ZeroHour
Schneier on Securitypublished ()ingested

Critical PGP Vulnerability

criticalVulnerabilityimportance 55
Full article132 words · extracted from schneier.com · click to collapse

EFF is reporting that a critical vulnerability has been discovered in PGP and S/MIME. No details have been published yet, but one of the researchers wrote:

We’ll publish critical vulnerabilities in PGP/GPG and S/MIME email encryption on 2018-05-15 07:00 UTC. They might reveal the plaintext of encrypted emails, including encrypted emails sent in the past. There are currently no reliable fixes for the vulnerability. If you use PGP/GPG or S/MIME for very sensitive communication, you should disable it in your email client for now.

This sounds like a protocol vulnerability, but we’ll learn more tomorrow.

News articles.

Tags: cryptanalysis, cryptography, email, encryption, PGP, protocols, vulnerabilities

Posted on May 14, 2018 at 9:33 AM26 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2018/05/critical_pgp_vu.html