Since the Efail guys and @EFF are failing at actually documenting mitigations, here they are:
- Use Enigmail 2.0 or later
- Use Thunderbird 52.7.0 or later
That's it. That fixes both the GPG issue and the back channels. If you've been running up to date software, *you're fine*.
-
-
So you cannot roll back the integrity protection on a message encrypted with modern gpg (because modern ciphers are tied to a hard MDC requirement), but old legacy messages are stuck back in that era, without the integrity protection.
Show this thread -
It seems the plan was already to fully deprecate those old cipher suites with GPG 2.3 (the next major version), thus basically erroring out on decrypting old messages without an override, to plug this particular hole (at the expense of really old emails).
Show this thread
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.