This sounds like multiple RCE issues in common PGP and S/MIME software, but the details are vague so far. Or it could be a side channel issue. Hmm.https://twitter.com/EFF/status/995906839958061056 …
-
-
Replying to @marcan42
"might reveal the plaintext of encrypted emails, including encrypted emails sent in the past" makes me think it's some nasty cryptographic issue; if it was RCE you'd think we'd be seeing a patch instead of "just disable it"
1 reply 0 retweets 0 likes -
plus, hard to imagine an implementation bug that affects all these email clients, but _nothing else_ using PGP
1 reply 0 retweets 0 likes -
Replying to @11rcombs
The only reasonable nasty cryptographic issue that fits the advice is a key disclosure side channel problem (receive encrypted email, somehow leaks part of your decryption key back).
2 replies 0 retweets 0 likes -
-
Replying to @11rcombs
They specifically mentioned automatic decryption in the post. > immediately disable and/or uninstall tools that automatically decrypt PGP-encrypted email.
1 reply 0 retweets 0 likes -
Replying to @marcan42
oh welp but if it was RCE you'd think there'd be a bigger fuss than "it could be used to decrypt existing emails", and "if you use PGP to handle very sensitive communications"?
2 replies 0 retweets 0 likes -
Replying to @11rcombs
I'm basically assuming all vulns are disclosed incompetently these days. Especially those coming from academics.
1 reply 0 retweets 0 likes -
Hector Martin Retweeted Hector Martin
Hector Martin added,
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.