Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A sufficiently powerful adversary will simply steal your emails. That's the actual real threat, not that the adversary will convincingly lie about you. That part they can already do without the benefit of your emails.


An adversary with sufficient impunity will simply lie and make things up.

DKIM without rotation and disclosure provides the capacity to do so with cryptographically provable integrity. Green's paper lists instances in which this has happened (as a proof-of-concept demmostration of the risk), and may have happened.

DKIM key rotation and public key disclosure at least denies adversaries this.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: