2 ms·
"They figured out mail clients which don't properly check for decryption errors and also follow links in HTML mails. So the vulnerability is in the mail clients
by keSSeaj 8y ago
"They figured out mail clients which don't properly check for decryption errors and also follow links in HTML mails. So the vulnerability is in the mail clients and not in the protocols. In fact OpenPGP is immune if used correctly while S/MIME has no deployed mitigation."
- by GnuPG (https://twitter.com/gnupg/status/995931083584757760 https://twitter.com/gnupg/status/995931083584757760)
- scandox 8y agoThis is worth reading with the Researcher then (publicly :)) asking him to "keep this quiet". I think some of the subsequent commentators have a point which is that the media will take this to mean PGP is broken.
- lbeltrame 8y agoAccording to Werner Koch (link to the email posted by other commenters already), the GnuPG people weren't contacted about this issue. So that comment from the researcher looks a little out of place, iMO.
- deleted 8y ago[deleted]
- spacenick88 8y agoYes and researchers shouldn't release incomplete teaser facts just to promote their publication and then cry wolf when their stupid paper embargo bullshit isn't adhered to.