A new security vulnerability has been discovered in PGP (and GPG) that affects a range of email clients and plugins. To protect yourself, EFF highly recommends that for now you uninstall or disable your PGP email plug-in. #efail 1/4https://www.eff.org/deeplinks/2018/05/attention-pgp-users-new-vulnerabilities-require-you-take-action-now …
If it's a crypto problem it could be something like using "invalid" keys (e.g. RSA > modulus) that when decrypted, the success or failure thereof leaks one bit of your key, and then you use image embeds to ping back the result.
-
-
hmm, interesting. If so, I wonder why they only identify email as a remedial step... "immediately disable and/or uninstall tools that automatically decrypt PGP-encrypted email"
-
My cynical guess is they only looked at the email use case and are negligently ignoring everything else.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.