Stories
Slash Boxes
Comments

SoylentNews is people

posted by chromas on Friday May 25 2018, @09:09AM   Printer-friendly
from the Less-than-a-week-ago dept.

https://medium.com/@cipherpunk/efail-a-postmortem-4bef2cea4c08

https://admin.hostpoint.ch/pipermail/enigmail-users_enigmail.net/2018-May/004995.html

Writing just for himself -- not for GnuPG and not for Enigmail and definitely not for his employer -- Robert J Hansen, an Enigmail developer and GnuPG volunteer, put together a postmortem on Efail:

Less than a week ago, some researchers in Europe published a paper with the bombshell title "Efail: Breaking S/MIME and OpenPGP Email Encryption using Exfiltration Channels." There were a lot of researchers on that team but in the hours after release Sebastian Schinzel took the point on Twitter for the group.

Oh, my, did the email crypto world blow up. The following are some thoughts that have benefited from a few days for things to settle.

They say that when there's a fire in a nightclub you're at more risk of dying from the stampede than the blaze. The panic kills both by crushing people underfoot, and by clogging the exits so that people have to stay in the club longer and breathe more hot smoke-filled air. The fire is a problem but the panic is worse. That's what we saw here, and frankly I place a lot of blame for that at the feet of the Electronic Frontier Foundation.

Previously: PGP and S/MIME Vulnerable, Take Action Now (Update: Embargo Broken)


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 3, Insightful) by takyon on Friday May 25 2018, @09:29AM

    by takyon (881) <takyonNO@SPAMsoylentnews.org> on Friday May 25 2018, @09:29AM (#683942) Journal

    I read Hansen's post when this was submitted. One of EFF's lamer moments due to the incredibly ambiguous statements they made in their alarmist blog post. I don't see any follow-up as Hansen seemed to believe was on the way. If you aren't going to donate to EFF because of it, pitch some money to the Internet Archive or something instead.

    I’ve sent a few very angry emails to Danny O’Brien taking his outfit to task for what I see as reckless conduct, and he’s been a gentleman in listening to them. That’s not to say he agrees with all of my criticisms, of course, but he gave me a fair hearing.

    I’m sure the EFF will soon be posting their own post-mortem. I look forward to seeing what they think of how they handled things in benefit of hindsight.

    --
    [SIG] 10/28/2017: Soylent Upgrade v14 [soylentnews.org]
    Starting Score:    1  point
    Moderation   +1  
       Insightful=1, Total=1
    Extra 'Insightful' Modifier   0  
    Karma-Bonus Modifier   +1  

    Total Score:   3