This sounds like multiple RCE issues in common PGP and S/MIME software, but the details are vague so far. Or it could be a side channel issue. Hmm.https://twitter.com/EFF/status/995906839958061056 …
Yeah but if it's an application layer issue like that, why is the OpenPGP "usage" relevant and success/failure to decrypt?
-
-
This Tweet is unavailable.
-
I guess it could even be something as dumb as <img src="http://eve/-----BEGIN PGP MESSAGE-----......"> (or the S/MIME equivalent)
- Show replies
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.