create account

Serious Vulnerability In PGP And S/MIME E-Mail Encryption by seckorama

View this thread on: hive.blogpeakd.comecency.com
· @seckorama · (edited)
$2.15
Serious Vulnerability In PGP And S/MIME E-Mail Encryption
A group of European researchers posted a [warning on Twiter](https://twitter.com/seecurity/status/995906576170053633) that the PGP/GPG and S/MIME email encryption included a group of serious vulnerabilities that can reveal the content of past (encrypted) messages to the attacker.
<center>![skul1.jpg](https://steemitimages.com/DQmVCyFZ39YgbMACCN5EsqNLyzLpfpBFAk4YZjP7WSzrb3V/skul1.jpg)
*[image source](https://pixabay.com/en/ransomware-cyber-crime-security-2320793/)*</center>
With the details of the vulnerability, the researchers had previously informed the Electronic Frontier Foundation, which confirmed that it's a serious threat.

As a first step, it's recommended to disable automatic decryption of messages, that is, disabling PGP/GPG encryption in mail clients (e.g., Enigmail in the Thunderbird client, GPGTools in Apple Mail, Gpg4win in Outlook).

The authors also published a [description of the vulnerability](https://efail.de/). There are two methods. 
- The first method is direct exfiltration, where the attacker steals the contents of the encrypted message by an HTML image badge which is embedded in a properly prepared message.
-  The second method is CBC/CFB Gadget Attack. It's an attack that exploits the specificity of Cipher Block Chaining encryption. The assumption of this attack is that an attacker knows at least one full block of plain text, which is not a problem in the given case since S/MIME encrypted emails usually begin with "Content-type: multipart/signed".    

<center>![efail2.png](https://steemitimages.com/DQmY4CTPbcXMh3ELSkS18dJvQ5canHgBHNMP4P5vQcFtjvs/efail2.png)
*[image source](https://efail.de/media/smime-attack.png)*</center>

As mentioned, the short-term solution is to disable encryption in the mail client and disable the HTML viewer, and the long-term solution will require the installation of appropriate updates (when available) and an upgrade of OpenPGP and S/MIME standards.

More details:
[PSA: PGP and S/MIME email clients may leak encrypted emails](https://thenextweb.com/security/2018/05/14/psa-pgp-and-s-mime-are-broken-and-leaking-encrypted-emails-stop-using-them-right-now/)
[Attention PGP Users: New Vulnerabilities Require You To Take Action](https://www.eff.org/deeplinks/2018/05/attention-pgp-users-new-vulnerabilities-require-you-take-action-now)
[Efail: Breaking S/MIME and OpenPGP Email Encryption using Exfiltration Channels - full technical report](https://efail.de/efail-attack-paper.pdf)

More security news:
[Malicious Chrome Extensions Infected Thousands Of Computers](https://steemit.com/security/@seckorama/malicious-chrome-extensions-infected-thousands-of-computers)
[Master Key For Hotel Rooms](https://steemit.com/security/@seckorama/master-key-for-hotel-rooms)
[Internet Passwords Will Soon Be A History?](https://steemit.com/security/@seckorama/internet-passwords-will-soon-be-a-history)
[Does This Change Will Speed Up Your Internet?](https://steemit.com/privacy/@seckorama/does-this-change-will-speed-up-your-internet)
[5 Privacies You Didn't Know You Lost](https://steemit.com/privacy/@seckorama/5-privacies-you-didn-t-know-you-lost)
[Piracy Is Popular Like Never Before](https://steemit.com/piracy/@seckorama/piracy-is-popular-like-never-before)
[Kaspersky Lab Joins Enterprise Ethereum Alliance](https://steemit.com/security/@seckorama/kaspersky-lab-joins-enterprise-ethereum-alliance)
[Slingshot - A State-Sponsored Malware](https://steemit.com/security/@seckorama/slingshot-a-state-sponsored-malware)

<center>Enjoy the rest of the day!
![logosecko.gif](https://res.cloudinary.com/hpiynhbhq/image/upload/v1510949615/f4uqakvlsemsjuvj0lrb.gif)
@seckorama

