Since the Efail guys and @EFF are failing at actually documenting mitigations, here they are:
- Use Enigmail 2.0 or later
- Use Thunderbird 52.7.0 or later
That's it. That fixes both the GPG issue and the back channels. If you've been running up to date software, *you're fine*.
-
-
Another important timeline tidbit: GPG has been failing with an error (not a warning) in cases of missing MDC since 2.1.9 (released in 2015). So as long as you have a version newer than that (and the client honors errors) you're fine too, e.g. for most commandline users.
Show this thread -
Note that *really old* encrypted messages, using ciphers prior to the introduction of MDC, are still vulnerable (if you have a side channel in the mail client). This is fundamental: those messages are using older crypto without integrity protection. GPG cannot error out on those.
Show this thread -
The only real solutions for those, besides mail clients plugging the side channels/app-level issues with those, are to either refuse to decrypt them outright (not great) or have an application-level warning and click through.
Show this thread -
So you cannot roll back the integrity protection on a message encrypted with modern gpg (because modern ciphers are tied to a hard MDC requirement), but old legacy messages are stuck back in that era, without the integrity protection.
Show this thread -
It seems the plan was already to fully deprecate those old cipher suites with GPG 2.3 (the next major version), thus basically erroring out on decrypting old messages without an override, to plug this particular hole (at the expense of really old emails).
Show this thread
End of conversation
New conversation -
-
-
Thank you for this thread. Reduces FUD to a minimum! :)
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.