I wrote a long post about the Efail disclosure to stop myself from tweeting about it anymore. Also it says mean things about PGP which I will regret for months.https://blog.cryptographyengineering.com/2018/05/17/was-the-efail-disclosure-horribly-screwed-up/ …
GPG has been using MDCs since 2002 or so, and the lack of an MDC with Twofish and AES (which should always have one since they were introduced after MDCs) became a hard fail in gpg 2.1.9 (released in 2015). So for gpg since 2015, only messages pre-2002 are malleable.
-
-
See? All this confusion is also why the disclosure was horrible. People think gpg is somehow vulnerable to malleability, when it really isn't and anything encrypted after 2002 should be safe.
-
Killing those old ciphers was already on the gpg roadmap (thus refusing to decrypt pre-2002 emails without an override) but they were understandably wary of locking up people's archives. Though Enigmail just did that by treating the gpg warning for those as a hard fail so...
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.