[cp-global] #efail explained

Steffen Haschler steffen at ccc-mannheim.de
Mon May 14 22:53:40 GMT 2018


https://efail.de/

On May 15, 2018 12:09:00 AM GMT+02:00, Dawning Sun <dawning_sun at mailbox.org> wrote:
>Hi,
>
>since it's a bit more complicated than "GPG/PGP is broken" I'd like to
>start a thread with infos on the topic. Including what we can do
>already. I'm looking forward to more infos and links from others, too.
>
>=== What's going on? ===
>
>I found this thread by a crypto mathematician very helpful:
>https://twitter.com/matthew_d_green/status/995989254143606789
>
>Then there's been explanations/statements by:
>
>* GnuPG:
>https://lists.gnupg.org/pipermail/gnupg-users/2018-May/060334.html
>* EFF:
>https://www.eff.org/deeplinks/2018/05/not-so-pretty-what-you-need-know-about-e-fail-and-pgp-flaw-0
>
>=== What can we do ? ===
>
>There's nothing to do if you're using Enigmail 2.0+ as it already
>includes fixes and/or workarounds:
>https://twitter.com/pEpFoundation/status/995993916888502273
>
>As a general rule disabling HTML helps to lower the chances of things
>going wrong. Here's how to do it in different clients:
>https://twitter.com/botherder/status/995966058371670016
>
>
>Ciao,
>Crille.

-- 
Sent from my Fairphone with K-9 Mail.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://cryptoparty.is/pipermail/global/attachments/20180515/2e35fd21/attachment.html>


More information about the global mailing list