Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OpenPGP with HTML susceptible to attack vector #9

Open
caffeineinc opened this issue May 15, 2018 · 0 comments
Open

OpenPGP with HTML susceptible to attack vector #9

caffeineinc opened this issue May 15, 2018 · 0 comments

Comments

@caffeineinc
Copy link

caffeineinc commented May 15, 2018

General advisory that OpenPGP is susceptible to attack vectors when used with HTML attachments.

This attack can be performed on an encrypted email that an attacker has collected, including emails that have been sent.

  • block all backchannels used in your email clients (only send/receive plain text)
  • stay up-to-date with patches from your email client and encryption plugins. Email clients may release a patch to fix this vulnerability once the S/MIME and OpenPGP standards are updated.

We should ensure plain text attachments until this is resolved.

see more info at cert

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant