IMO, because active content in e-mails is an ancient horse that has been beaten to death and the fact that this is *still* a problem just demonstrates a pervasive failure of email clients to take privacy seriously, PGP completely aside.
-
-
Efail only listed *one* backchannel for Thunderbird and I tested it and found it didn't work in the current version. If there's another backchannel, well, then that's a different bug. And little to do with PGP per se.
-
The new Enigmail has a bunch of mitigations for the concatenation/MIME merging crap that enables all of this, but all of that is irrelevant if you can't actually ping back the data to a server, which as far as I can tell you can't, at least not the way the Efail paper describes.
End of conversation
New conversation -
-
-
-
Good advice would've been to disable HTML. "Uninstall Enigmail" is still ridiculous.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.