@dangoodin001 @arstechnica can we please tone down the Efail FUD? *Both* Thunderbird *and* Enigmail were patched in ways sufficient to mitigate the flaw months before the Efail disclosure. *Additional* mitigations are being released just to be safe.https://twitter.com/marcan42/status/996275862273081344 …
-
-
This thing was coordinated so poorly that nobody, not even the researchers, seems to know what was patched when, and everyone was caught off guard with announcements. But if you *actually* dig up the bug reports and commits, no up-to-date Enigmail+Thunderbird was vulnerable.
Show this thread -
Refs: - Thunderbird patch for HTML request leak: https://hg.mozilla.org/releases/comm-release/rev/6e229daf13cc … (fixed in 52.7.0) - Enigmail bug for malleability (fixed in 2.0): https://sourceforge.net/p/enigmail/bugs/721/ … - Thunderbird S/MIME leak fix (upcoming in next release):https://hg.mozilla.org/releases/comm-release/rev/6f5d2abfedc9 …
Show this thread
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.