1. You can almost always guess some plaintext. That’s a key point of the paper. 2. Zlib is tough but it’s 1/3 not 1/100,000. Not a huge ask. 3. By outdated, do you mean “a version that was current for the past N years prior to this disclosure” because duh.
*Follow up* on that notice to actually find out what got patched where. Because when I asked *them* they still claimed Thunderbird was vulnerable (to the PGP issue, in context) which turned out to be total bullshit.
-
-
Thunderbird kept their ticket private. I don’t think the researchers (and the CERT) were told the status.
-
So.... ask? Or, you know, just *try* the damn exploit on the current release (like I did) before coordinating a panic-inducing media reaction with the EFF?
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.