[Take a look at my DTube Channel](https://d.tube/#!/c/seckorama)
[Check out my DSound Channel](https://dsound.audio/#/@seckorama)</center>
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,
properties (23)
authorseckorama
permlinkserious-vulnerability-in-pgp-and-s-mime-e-mail-encryption
categorysecurity
json_metadata{"tags":["security","privacy","cybercrime","teamslovenia","steemitbalkan"],"users":["seckorama"],"image":["https://steemitimages.com/DQmVCyFZ39YgbMACCN5EsqNLyzLpfpBFAk4YZjP7WSzrb3V/skul1.jpg","https://steemitimages.com/DQmY4CTPbcXMh3ELSkS18dJvQ5canHgBHNMP4P5vQcFtjvs/efail2.png","https://res.cloudinary.com/hpiynhbhq/image/upload/v1510949615/f4uqakvlsemsjuvj0lrb.gif"],"links":["https://twitter.com/seecurity/status/995906576170053633","https://pixabay.com/en/ransomware-cyber-crime-security-2320793/","https://efail.de/","https://efail.de/media/smime-attack.png","https://thenextweb.com/security/2018/05/14/psa-pgp-and-s-mime-are-broken-and-leaking-encrypted-emails-stop-using-them-right-now/","https://www.eff.org/deeplinks/2018/05/attention-pgp-users-new-vulnerabilities-require-you-take-action-now","https://efail.de/efail-attack-paper.pdf","https://steemit.com/security/@seckorama/malicious-chrome-extensions-infected-thousands-of-computers","https://steemit.com/security/@seckorama/master-key-for-hotel-rooms","https://steemit.com/security/@seckorama/internet-passwords-will-soon-be-a-history","https://steemit.com/privacy/@seckorama/does-this-change-will-speed-up-your-internet","https://steemit.com/privacy/@seckorama/5-privacies-you-didn-t-know-you-lost","https://steemit.com/piracy/@seckorama/piracy-is-popular-like-never-before","https://steemit.com/security/@seckorama/kaspersky-lab-joins-enterprise-ethereum-alliance","https://steemit.com/security/@seckorama/slingshot-a-state-sponsored-malware","https://d.tube/#!/c/seckorama","https://dsound.audio/#/@seckorama"],"app":"steemit/0.1","format":"markdown"}
created2018-05-15 15:59:12
last_update2018-05-15 16:13:45
depth0
children6
last_payout2018-05-22 15:59:12
cashout_time1969-12-31 23:59:59
total_payout_value1.934 HBD
curator_payout_value0.219 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length3,784
author_reputation681,351,390,756,697
root_title"Serious Vulnerability In PGP And S/MIME E-Mail Encryption"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id55,849,359
net_rshares436,816,161,759
author_curate_reward""
vote details (64)
@saracampero ·
very good article @sckorama, you are right in many things. You have incredible talent and ability ne the computer. God bless you.
properties (22)
authorsaracampero
permlinkre-seckorama-serious-vulnerability-in-pgp-and-s-mime-e-mail-encryption-20180516t084621049z
categorysecurity
json_metadata{"tags":["security"],"users":["sckorama"],"app":"steemit/0.1"}
created2018-05-16 08:07:45
last_update2018-05-16 08:07:45
depth1
children1
last_payout2018-05-23 08:07:45
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length129
author_reputation202,123,147,213,699
root_title"Serious Vulnerability In PGP And S/MIME E-Mail Encryption"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id55,968,389
net_rshares0
@seckorama · (edited)
Thank you :)
properties (22)
authorseckorama
permlinkre-saracampero-re-seckorama-serious-vulnerability-in-pgp-and-s-mime-e-mail-encryption-20180516t103530637z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-05-16 10:36:57
last_update2018-05-16 10:37:51
depth2
children0
last_payout2018-05-23 10:36:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length12
author_reputation681,351,390,756,697
root_title"Serious Vulnerability In PGP And S/MIME E-Mail Encryption"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id55,986,807
net_rshares0
@security101 ·
Thank you for sharing! 
Most vulnerability’s seem to be fixed in thunderbird 52.7 nevertheless it will need 52.8 to fix every vuln. 
As you mentioned it is important to disable html and show emails only in plain text. 
At the moment the best practice seems to decrypt encrypted mails out of the mail client - like in CLI of GPG or so
👍  
properties (23)
authorsecurity101
permlinkre-seckorama-serious-vulnerability-in-pgp-and-s-mime-e-mail-encryption-20180515t161452750z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-05-15 16:14:51
last_update2018-05-15 16:14:51
depth1
children1
last_payout2018-05-22 16:14:51
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length333
author_reputation1,496,739,907,691
root_title"Serious Vulnerability In PGP And S/MIME E-Mail Encryption"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id55,851,868
net_rshares4,258,684,980
author_curate_reward""
vote details (1)
@seckorama ·
Yes, you're right. No html and decrypt outside mail client.
👍  
properties (23)
authorseckorama
permlinkre-security101-re-seckorama-serious-vulnerability-in-pgp-and-s-mime-e-mail-encryption-20180515t185304971z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-05-15 18:52:27
last_update2018-05-15 18:52:27
depth2
children0
last_payout2018-05-22 18:52:27
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length59
author_reputation681,351,390,756,697
root_title"Serious Vulnerability In PGP And S/MIME E-Mail Encryption"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id55,874,174
net_rshares2,677,034,070
author_curate_reward""
vote details (1)
@vibrantyogini ·
Thanks for making me aware of this. It is hard to keep on top of security as technology continues to grow! I love your artwork by the way too!
👍  
properties (23)
authorvibrantyogini
permlinkre-seckorama-serious-vulnerability-in-pgp-and-s-mime-e-mail-encryption-20180516t085833683z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-05-16 08:58:33
last_update2018-05-16 08:58:33
depth1
children1
last_payout2018-05-23 08:58:33
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length142
author_reputation1,573,513,250,459
root_title"Serious Vulnerability In PGP And S/MIME E-Mail Encryption"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id55,974,398
net_rshares2,282,952,402
author_curate_reward""
vote details (1)
@seckorama ·
Thank you, glad you like my artworks, too :)
properties (22)
authorseckorama
permlinkre-vibrantyogini-re-seckorama-serious-vulnerability-in-pgp-and-s-mime-e-mail-encryption-20180516t103647460z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-05-16 10:38:12
last_update2018-05-16 10:38:12
depth2
children0
last_payout2018-05-23 10:38:12
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length44
author_reputation681,351,390,756,697
root_title"Serious Vulnerability In PGP And S/MIME E-Mail Encryption"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id55,986,978
net_rshares0