in reality.
> they are choosing non-repudiation over privacy
They totally are not. They have no idea what are the properties of email. As an example, a non-tech friend of mine was once surprised that email does not provide any confidentiality.
I don't have a strong opinion on the chances of success that this campaign has. What I am saying is that if the campaign was successful in increasing the repudiability of email, that would make it easier for people to repudiate emails that they've sent, and that would be a bad thing in the context of resolving disputes. Do you agree?
I've raised VC money based on emailed contracts, bought businesses based on them, bought domain names.
It is incredibly standard and legal (in almost all of the jurisdictions I've worked in, which is a lot).)
The argument here is more that customers of gmail and other email services are not offered repudiation as a feature.
https://www.washingtonexaminer.com/opinion/the-hunter-biden-...
what about a _telegram_ message?
If you want transparency from your politicians, then you should demand unconditional archival and publication of campaign e-mails. Build transparency into the system. Leakers are not archivists, nor are they journalists. They are leakers, with an entirely different set of motivations and incentives which only sometimes align with journalistic or archival motivations. You as a member of the public will not hear about leaks if the person in possession of those leaked files has successfully extorted or ransomed the politician they came from. In this particular threat model, DKIM does not provide a social benefit to you as a citizen, it provides a monetary benefit to the leaker.
This. Publishing the DKIM keys would be a huge loss for email archivists and historians in general. E.g. a couple weeks ago Donald Knuth published all of the emails he's sent and received over the last 20+ years of his career[1], without DKIM how would we know that they are authentic?
[1] https://library.stanford.edu/blogs/special-collections-unbou...
I get my head around them by thinking they are bad? As in, not good. An undesirable property.
I mean I try to publish most of my interesting email conversations on the web, because every time you have a good email conversation that isn't public it's like taking a $100 bill and lighting it on fire. So I wouldn't ever personally use disappearing messages.
Literally the first rule of email is that if you wouldn't want it on the front page of the NYT then you shouldn't send it. The first national scandal involving email was Iran Contra in 1986. People should know by now not to put anything into an email that they wouldn't be comfortable with the entire world knowing. And while privacy is hugely important to individuals and essential for a healthy society, to me rotating DKIM keys feels like it's incentivizing people to use email incorrectly.
There is not a popular email system in existence that says
"To: myfriend@mailserver.com CC: Everyone [NON-EDITABLE]"
Quite the opposite is true. Gmail, for example, says "Google.com Mail protects your message during delivery As you add people to this message, this icon will let you know your message is secure."
As for authenticity, you could contact him, or his correspondents?
Yes.
> As for authenticity, you could contact him, or his correspondents?
Correspondents aren't necessarily going to tell the truth about the authenticity of their own email. And that's assuming they're alive, reachable, and willing to talk, all of which may not be the case now and will be the case with 100% certainty in the future.