Compsci guru wants 'right to be forgotten' for old email, urges Google and friends to expire, reveal crypto-keys
- Reference: 1605770650
- News link: https://www.theregister.co.uk/2020/11/19/dkim_encryption_expiration/
- Source link:
He has asked the Gmail goliath, as the largest commercial email service, to rotate its Domain Keys Identified Mail (DKIM) encryption keys periodically and to publish old keys to reduce the incentive for hackers to steal and leak email messages.
In so doing, he's advocating for a "right to be forgotten" for aged email, or more precisely for the ability to plausibly deny authorship of messages published without permission, after a certain period of time.
In an [1]online post published earlier this week, Green argues that DKIM has become "a monster."
As he explains, email service providers like Google's Gmail add a DKIM cryptographic signature to email messages. Used in conjunction with other email security protocols like DMARC, which can prevent cryptographic signatures from being removed, message recipients can be assured of the authenticity of signed messages and their contents.
But Green is concerned that the ability to verify message authenticity incentivizes hackers to steal email. DKIM, he argues, was designed to fight spam, not to tie people to their messages forever.
"This new non-repudiation feature was not part of DKIM’s design goals," Green says. "The designers didn’t intend it, nobody discussed whether it was a good idea, and it seems to have largely taken them by surprise. Worse, this surprise feature has some serious implications: it makes us all more vulnerable to extortion and blackmail."
It also enables reporters to authenticate leaked email messages, like those published by Wikileaks in 2016 from former Obama administration counselor John Podesta, by news organizations in 2017 covering messages sent by President Trump’s personal lawyer Mark Kasowitz, and by others reporting on matters of public interest. As Green points out, the Associate Press offers [2]a shell script to assist investigative reporters interested in verifying DKIM signatures.
Nonetheless, Green contends DKIM's unintended side effect of permanent accountability should be rolled back. He says that while people may find the consequences agreeable "because it suits a partisan preference, or because the people who got 'caught' sort of deserved it," everyone is potentially vulnerable to being victimized.
"[B]ad things happen to good people too," he says. "If you build a mechanism that incentivizes crime, sooner or later you will get crimed on."
If Google were to publish its DKIM keys after a certain period of time, then messages signed with those decommissioned keys could no longer be convincingly tied to a given author.
That's not obviously a desirable outcome at a time when lack of accountability for online communication has made misinformation and disinformation a major concern around the world.
Green allows that cryptographic authentication can be useful in some circumstances but points out that no commercial email customer has asked for DKIM as a default feature. If people want to author messages that can be cryptographically linked to them, they can choose to use tools like GnuPGP.
As an alternative to DKIM, Green and two colleagues, Michael A. Specter and Sunoo Park, have proposed a way to create [3]cryptographic signatures that expire , becoming forgeable after a certain period of time without invalidating the associated public key for unexpired signatures.
The Register asked Google whether it would consider rotating and publishing its DKIM keys. We've not heard back. ®
Get our [4]Tech Resources
[1] https://blog.cryptographyengineering.com/2020/11/16/ok-google-please-publish-your-dkim-secret-keys/
[2] https://github.com/associatedpress/verify-dkim
[3] http://www.mit.edu/~specter/blog/2020/dkim/
[4] https://whitepapers.theregister.com/
Re: One wonders ...
Elsewhere we have public discussion (and outrage) about the insertion of so called "backdoors" into public messaging services. These backdoors allow snoopers to read otherwise inaccessible messages. This discussion about email attribution has a similar flavour, but this time the discussion is about the attribution of a message to the originator.
*
Both problems can be solved at a stroke by using private ciphers. This approach makes the use of backdoors moot, and it also solves the attribution problem since, although the message can be attributed to an originator, only the originator and the recipient can understand the message!!
*
Problems solved (plural)!!
*
04a315ce0NxJ0Xnl0ney1gyn1F3j16ff1AMY1DiO
0rFg0akv13lK0Ocy08Qc1khz1htq1B711XRs15B4
0B1r15810mjb01gX1NwQ0Ivp1Ykq0NUH1Fin06zd
0ETm0sCQ0jH00oXY1I9=1U9b11oN0rQ41RbX0SCV
0Vfi1Gge0z8X00k806H50mPj0pE41f4E1LR$1j3o
Re: One wonders ...
I regularly email microsoft calling them cunts
Happy to stand by those emails too
Re: One wonders ...
I would email Google and call them the same if only I could find an email address for them...
Re: One wonders ...
I tried postmaster@google.com and absue@google.com, when the DoSed out Internet connection, I just got a reply saying they get too many email messages to those accounts and they are automatically deleted and never read...
He says that while people may find the consequences agreeable "because it suits a partisan preference, or because the people who got 'caught' sort of deserved it,"
This proposal appears very partisan to me. One party in particular, which has recently been voted out. That's the only high-profile situation I know of where someone habitually denies saying something that they definitely did say and may benefit from muddying waters to obscure the truth.
I think you will find all political parties would prefer to be able to deny future emails.
Just looking at the last few months, both the Trump camp and the Biden family have very high profile news articles involving mails verified by using DKIM signatures.
