A new set of vulnerabilities affecting users of PGP and S/MIME
1–10 of 79 posts
Re: A new set of vulnerabilities affecting users of PGP and S/MIME
#2Re: A new set of vulnerabilities affecting users of PGP and S/MIME
#3EDIT: Having read a bit more I'm not so convinced that this explanation makes sense.
Re: A new set of vulnerabilities affecting users of PGP and S/MIME
#4This advice strongly suggests a side-channel attack, not anything which affects encrypted data at rest. The worst case is that PGP has a remote code execution vulnerability in the decryption step.
Re: A new set of vulnerabilities affecting users of PGP and S/MIME
#5[I've removed an earlier longer version of this comment.]
Re: A new set of vulnerabilities affecting users of PGP and S/MIME
#6Re: A new set of vulnerabilities affecting users of PGP and S/MIME
#7My main question is does it affect gpg as well?
Re: A new set of vulnerabilities affecting users of PGP and S/MIME
#81. A bug in a library any pgp implementation uses, likely allowing even remote code execution
2. A bad Interaktion with some other mail "extension"* e.g. external bodies
*With extension I mean anything added to mail in a later rfc, which isn't really an extension in the classical sense but I'm not sure what to call it otherwise
Re: A new set of vulnerabilities affecting users of PGP and S/MIME
#9My main question is does it affect gpg as well?
The flaws “might reveal the plaintext of encrypted emails, including encrypted emails you sent in the past,” Sebastian Schinzel, a professor of computer security at Münster University of Applied Sciences, wrote on Twitter. “There are currently no reliable fixes for the vulnerability. If you use PGP/GPG or S/MIME for very sensitive communication, you should disable it in your email client for now.”
Re: A new set of vulnerabilities affecting users of PGP and S/MIME
#10I think PGP should implement a centralized auto-update mechanism so that software can disable itself in cases as severe as listed (with advice to "immediately disable and/or uninstall tools that automatically decrypt PGP-encrypted email"). [I've removed an earlier longer version of this comment.]
You're getting downvoted with no replies because almost everybody disagrees with you but nobody can be bothered to argue your nonsensical points.
EDIT: I see now what's going on. You baited people into disagreeing with your crackpottery, you then edited-down or deleted all of your comments in this thread so that we are the ones who look like crackpots. Well played, I guess, but not the kind of conduct I've come to expect on HN.