Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 17 submissions in the queue.

Submission Preview

No link to story available

PGP and S/MIME Clients Vulnerable, Disable Now

Accepted submission by takyon at 2018-05-14 07:25:43
Security

Attention PGP Users: New Vulnerabilities Require You To Take Action Now [eff.org]

A group of European security researchers have released a warning [twitter.com] about a set of vulnerabilities affecting users of PGP and S/MIME. EFF has been in communication with the research team, and can confirm that these vulnerabilities pose an immediate risk to those using these tools for email communication, including the potential exposure of the contents of past messages.

The full details will be published in a paper on Tuesday at 07:00 AM UTC (3:00 AM Eastern, midnight Pacific). In order to reduce the short-term risk, we and the researchers have agreed to warn the wider PGP user community in advance of its full publication.

Our advice, which mirrors that of the researchers, is to immediately disable and/or uninstall tools that automatically decrypt PGP-encrypted email. Until the flaws described in the paper are more widely understood and fixed, users should arrange for the use of alternative end-to-end secure channels, such as [eff.org] Signal [eff.org], and temporarily stop sending and especially reading PGP-encrypted email.

Also at Ars Technica [arstechnica.com] and The Register [theregister.co.uk].


Original Submission