Verba volant, scripta manent
It's a so old saying it's in Latin. It's far better if people understand the need to think twice before sending an email.
Quoting latin and not translating it?
You are Boris Johnson and I claim the right to kick you in the 'nads.
Any repetition and I will reply in Perl.
Are we meant to be surprised that a bunch of muppets tried to solve a problem and created multiple more in the process?
Welcome to software development, the place where people sneeze and declare the snot on the screen as finished code, with their manager nodding in agreement with statements like “just get it out the door making money”
Does anyone else get the impression we aint got a scooby doo with what we’re doing, and its basically a giant shitshow?
Don 't think Compsci Guru fits here...
The idea of releasing Private Keys so that there is "no proof that an email wasn't spoofed" is fundamentally dumb. Also, I hope that Google don't configure their HSMs to allow random copies of private keys to be floating around somewhere...
Re: Don 't think Compsci Guru fits here...
I think you misunderstand... The proposal is not to release keys used for signing. It is to release keys used for spam prevention, which can accidentally be used for cryptographically verifying mails that the sender did not intend to be cryptographically signed.
Signing and delivering are two separate processes and I should be able to do one without the other if I wish (although you are welcome to make a decision that you are not willing to receive mails which the sender chose not to sign, of course).
Don't start with Google
He makes a good point: the act of sending an email should be separate from the act of (cryptographically very strong) signing an email. The tradeoffs involved are very different and should be considered separately.
His mistake, though, is starting with Google. It would be much better to start with big commercial organisations. Just like they have policies on deleting received emails after some time to protect themselves from future liability, they really need policies on publishing their DKIM keys regularly to legally protect their sent emails (by giving them plausible deniability).
Once it becomes a standard requirement in the commercial world, people like GMail will fall in line.
Meanwhile, as I operate my own mail server, I will start doing it as a matter of principle.
Re: Don't start with Google
::mental note:: Graham Cobb does not stand behind everything he puts into email. It is therefore safe to disregard everything he puts into email.
Re: Don't start with Google
As you wish. You are certainly at liberty to choose not to receive emails from me, or anyone else. You are welcome to require that emails I send to you are signed.
Just don't mix that up with the delivery process.
Just like in the real world: in the UK there is no requirement or expectation that postal mail has a return address. Some people might choose not to open post which does not have a return address on the envelope. That is their choice. But the post office does not add return addresses to all email just because some people make that choice.
Re: Don't start with Google
I do not think you properly parsed what I wrote. Try again?
Re: Don't start with Google
This isn't cryptographically signing an email - that would be PGP or S/MIME. This is verifying the email was sent from the originating domain and not spoofed, it doesn't verify the account on that domain.
The DKIM only verifies that the sending domain authorized the sent email.
Re: Don't start with Google
That was the intention of DKIM. However, the point being made, is that DKIM does, accidentally, also verify that the email contents have not been changed since the mail was sent. That was never the intent of DKIM and it opens corporations up to much more liability.
Re: Don't start with Google
As it is a legal requirement for every business to keep 10 years worth of ALL email correspondence in an unalterable archive over here, I don't see DKIM making it any better / worse. If the email was sent from the source domain, the source domain has to legally have a copy of the email on hand anyway.
The lawyers still need a court order to get access to the original message from the archive.
I think DKIM brings more benefits, and for me, the whole point of DKIM is that I don't get an altered message. If it didn't verify the email was not altered during its journey, I would have thought that would have opened up even more problems - I send a message saying, "hi, thanks for the info" and the recipient gets a "hi, you a piece of s***"...
I would say that it reduces liability, because any message that isn't probably DKIMed is obviously a fake.
He wants to stop "incentivising crime"
by making it possible for everyone to plausibly deny that they sent an email.
And in the process, making it possible to plan crimes using email and get away with it, because all such emails would then be inadmissable as evidence as it would no longer be provable that the sender actually sent the email.
Hell of an unintended consequence.
Um, in a word : no
You send me a mail, it becomes mine to do with as I please, and the fact that you're the one who sent it is not and never will be deniable.
What kind of stupid idea is that anyway ? The right to be forgotten concerns news articles on people who didn't them and would like the article to be removed from search engine results.
That is a far cry from an email situation. I know you sent it, you know you sent it. You might regret sending it, but you did. No use denying it five years later.
"sooner or later you will get crimed on"
Too late, alas, for the english language; it is already particularly victimised by the tech fraternity.
Re: "sooner or later you will get crimed on"
Did the great Bill Watterson teach you nothing? Verbing weirds language . Weirding is not a bad thing, especially in informal writing/speech. Unless you lack the humo(u)r gene, of course, in which case I feel very, very sorry for you..
Re: "sooner or later you will get crimed on"
Languages mutate, sometimes in ways that seem ugly to those not using the newer forms. Try to prevent it and you are just an old git shouting, "Get off my lawn!"
One wonders ...
... what skeletons Matthew Green has in his closet, and why he sent them via email in the first place. Didn't this supposed computer literate person know that one shouldn't put anything into email that one wouldn't shout from the roof-tops? Once it's sent, it is gone, and completely out of your control.