so... about efail. the latest Enigmail version contains a few Mitigations. They don't work. I found a trivial bypass. So to be clear: efail is still exploitable with latest Enigmail+Thunderbird and default settings.
-
Show this thread
Replying to @hanno
Are you using a different exfiltration leak? As far as I can tell, the one in the Efail (link rel="preconnect") is plugged in the current version of Thunderbird.
9:40 AM - 17 May 2018
0 replies
0 retweets
2 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.