This sounds like multiple RCE issues in common PGP and S/MIME software, but the details are vague so far. Or it could be a side channel issue. Hmm.https://twitter.com/EFF/status/995906839958061056 …
The only reasonable nasty cryptographic issue that fits the advice is a key disclosure side channel problem (receive encrypted email, somehow leaks part of your decryption key back).
-
-
My guess is it affects everything using PGP/GPG, but focusing on narrow use cases for no particular reason is par for the course for stupid named, media whored vuln disclosure these days. ¯\_(ツ)_/¯
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
or something leaking _in outbound emails_
-
They specifically mentioned automatic decryption in the post. > immediately disable and/or uninstall tools that automatically decrypt PGP-encrypted email.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.