Long thread. If you want to know the high-level details of the Efail attack, read. Yes, it was embargoed; yes, we were respecting the embargo; but links to the paper are now easy to get, so... here goes. 1/
Is 2.0.0 the threshold version for the fix? I see a bunch of security fixes went into 1.9.9, but I'm not sure if it's one of those or this was fixed later (Gentoo has 1.9.9 as stable and I'm trying to figure out if I need to file a security stablereq). https://bugs.gentoo.org/643490
-
-
Honestly, I don't know. I didn't know anything about this Efail paper until Saturday. We've been a little busy kicking the tires and making sure all the lugnuts are tightened. Now that we know we're OK, we'll start looking at exactly which versions aren't OK.
-
So they didn't even contact Enigmail about this (nor GnuPG apparently)? Amazing.
- Show replies
New conversation -
-
-
Official word from Patrick is the full
#Efail fixes weren't introduced until 2.0. File the request with Gentoo. :) -
This Tweet is unavailable.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.