I wrote a long post about the Efail disclosure to stop myself from tweeting about it anymore. Also it says mean things about PGP which I will regret for months.https://blog.cryptographyengineering.com/2018/05/17/was-the-efail-disclosure-horribly-screwed-up/ …
See? All this confusion is also why the disclosure was horrible. People think gpg is somehow vulnerable to malleability, when it really isn't and anything encrypted after 2002 should be safe.
-
-
Killing those old ciphers was already on the gpg roadmap (thus refusing to decrypt pre-2002 emails without an override) but they were understandably wary of locking up people's archives. Though Enigmail just did that by treating the gpg warning for those as a hard fail so...
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.