<html><head></head><body><a href="https://efail.de/">https://efail.de/</a><br><br><div class="gmail_quote">On May 15, 2018 12:09:00 AM GMT+02:00, Dawning Sun <dawning_sun@mailbox.org> wrote:<blockquote class="gmail_quote" style="margin: 0pt 0pt 0pt 0.8ex; border-left: 1px solid rgb(204, 204, 204); padding-left: 1ex;">
<pre class="k9mail">Hi,<br><br>since it's a bit more complicated than "GPG/PGP is broken" I'd like to<br>start a thread with infos on the topic. Including what we can do<br>already. I'm looking forward to more infos and links from others, too.<br><br>=== What's going on? ===<br><br>I found this thread by a crypto mathematician very helpful:<br><a href="https://twitter.com/matthew_d_green/status/995989254143606789">https://twitter.com/matthew_d_green/status/995989254143606789</a><br><br>Then there's been explanations/statements by:<br><br>* GnuPG: <a href="https://lists.gnupg.org/pipermail/gnupg-users/2018-May/060334.html">https://lists.gnupg.org/pipermail/gnupg-users/2018-May/060334.html</a><br>* EFF:<br><a href="https://www.eff.org/deeplinks/2018/05/not-so-pretty-what-you-need-know-about-e-fail-and-pgp-flaw-0">https://www.eff.org/deeplinks/2018/05/not-so-pretty-what-you-need-know-about-e-fail-and-pgp-flaw-0</a><br><br>=== What can we do ? ===<br><br>There's nothing to do if you're using Enigmail 2.0+ as it already<br>includes fixes and/or workarounds:<br><a href="https://twitter.com/pEpFoundation/status/995993916888502273">https://twitter.com/pEpFoundation/status/995993916888502273</a><br><br>As a general rule disabling HTML helps to lower the chances of things<br>going wrong. Here's how to do it in different clients:<br><a href="https://twitter.com/botherder/status/995966058371670016">https://twitter.com/botherder/status/995966058371670016</a><br><br><br>Ciao,<br>Crille.<br><br></pre></blockquote></div><br>
-- <br>
Sent from my Fairphone with K-9 Mail.</body></html>