Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, this is the point. Most (nearly all?) of the publicly available providers a user is likely to use won't allow you to use their MTAs and set From headers in a way that would impersonate someone else on that domain, provided you're authenticated as yourself.

So pointing out DKIM only authenticates the domain only weakens the argument from "UserX at Gmail sent this email" to "UserX at Gmail sent this email provided no one found a suitable, currently unknown exploit at Gmail or performed an inside job".

For a journalist and most juries, provided the absence of any reasonable suspicion or evidence of weaknesses / foul play at Gmail, both statements have equal strength.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: