Here are instructions for disabling the Enigmail or GPGTools plug-ins in some common email clients: Thunderbird: https://www.eff.org/deeplinks/2018/05/disabling-pgp-thunderbird-enigmail … Apple Mail: https://www.eff.org/deeplinks/2018/05/disabling-pgp-apple-mail-gpgtools … Outlook:https://www.eff.org/deeplinks/2018/05/disabling-pgp-outlook-gpg4win …
-
-
Show this thread
-
More details about the vulnerability will be made public on 2018-05-15 07:00 UTC. We will release more explanations and analysis then.https://twitter.com/seecurity/status/995906576170053633 …
Show this thread -
For now, do not decrypt encrypted PGP messages that you receive using your email client. Instead, use non-email based messaging platforms, like Signal, for your encrypted messaging needs.
Show this thread -
EFF took a close look at the
#efail PGP vulnerability. Here’s how it works in plain-as-possible language, and why we’ve recommended—for now—users disable PGP email plugins.https://www.eff.org/deeplinks/2018/05/not-so-pretty-what-you-need-know-about-e-fail-and-pgp-flaw-0 …Show this thread
End of conversation
New conversation -
-
-
...WHAT?
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Like others stated it's a vulnerability in some email clients, not in GPG itself. I expected much more of
@EFF, this misinformation is very disappointing. - 1 more reply
New conversation -
-
-
Ainda bem que não uso PGP e meus emails são todos inseguros kkkkk
-
por vacuidade nem precisa se preocupar kkkk
-
Eles recomendam desinstalar o PGP (recomendação estranha anyway), isso já fiz!
- 1 more reply
New conversation -
-
Lessons learned from
#efail: * Using HTML mail undermines encryption * Use text mode for emails if encryption is important * Don't panic and read more than the headlines * End-to-end encryption comprises client softwareThanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
@threadreaderapp unroll this please - 1 more reply
New conversation -
-
-
Nice backdoor...
-
what is interesting is that the vulnerability caused by a bad implementation of the PGP paper from pgp/openGPG clients. clients like protonmail are not affected since they implemented PGP with love.
-
Using
@Protonmail for 2 years now. I'm pretty amazed by it.
End of conversation
New conversation -
-
-
Disappointed in the EFF over this vuln hype. You hurt your trustworthiness by playing into this petty, hyped, and inaccurate disclosure
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.