I would go further: the fact that you can maul encrypted PGP emails in various ways was known well before Cure53. It’s been known since the late 1990s. But nobody has ever taken it seriously enough to comprehensively address it across all clients. Guess why?
-
-
That seems on the EFF. But I saw some threads from 5/14 re: Enigmail saying that some modes were still vulnerable. So I’m a bit skeptical about this.
-
No, mostly it's on the researchers, who seemed to be completely lost as to what was being mitigated when and where, and who were entirely responsible for feeding the info to the EFF as far as I can tell (and on the EFF for buying it).
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.