The root causes here are various, but one of them is active content in general. Another is the lack of MACs in PGP (originally). Another is that apparently it's 2018 and people are still not checking error codes. Another is that PGP mail is a patchjob of pseudo-standards.
-
-
Replying to @marcan42
All of these flaws (still) exist in 2018 because nobody thought they were comprehensively exploitable together. Now they’re being fixed. This is a good outcome.
1 reply 0 retweets 3 likes -
Replying to @matthew_d_green
Wouldn't it have been great if they'd bothered to follow up with the mitigations and tested the exploit again and confirmed what was fixed and wasn't. Then we'd still have the same outcome, minus the panic reaction and confused, FUD-filled media coverage.
1 reply 0 retweets 2 likes -
Replying to @marcan42 @matthew_d_green
I’m recommending people delete Signal Desktop until we can be sure it’s fixed. Is that bad advice or “FUD”? You are literally arguing against being cautious with encrypted messaging tools.
2 replies 0 retweets 2 likes -
Replying to @bascule @matthew_d_green
I'm not arguing against being cautious, I'm arguing against *not doing the damn research* to figure out the facts before stirring up a media shitstorm. If we really *couldn't* know then being cautious is warranted, but we *can* and they were just lazy.
1 reply 0 retweets 0 likes -
Replying to @marcan42 @matthew_d_green
As we just saw with Signal Desktop, initial fixes to vulnerabilities are often insufficient and new ones are often found soon thereafter. You didn’t answer my question, but turns out I was right in practice to suggest caution.
1 reply 0 retweets 0 likes -
The EFF was doing the exact same thing I did except with
#Efail, and you’re calling it FUD. Why don’t you go look in a mirror and ask yourself who’s spreading FUD?1 reply 0 retweets 0 likes -
Tony “Abolish (Pol)ICE” Arcieri 🦀 Retweeted hanno
Tony “Abolish (Pol)ICE” Arcieri 🦀 added,
1 reply 0 retweets 0 likes -
Replying to @bascule @matthew_d_green
Where's the PoC? Is this related the leak the Efail guys used or a completely different one? Is he using the direct exfiltration, since the PGP malleability should be gone for good? At this point this is just proving that HTML email is a fucking terrible idea more than anything.
2 replies 0 retweets 1 like -
Efail only listed *one* backchannel for Thunderbird and I tested it and found it didn't work in the current version. If there's another backchannel, well, then that's a different bug. And little to do with PGP per se.
1 reply 0 retweets 0 likes
The new Enigmail has a bunch of mitigations for the concatenation/MIME merging crap that enables all of this, but all of that is irrelevant if you can't actually ping back the data to a server, which as far as I can tell you can't, at least not the way the Efail paper describes.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.