Someone claims they have a variant of Efail that works on current versions. I don't know what exfiltration method they're using, since the only one documented on the Efail paper for Thunderbird is fixed as far as I can tell. No further details yet.https://twitter.com/hanno/status/997138771194859521 …
-
Show this thread
-
The Efail mitigations he's talking about in Enigmail relate to the MIME merging / injection stuff that enables all of this (and which is fragile to mitigate by nature), but that is all irrelevant without a remote content blocking bypass, and the one used by Efail should be fixed.
1 reply 0 retweets 1 likeShow this thread -
Replying to @marcan42
Without seeing his attack I'm not able to say definitively, but I wish people would be more careful in distinguishing between "Enigmail has a bug" and "Thunderbird has a bug". Some of these bugs are in TB, not Enigmail.
1 reply 0 retweets 0 likes -
Replying to @robertjhansen @marcan42
I understand the desire to have a single throat to strangle, but unfortunately, we have no ability to patch Thunderbird and only a limited ability to mitigate their bugs.
1 reply 0 retweets 0 likes
I know it's a Thunderbird problem; I never said otherwise. The whole thing relies on a remote content block bypass, which is strictly a Thunderbird problem.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.