3 ms·
> optional, so is not a useful mitigation here Why in the heck does anyone ever send encrypted-only, non-signed messages?!?!
by floatboth 8y ago
> optional, so is not a useful mitigation here
Why in the heck does anyone ever send encrypted-only, non-signed messages?!?!
- AgentME 8y agoOther than anonymity, non-repudiation is a possibility. I may not want the recipient of my messages to be able to undeniably prove what I said to them. This case is important if I'm saying unflattering things about a mutual friend, or my messages could be read as admitting a crime, etc. (Though note that the vulnerability here still applies to signed messages too: https://efail.de/#will-signatures https://efail.de/#will-signatures)