OpenPGP

Enigmail verschickt Krypto-Mails im Klartext (heise security article)

2018/10/03: Heise security article on the Enigmail bug under WindowsRead more

By tracking versions? Example with PGP

This history is a very detailed and focused one and I really love the way most information is documented with links. It is a very useful source of primary and secondary documents...Read more

Spoofing OpenPGP and S/MIME Signatures in Emails (13:19 - 19.04.30)

Stephen Farrell's mail in response to ilf mail about OpenPGPRead more

A unified timeline of Efail PGP disclosure events

2018/05/16: Timeline of the Efail vulnerabilities disclosures to PGP vendors and usersRead more

What's the matter with PGP? (Matthew Green blog post)

2014/08/13: Green's criticisms towards OpenPGPRead more

SigSpoof: Spoofing signatures in GnuPG, Enigmail, GPGTools and python-gnupg (NeoPG blog post)

2018/06/13: Blog post on the "SigSpoof". Marcus Brinkmann found this vulnerability that allows spoofing “signed” messages that are not actually signed. This post proves the vulnerability and shows the medias' reactionsRead more

How To Turn PGP Back On As Safely As Possible (EFF article)

2018/05/29: EFF recommendation for PGP users on how to react to the EFAIL vulnerabilities disclosureRead more

Efail: Breaking S/MIME and OpenPGP Email Encryption using Exfiltration Channels

EFAIL Usenix paper, released (in a draft version) on may 14, 2018 due to embargo break. It describes the EFAIL attacks (technique: malleability gadgets) to reveal plaintext of emails encrypted with S/MIME and OpenPGP.Read more

Negociation as a drawback?

The authors make a bold statement:

If we've learned 3 important things about cryptography design in the last 20 years, at least 2 of them are that negotiation and compatibility

...Read more
Subscribe to OpenPGP