Write a comment

A group of European security researchers have released a warning about a set of vulnerabilities affecting users of PGP and S/MIME. These vulnerabilities pose an immediate risk to those using these tools for email communication, including the potential exposure of the contents of past messages.

A group of European security researchers have released a warningabout a set of vulnerabilities affecting users of PGP and S/MIME. The Electronic Frontier Foundation (EFF) says it has been in communication with the research team, and can confirm that these vulnerabilities pose an immediate risk to those using these tools for email communication, including the potential exposure of the contents of past messages.

The full details of the vulnerability will be published in a paper tomorrow (Tuesday, 15 May, at 3:00 a.m. EST, midnight Pacific).

EFF says that in order to reduce the short-term risk, EFF the researchers have agreed to warn the wider PGP user community in advance of the full publication of the vulnerability.

EFF and the researchers urge users to immediately disable and/or uninstall tools that automatically decrypt PGP-encrypted email.

For a detailed discussion of the vulnerability and how to minimize the risk it entails, see Erica Portnoy, Danny O’Brien, and Nate Cardozo, “Not So Pretty: What You Need to Know About E-Fail and the PGP Flaw” (EFF, 14 May 2018).

Until the flaws described in the paper are more widely understood and fixed, users should arrange for the use of alternative end-to-end secure channels, such as Signal, and temporarily stop sending and especially reading PGP-encrypted email.

Users should refer to these guides on how to temporarily disable PGPplug-ins in:

Thunderbird with Enigmail

Apple Mail with GPGTools

Outlook with Gpg4win

EFF notes that these steps are intended as a temporary, conservative stopgap until the immediate risk of the exploit has passed and been mitigated against by the wider community.

 

Loading comment... The comment will be refreshed after 00:00.

Be the first to comment.

Say something here...
You are a guest ( Sign Up ? )
or post as a guest
 

 

 

Latest

Write a comment

Heads-Up Taiwan: 167 MPH Winds - 200 MPH Gusts!

September 23, 2018
8 Comments

Amazon Associates BEWARE! Have Just TERMINATED Relationship with Amazon Associates

September 23, 2018
12 Comments

Russia to Israel: Who is in control of your military? Says Israel "Ungrateful" and "Criminally Negligent" in Downing of IL-20 Plane

September 23, 2018
1 Comment

Democrats Could be HELD in Senate Session through OCTOBER - Can't Campaign!

September 21, 2018
Write a comment

Mitch McConnell: Has the Votes to Confirm Kavanaugh

September 21, 2018
41 Comments

SYRIA ATTACKED AGAIN - "MISSILES FROM THE SEA" -- Russian IL-20 Aircraft with 14 Troops aboard "HIT" - falls into the Med.

September 17, 2018
5 Comments

North Carolina Nuclear Plant Declares EMERGENCY

September 17, 2018
22 Comments

AMBUSHED! US Forces KILLED by ISIS in Syria

September 16, 2018
12 Comments

Here it is: Filming of a FALSE Chemical Attack at Hospital in Syria

September 16, 2018
5 Comments

Hurricane Leaves Major "Hole" In US National Defenses!

September 15, 2018
19 Comments

RUSSIANS BOMB AL-TANF - PERIMETER OF U.S. BASE; AMERICAN TROOPS "TRAPPED"

September 15, 2018
Write a comment

47.3 Inches of Rain in 48 Hours - and it's still raining!

September 15, 2018
9 Comments

COVERT INTEL: Solar Observatory Closure in New Mexico

September 15, 2018
2 Comments

Mueller Refers Former Obama White House Counsel for Criminal Prosecution!

September 15, 2018
12 Comments

COVERT INTEL: Keep an eye on Europe This Weekend; Germany, Austria, Lichtenstein in particular

September 14, 2018