Live data from Hacker News

EFail – Vulnerabilities in end-to-end encryption technologies OpenPGP and S/MIME

efail.de

1–10 of 306 posts

Re: EFail – Vulnerabilities in end-to-end encryption technologies OpenPGP and S/MIME

#2
Robert Hansen just sent the following email to the gnupg-users list:

to GnuPG-Users

[taps the mike]

Hi. I maintain the official GnuPG FAQ. So let me start off by answering a question that is certainly about to be asked a lot: "Should we be worried about OpenPGP, GnuPG, or Enigmail? The EFF's advising us to uninstall it!"

https://www.eff.org/deeplinks/2018/05/attention-pgp-users-ne...

Werner saw a preprint of this paper some time ago. I saw it recently. Patrick Brunschwig of Enigmail saw it. None of us are worried. Out of respect for the paper authors I will skip further comment until such time as the paper is published.

It would've been nice if EFF had reached out to us for comment, rather than apparently only talking to the paper authors. We hope they'll reach out next time.

Re: EFail – Vulnerabilities in end-to-end encryption technologies OpenPGP and S/MIME

#3

Robert Hansen just sent the following email to the gnupg-users list: to GnuPG-Users [taps the mike] Hi. I maintain the official GnuPG FAQ. So let me start off by answering a question that is certainly about to be asked a lot: "Should we be worried about OpenPGP, GnuPG, or Enigmail? The EFF's advising us to uninstall it!" https://www.eff.org/deeplinks/2018/05/attention-pgp-users-ne... Werner saw a preprint of this pap…

Werner Koch goes into further detail at the start of the gnupg-users thread @ https://lists.gnupg.org/pipermail/gnupg-users/2018-May/06031...

Re: EFail – Vulnerabilities in end-to-end encryption technologies OpenPGP and S/MIME

#5
If I understood correctly, I think this can be prevented by a single configuration change: "Do not automatically load inline content" but this is just speculation.

I'd disable HTML rendering completely until everything becomes clearer.

Re: EFail – Vulnerabilities in end-to-end encryption technologies OpenPGP and S/MIME

#8
post #5

If I understood correctly, I think this can be prevented by a single configuration change: "Do not automatically load inline content" but this is just speculation. I'd disable HTML rendering completely until everything becomes clearer.

Pretty much. Should have that as default anyway to avoid sending tracking beacons to spammers.

Re: EFail – Vulnerabilities in end-to-end encryption technologies OpenPGP and S/MIME

#9
post #6

While HTTPS is taking over web traffic, encrypted email could be considered a failure, at this point. I wonder what percentage of emails are encrypted using GPG. Based on my experience it's probably less than 0.001%.

PGP and HTTPS have very different trust models so it's comparing apples to oranges. That being said I agree that PGP failed to gain widespread adoption even though I personally use GnuPG daily and sign all of my emails. I'm still hoping that it'll make a comeback but I'm not holding my breath.
Post reply on HN