Since the Efail guys and @EFF are failing at actually documenting mitigations, here they are:
- Use Enigmail 2.0 or later
- Use Thunderbird 52.7.0 or later
That's it. That fixes both the GPG issue and the back channels. If you've been running up to date software, *you're fine*.
-
-
You are right, however in this case the potential malware equivalent is pretty aggressive and doesn't need user interaction if they're running old software. Attacks need to be targeted of course though.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.