Cory Doctorow's linkblog · @pluralistic
41105 followers · 40932 posts · Server mamot.fr
CisHuman.org · @cishumanorg
10 followers · 127 posts · Server geekdom.social
Campusradio Karlsruhe · @campusradioka
43 followers · 56 posts · Server sueden.social

E-Mails: Not Safe For Work?

Was ist, wenn deine E-Mails nicht so sicher sind, wie du denkst? Schonmal vom gehört? Denn auch Ende-zu-Ende-Verschlüsselungen können geknackt werden. David und Béla erklären das in
17.2. 9 Uhr

campusradio-karlsruhe.de/2023/

#efail #softwarekatastrophen

Last updated 3 years ago

LisPi · @lispi314
88 followers · 1704 posts · Server mastodon.top

@laplace You can, but to a point (efail.de/) has demonstrated why that's a brittle way to handle the issue.

There are also other issues with 's quality as a cryptographic implementation (part of those design flaws being inherent to ).

I haven't given its code enough of a look-over, but (nncp.mirrors.quux.org/) seems like a viable method (nncp.mirrors.quux.org/UsecaseP) that is also simpler (complete.org/nncp/).

#efail #gpg #pgp #NNCP #email #asynchronouscommunication

Last updated 3 years ago

Aaron Toponce ⚛️:debian: · @atoponce
953 followers · 2864 posts · Server fosstodon.org

It's been 3 years since the disclosure, and I'm still impressed with the attack.

#efail

Last updated 4 years ago

CryptoParty Berlin · @cryptoparty_berlin
650 followers · 1141 posts · Server aleph.land

Today's talk recommendation is rather technical: "Attacking end-to-end email encryption" -- explained:
media.ccc.de/v/35c3-9463-attac

#35c3 #efail

Last updated 7 years ago

Yellow Flag · @WPalant
651 followers · 2784 posts · Server infosec.exchange

@varx I just got reminded of it recently thanks to .

#efail

Last updated 7 years ago

RA Michael Seidlitz · @ramichaelseidlitz
712 followers · 5394 posts · Server mastodon.cloud

GPG Suite 2018.3 with 3.0b7 and 2.2.8 fixes and

releases.gpgtools.org/GPG_Suit

#gpgmail #gnupg #efail #sigspoof

Last updated 8 years ago

I managed two team meetings in under an hour today... plus getting a contributor on IRC unstuck! Woo!

One of the meetings was w/ our PM. In case you were wondering why pay for a PM, these are things I put on her plate:

Desktop packages: almost ready, so how do we a) get people to test, b) coordinate translations and i18n/QA, c) release and d) structure ongoing relations w/ contractors?

EFail: I feel I made mistakes in handling . Followup? We need processes for security issues!

#mailpile #efail

Last updated 8 years ago

RA Michael Seidlitz · @ramichaelseidlitz
712 followers · 5394 posts · Server mastodon.cloud

GPG Suite 2018.2 with 3.0b6 which includes mitigations against exploits

releases.gpgtools.org/GPG_Suit

#gpgmail #efail

Last updated 8 years ago

X_Cli · @x_cli
271 followers · 1441 posts · Server infosec.exchange
Toni Hermoso Pulido · @toniher
234 followers · 634 posts · Server mastodont.cat

Email is a mess, writes @quinnnorton@twitter.com, and it's going to get worse. theatlantic.com/technology/arc -> After efail.de

#efail

Last updated 8 years ago

Parker Higgins · @xor
3887 followers · 2503 posts · Server mastodon.xyz

Does anybody know if it's possible to view a single message as HTML in Thunderbird without switching my default? I've turned off HTML email since but a lot of mass-mailings don't even have a text option at all!

#efail

Last updated 8 years ago

Daniel (dkg) at the ACLU is one of the smarter people in the PGP world. He says some reasonable things about#EFail (and ) here: aclu.org/blog/privacy-technolo

Reading this, I get the feeling he's missing point 2) from my previous toot - how is particularly scary because Lazy User A can put Careful User B at risk.

In InfoSec, we're so used to thinking in an individualistic way about how we protect ourselves, I think we often fail to consider how our choices affect others.

#effail #efail

Last updated 8 years ago

jomo · @jomo
1509 followers · 4753 posts · Server mstdn.io

Turns out Thunderbird + Enigmail is still vulnerable to 😑

twitter.com/hanno/status/99713

#efail

Last updated 8 years ago

manhack · @manhack
1294 followers · 9957 posts · Server social.tcit.fr

RT @EFF@twitter.com: There has been a lot of different information about the vulnerability in PGP, GPG, and S/MIME in the last few days. We’ve attempted to answer some important questions about the current state of email security here. eff.org/deeplinks/2018/05/pgp-
🐦🔗: twitter.com/EFF/status/9965569

#efail

Last updated 8 years ago

miramarco · @miramarco
383 followers · 8964 posts · Server octodon.social

I’m so accustomed to dropping the “e” from “email” that it was only few moments ago that I realized that is a pun on “email”

#efail

Last updated 8 years ago

The more I think about and the 's take, the more sympathy I have with their approach.

I wish they'd given more nuanced advice and avoided some of drama, but here are some factors to consider:

1) People don't read. Security advice needs to be simple.

2) Lazy User A can put careful User B at risk.

3) Social engineering works.

4) The PGP/e-mail community's knee-jerk was "we're not vulnerable."

But many were & are vulnerable if you count SocEng and/or old versions. too.

#efail #mailpile #eff

Last updated 8 years ago

Went to update the blog post to mention our nightly Debian packages... and discovered that our build-bot had been dormant for 10 days, due to a full disk. Oops!

Fixed that. The nightly packages are up to date now.

Added the buildbot output to my monitors, so it won't take me 10 days to notice next time.

Updated the blog post: mailpile.is/blog/2018-05-14_PG

Whee!

#mailpile #efail

Last updated 8 years ago

Micah Lee · @micahflee
6895 followers · 1225 posts · Server mastodon.social

PGP users,

I implemented a simple exploit for Apple Mail, which is vulnerable to direct exfiltration with its default settings. The mitigation, disabling remote content, works but is brittle. So never click "Load Remote Content". (Thunderbird/Enigmail is vulnerable in a similar way, but I haven't tried that one yet.)

youtube.com/watch?v=_67Pz9zpPb

#efail

Last updated 8 years ago