I wrote a long post about the Efail disclosure to stop myself from tweeting about it anymore. Also it says mean things about PGP which I will regret for months.https://blog.cryptographyengineering.com/2018/05/17/was-the-efail-disclosure-horribly-screwed-up/ …
-
-
Let's be fair here, data encrypted with non-ancient GPG and decrypted with modern GPG by something checking obvious error codes is *fine*. It's not *that* bad. What makes it a huge mess is all the higher-level screwups.
-
I mean if people had been checking error codes it might have been fine. Unless they have a parser vulnerability and process the data before checking the code, in which case they’re screwed beyond belief.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.