Alô, pessoal que estiver usando OpenPGP no Mail do Mac. Tem brecha que precisa ser tapada.


Alô, pessoal que estiver usando OpenPGP no Mail do Mac. Tem brecha que precisa ser tapada.

= = =

EFAIL — May 14th, 2018

A new kind of vulnerability regarding OpenPGP encrypted messages has been found by a team of european researchers called EFAIL which also affects macOS Mail and our Mail plugin GPGMail.

By exploiting a combination of flaws in the way encrypted data is handled in GPGMail as well as Mail, an attacker having access to the encrypted cyphertext may be able to exfiltrate the decrypted content once a user reads the message and have the decrypted content sent to a remote server under their control.

GPG Suite 2018.2 will include mitigations against this vulnerability and will be released this week.

As a temporary workaround, please disable the option to "Load remote content in messages" in Mail → Preferences → Viewing to thwart a possible attack.

Comentários

Postagens mais visitadas deste blog

FINALMENTE!

Veja neste minivídeo que entrega cuidadosa! Este verdadeiro ANIMAL da FedEx joga por cima da...