Live data from Hacker News

A new set of vulnerabilities affecting users of PGP and S/MIME

eff.org

1–10 of 79 posts

Re: A new set of vulnerabilities affecting users of PGP and S/MIME

#3
Given that they recommend against decrypting any email, it sounds like the bug is some sort of remote-code-execution against the decryption step, that would then allow (among ~anything else) exfiltration of keys, ciphertexts, and plaintexts.

EDIT: Having read a bit more I'm not so convinced that this explanation makes sense.

Re: A new set of vulnerabilities affecting users of PGP and S/MIME

#4
> Our advice, which mirrors that of the researchers, is to immediately disable and/or uninstall tools that automatically decrypt PGP-encrypted email.

This advice strongly suggests a side-channel attack, not anything which affects encrypted data at rest. The worst case is that PGP has a remote code execution vulnerability in the decryption step.

Re: A new set of vulnerabilities affecting users of PGP and S/MIME

#5
I think PGP should implement a centralized auto-update mechanism so that software can disable itself in cases as severe as listed (with advice to "immediately disable and/or uninstall tools that automatically decrypt PGP-encrypted email").

[I've removed an earlier longer version of this comment.]

Re: A new set of vulnerabilities affecting users of PGP and S/MIME

#8
I wouldn't be surprised if this is either:

1. A bug in a library any pgp implementation uses, likely allowing even remote code execution

2. A bad Interaktion with some other mail "extension"* e.g. external bodies

*With extension I mean anything added to mail in a later rfc, which isn't really an extension in the classical sense but I'm not sure what to call it otherwise

Re: A new set of vulnerabilities affecting users of PGP and S/MIME

#9

My main question is does it affect gpg as well?

According to the quote in the article, yes.

The flaws “might reveal the plaintext of encrypted emails, including encrypted emails you sent in the past,” Sebastian Schinzel, a professor of computer security at Münster University of Applied Sciences, wrote on Twitter. “There are currently no reliable fixes for the vulnerability. If you use PGP/GPG or S/MIME for very sensitive communication, you should disable it in your email client for now.”

Re: A new set of vulnerabilities affecting users of PGP and S/MIME

#10

I think PGP should implement a centralized auto-update mechanism so that software can disable itself in cases as severe as listed (with advice to "immediately disable and/or uninstall tools that automatically decrypt PGP-encrypted email"). [I've removed an earlier longer version of this comment.]

The problem with a comment like this is that it's practically impossible to reply to it without sinking to the same level.

You're getting downvoted with no replies because almost everybody disagrees with you but nobody can be bothered to argue your nonsensical points.

EDIT: I see now what's going on. You baited people into disagreeing with your crackpottery, you then edited-down or deleted all of your comments in this thread so that we are the ones who look like crackpots. Well played, I guess, but not the kind of conduct I've come to expect on HN.

Post reply on HN