This sounds like multiple RCE issues in common PGP and S/MIME software, but the details are vague so far. Or it could be a side channel issue. Hmm.https://twitter.com/EFF/status/995906839958061056 …
They specifically mentioned automatic decryption in the post. > immediately disable and/or uninstall tools that automatically decrypt PGP-encrypted email.
-
-
oh welp but if it was RCE you'd think there'd be a bigger fuss than "it could be used to decrypt existing emails", and "if you use PGP to handle very sensitive communications"?
-
I'm basically assuming all vulns are disclosed incompetently these days. Especially those coming from academics.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.