A new security vulnerability has been discovered in PGP (and GPG) that affects a range of email clients and plugins. To protect yourself, EFF highly recommends that for now you uninstall or disable your PGP email plug-in. #efail 1/4https://www.eff.org/deeplinks/2018/05/attention-pgp-users-new-vulnerabilities-require-you-take-action-now …
-
Show this thread
-
This Tweet is unavailable.
-
They're not saying you should use plaintext, they're saying you should use something else until the bug is fixed. This is probably a remote code execution bug (or an active key disclosure flaw). You shouldn't *decrypt* (untrusted) incoming email [which could be malicious].
1 reply 0 retweets 2 likes -
Seems to me what they are actually saying is that automatic decryption of incoming messages, and the handling thereof is the issue... nothing to do with transmitting / decrypting / reading encrypted messages in a "safe" environment.
1 reply 1 retweet 4 likes -
Replying to @attiegrande @marcan42 and
I suspect the automaton possible with something like JavaScript being the culprit, and the email client's "features" bring far to cooperative... possibly linked with storing plain text after initial (and automatic) decryption of incoming messages.
1 reply 0 retweets 0 likes -
If it's a crypto problem it could be something like using "invalid" keys (e.g. RSA > modulus) that when decrypted, the success or failure thereof leaks one bit of your key, and then you use image embeds to ping back the result.
1 reply 0 retweets 0 likes -
hmm, interesting. If so, I wonder why they only identify email as a remedial step... "immediately disable and/or uninstall tools that automatically decrypt PGP-encrypted email"
1 reply 0 retweets 0 likes
My cynical guess is they only looked at the email use case and are negligently ignoring everything else.
-
-
0 replies 0 retweets 0 likesThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.