Before anyone freaks out about "efail", realize that using it would be: 1) extremely easy to detect 2) archived in your target's email As an attacker, I could not care less about this technique. It's intellectually neat, but operationally stupid. https://efail.de/efail-attack-paper.pdf …
-
-
I don’t know the details, but this disclosure has dragged on for weeks. I’m pretty sure major mail client vendors were in the loop. Why they haven’t patched, IDK.
-
I mean, even if Google surveyed all of Gmail for indicators of exploitation I'm pretty sure they'd find none. An attack that leaves the exploit payload in your target's inbox but does not provide code execution to clean it up is pretty useless IMHO.
- 1 more reply
New conversation -
-
-
I think you’re confusing one bug with an architectural failure. I’d like it too if Signal completely ditched Desktop, but it’s miles and miles ahead of email even with it. Empheral communication and minimized metadata are huge wins for Signal.
End of conversation
New conversation -
-
-
unless you don't want to be identified by a phone plan that you pay for, then you can't use Signal
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.