Re: mail signing history, was Call for Community Feedback: Retiring IETF FTP Service

Michael Thomas <mike@mtcc.com> Wed, 18 November 2020 22:41 UTC

Return-Path: <mike@fresheez.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C535F3A0DFA for <ietf@ietfa.amsl.com>; Wed, 18 Nov 2020 14:41:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.65
X-Spam-Level:
X-Spam-Status: No, score=-1.65 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.25, NICE_REPLY_A=-0.001, RCVD_IN_DNSWL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=mtcc-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bEBAdSCXcXIh for <ietf@ietfa.amsl.com>; Wed, 18 Nov 2020 14:41:28 -0800 (PST)
Received: from mail-pf1-x42e.google.com (mail-pf1-x42e.google.com [IPv6:2607:f8b0:4864:20::42e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AA6443A0DEB for <ietf@ietf.org>; Wed, 18 Nov 2020 14:41:28 -0800 (PST)
Received: by mail-pf1-x42e.google.com with SMTP id c66so2527724pfa.4 for <ietf@ietf.org>; Wed, 18 Nov 2020 14:41:28 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mtcc-com.20150623.gappssmtp.com; s=20150623; h=subject:to:references:from:message-id:date:user-agent:mime-version :in-reply-to:content-transfer-encoding:content-language; bh=NiURSP/nXH0xbPY22u4IPNDcaVUjbPMja16IRWLenkI=; b=oF19RIN0oDfRKBqAfXc9qRLAtuLH5JPi01LWGPPKx+0K3tFR9+ES7TcIb5wpXIK8jk vIoT6AQfK3ObxbADY+U3MaDaMxUtQRcfdnMe9Ykc77dmPFfbp3u5PpamhpFv1ZRJi+Rv fqu/wXj8ZickAb+/muPGn15B7AGczHPezLykS68tqZ2hyWO7ZrdNof+UcU7fycH3ltA/ oRFGKApjV405FfI9SFrhAxyE+NJBUjxF3F8/wyFsQa56lemvpz/492AnG4rNCS3Oy6gl ZHqumsYPM+htOY8SDV8MpfqShT6xsFfcXboUhp1ioMurclTZSRAopEYMwG3uKvwj5uya ytMA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-transfer-encoding :content-language; bh=NiURSP/nXH0xbPY22u4IPNDcaVUjbPMja16IRWLenkI=; b=Ai5Z884Qzr0dEYYOxL99yYXMou/nsyAy6WH/8uol6l7frGgzhnee8ZK2PomzL7RsXD mr5MTD4zQWwig4wg9IY2i7hZnuff13AD22dAeBxFoiWwc1edPEO0dAf28/LGN92d9pm4 zeFqx1jkneW2YFux1w1oeUFZ4f9TYGPdAm5FxKOMW46Uti40wN4XaMIvkDqD6SgIBRwu BXwEZfl0nyGad4uzdoc/vHTASb/SPgAMScUFOH4XBXlVkSeFwblMia4FyeVpOJSMeAiR PXCoFtabz0Gm3v9V9vt2rSEaSVtHnbpWh1O4PW8olxa4+xU/t+Po4zUOSQW+/1a8N80z IO2w==
X-Gm-Message-State: AOAM532aAHkXWoX1LFya6CmZlqeH4RSFK472rGeaJcjOp/miINm3vQir D27MfhTA0dqNe2KglsZqp31d1zlqDRbAdA==
X-Google-Smtp-Source: ABdhPJxEDFRlJ32SrhXM4HfD702jYMCCwR9GSVLj2mo2nl9gJCMB3eV6FD1XQLvQUyPNS9MxYHJ1WA==
X-Received: by 2002:aa7:8616:0:b029:18b:421b:9168 with SMTP id p22-20020aa786160000b029018b421b9168mr6656855pfn.33.1605739287265; Wed, 18 Nov 2020 14:41:27 -0800 (PST)
Received: from mike-mac.lan (107-182-37-5.volcanocom.com. [107.182.37.5]) by smtp.gmail.com with ESMTPSA id k17sm7558099pgh.41.2020.11.18.14.41.26 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 18 Nov 2020 14:41:26 -0800 (PST)
Subject: Re: mail signing history, was Call for Community Feedback: Retiring IETF FTP Service
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>, ietf@ietf.org
References: <01RS5CFAY5S0005PTU@mauve.mrochek.com> <20201118211937.01A22278DC6F@ary.qy> <01RS5Q2L2D6Y005PTU@mauve.mrochek.com> <5239b5-3d2-4079-5f5d-f4a2e0c5552@taugh.com> <c9c6d83e-cf79-262e-ae0e-361050026912@mtcc.com> <e6c9a6b0-f412-76f0-24a4-d11512c1be36@cs.tcd.ie> <5b56c99c-d4ee-1275-5479-3aef9ab2ab11@mtcc.com> <abb3c271-7a9a-b3bc-1f4a-c68b2f55b35d@cs.tcd.ie>
From: Michael Thomas <mike@mtcc.com>
Message-ID: <20eacf90-c670-02b3-c1d9-4de0574f7a05@mtcc.com>
Date: Wed, 18 Nov 2020 14:41:25 -0800
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:68.0) Gecko/20100101 Thunderbird/68.12.1
MIME-Version: 1.0
In-Reply-To: <abb3c271-7a9a-b3bc-1f4a-c68b2f55b35d@cs.tcd.ie>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf/BboC-ZBFTaHv_jIu7_Cj719h4r8>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 18 Nov 2020 22:41:30 -0000

On 11/18/20 2:29 PM, Stephen Farrell wrote:
>
>
>>> Publishing the private key enables various forms of
>>> denyability - if someone claims msg1 is original
>>> anyone with access to the private can produce a
>>> msg2 that seems as cryptographically correct but
>>> is clearly bogus (e.g. containing lottery numbers
>>> that post-date message timestamps).
>>
>>
>> Yes, i acknowledge that above albeit obliquely. What i don't see is 
>> how you align providers goals' with individual users' goals.
>
> My guess is that email service providers that are
> concerned about potential leakage of message store
> content would be motivated to do this so as to
> re-assure their users and/or maybe help avoid future
> liability (financial or moral).

It would be pretty disasterous regardless of a valid DKIM signature. 
Most people have no clue that email *also* prevents deniability but  the 
damage would already be done because nobody's going believe that 
somebody's long cheating email romance was just elaborately spoofed. 
Same goes for providers if they screw up: an invalidated DKIM signature 
is not going to protect them from lawsuits.

MIke