Skip to content

OpenPGP with HTML susceptible to attack vector  #9

@caffeineinc

Description

@caffeineinc

General advisory that OpenPGP is susceptible to attack vectors when used with HTML attachments.

This attack can be performed on an encrypted email that an attacker has collected, including emails that have been sent.

  • block all backchannels used in your email clients (only send/receive plain text)
  • stay up-to-date with patches from your email client and encryption plugins. Email clients may release a patch to fix this vulnerability once the S/MIME and OpenPGP standards are updated.

We should ensure plain text attachments until this is resolved.

see more info at cert

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions