Shostack + Friends Blog

 

'EFAIL' Is Why We Can't Have Golden Keys

[no description provided]

I have a new essay at Dark Reading, "'EFAIL' Is Why We Can’t Have Golden Keys." It starts:

There's a newly announced set of issues labeled the "EFAIL encryption flaw" that reduces the security of PGP and S/MIME emails. Some of the issues are about HTML email parsing, others are about the use of CBC encryption. All show how hard it is to engineer secure systems, especially when those systems are composed of many components that had disparate design goals.