https://lists.gnupg.org/pipermail/gnupg-users/2018-May/06031...
A new set of vulnerabilities affecting users of PGP and S/MIME
41–50 of 79 posts
Re: A new set of vulnerabilities affecting users of PGP and S/MIME
#42- by GnuPG (https://twitter.com/gnupg/status/995931083584757760)
Re: A new set of vulnerabilities affecting users of PGP and S/MIME
#43Re: A new set of vulnerabilities affecting users of PGP and S/MIME
#44Response by Werner Koch (GPG), contains some details: https://lists.gnupg.org/pipermail/gnupg-users/2018-May/06031...
Re: A new set of vulnerabilities affecting users of PGP and S/MIME
#45I think PGP should implement a centralized auto-update mechanism so that software can disable itself in cases as severe as listed (with advice to "immediately disable and/or uninstall tools that automatically decrypt PGP-encrypted email"). [I've removed an earlier longer version of this comment.]
The problem with a comment like this is that it's practically impossible to reply to it without sinking to the same level. You're getting downvoted with no replies because almost everybody disagrees with you but nobody can be bothered to argue your nonsensical points. EDIT: I see now what's going on. You baited people into disagreeing with your crackpottery, you then edited-down or deleted all of your comments in thi…
Re: A new set of vulnerabilities affecting users of PGP and S/MIME
#46Response by Werner Koch (GPG), contains some details: https://lists.gnupg.org/pipermail/gnupg-users/2018-May/06031...
So in short, if you have all mails set to display as plain text rather than HTML, there's no problem?
There are two ways to mitigate this attack
- Don't use HTML mails. Or if you really need to read them use a proper MIME parser and disallow any access to external links.
- Use authenticated encryption.
Re: A new set of vulnerabilities affecting users of PGP and S/MIME
#47Earlier quoted context omitted.
PGP is both software and an encryption system. ( https://tools.ietf.org/html/rfc4880 )
To be more precise, the standardized encryption system is called OpenPGP (RFC4880) whereas PGP is the name of tool which was written by Phil Zimmermann.
Re: A new set of vulnerabilities affecting users of PGP and S/MIME
#48Response by Werner Koch (GPG), contains some details: https://lists.gnupg.org/pipermail/gnupg-users/2018-May/06031...
To me this sounds strictly like a MUA issue, not a PGP/SMIME one. If that's really all it is it does seem massively overblown to me. Why not single out the broken MUA implementations instead of saying "don't decrypt emails OR YOU'LL DIE"? I mean just look at the wild speculation in this thread, nobody understood what was going on or even what was really vulnerable and what wasn't. Given the alarmist tone and the claims of "no workaround available" I was personally expecting a deep conceptual flaw in PGP/SMIME themselves. Terrible communication IMO. The parent email in the GnuPG thread seems to agree: https://lists.gnupg.org/pipermail/gnupg-users/2018-May/06031...
We'll know for sure tomorrow I suppose.
Re: A new set of vulnerabilities affecting users of PGP and S/MIME
#49"They figured out mail clients which don't properly check for decryption errors and also follow links in HTML mails. So the vulnerability is in the mail clients and not in the protocols. In fact OpenPGP is immune if used correctly while S/MIME has no deployed mitigation." - by GnuPG ( https://twitter.com/gnupg/status/995931083584757760 )
Re: A new set of vulnerabilities affecting users of PGP and S/MIME
#50"They figured out mail clients which don't properly check for decryption errors and also follow links in HTML mails. So the vulnerability is in the mail clients and not in the protocols. In fact OpenPGP is immune if used correctly while S/MIME has no deployed mitigation." - by GnuPG ( https://twitter.com/gnupg/status/995931083584757760 )
This is worth reading with the Researcher then (publicly :)) asking him to "keep this quiet". I think some of the subsequent commentators have a point which is that the media will take this to mean PGP is broken.