-
Notifications
You must be signed in to change notification settings - Fork 8
Open
Description
General advisory that OpenPGP is susceptible to attack vectors when used with HTML attachments.
This attack can be performed on an encrypted email that an attacker has collected, including emails that have been sent.
- block all backchannels used in your email clients (only send/receive plain text)
- stay up-to-date with patches from your email client and encryption plugins. Email clients may release a patch to fix this vulnerability once the S/MIME and OpenPGP standards are updated.
We should ensure plain text attachments until this is resolved.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels