home.social

#efail — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #efail, aggregated by home.social.

fetched live
  1. 🔒 I waited 4 years for Mailfence. Here's why it failed:

    99% of emails unencrypted (manual PGP setup required, zero user guidance)
    Closed-source = zero verification
    No E2EE for calendar/contacts
    OpenPGP EFAIL vulnerabilities remain exploitable
    Metadata still fully exposed

    EU jurisdiction ≠ cryptographic protection.
    Privacy theater is still theater. You deserve better.
    Full technical analysis: open.substack.com/pub/kaifisah

    #Privacy #EmailSecurity #OpenPGP #EFAIL #InfoSec #PrivacyTools

  2. It's been 3 years since the disclosure, and I'm still impressed with the attack.

  3. Today's #35C3 talk recommendation is rather technical: "Attacking end-to-end email encryption" -- #EFail explained:
    media.ccc.de/v/35c3-9463-attac

  4. @varx I just got reminded of it recently thanks to #Efail.

  5. @bob @dredmorbius @QuantumHemp #Efail was a storm in a teacup. I was disappointed to see a lot of people who normally say sensible things about security getting over-excited about it.

  6. I managed two #Mailpile team meetings in under an hour today... plus getting a contributor on IRC unstuck! Woo!

    One of the meetings was w/ our PM. In case you were wondering why pay for a PM, these are things I put on her plate:

    Desktop packages: almost ready, so how do we a) get people to test, b) coordinate translations and i18n/QA, c) release and d) structure ongoing relations w/ contractors?

    EFail: I feel I made mistakes in handling #EFail. Followup? We need processes for security issues!

  7. Als Folge der Efail-Probleme erzwingt GnuPG 2.2.8 jetzt die Verwendung von Prüfcodes. Außerdem beseitigt das Update ein neu entdecktes Sicherheitsproblem. www.heise.de/security/meldung/… #Gnupg #PGP #Verschlüsselung #efail
  8. Entwarnung für alle, die #Thunderbird nutzen: Selbst die @EFF rät jetzt dazu, die E-Mail-Verschlüsselung mit dem Add-on #Enigmail wieder zu aktivieren.

    Die als #efail bekannt gewordenen Sicherheitslücken sind gestopft.

    eff.org/deeplinks/2018/05/how-

    #PGP #GnuPG #Überwachung /c

  9. @micahflee given that #EFail only worked with #HTMLMail turned on, the whole things seems to me like a storm in a teacup. I mean, nobody who use PGP and cares about security lets their mail client run HTML code, right? Right?
    coactivate.org/projects/disint

  10. @HerraBRE @lain I'm not arguing for KMail being safe from #EFail (although I remember it being mentioned explicitly as not affected).

    But in KMail by default HTML is not shown, and remote resources are not loaded.

  11. It seems like #Apple decided to make it impossible to disable HTML e-mail.

    And it seems like they made this decision lately. Perhaps even after #EFail.

    What the fsck is wrong with these people.

  12. Die Diskussion über die elektronische Gesundheitskarte (eGK) geht weiter. Der Präsident der Bundesärztekammer will ein neues System, das das Smartphone der Patienten einbezieht. www.heise.de/newsticker/meldun… #Datenschutz #ElektronischeGesundheitskarte #Gematik #eGK #efail
  13. Benutzer sollte das Update des E-Mail-Programms umgehend installieren, denn es schließt mehrere, teils kritische Lücken. Die Efail-Schwachstellen sind jedoch nicht vollständig behoben. www.heise.de/security/meldung/… #Sicherheitslücken #Thunderbird #Thunderbird52 #efail
  14. Weil über #EFAIL so viel Unsinn geschrieben wurde, veröffentlichen wir einen Text der @[email protected] auf deutsch, der das zu erklären versucht und besseren Rat gibt:
    „E-Mail-Verschlüsselung und Sicherheitsnihilismus“
    digitalcourage.de/2018/05/21/e

    Vielen Dank den Übersetzern!
    #eHTMLfail #EFFail

  15. Benutzer sollte das Update des E-Mail-Programms umgehend installieren, denn es schließt mehrere, teils kritische Lücken. Die Efail-Schwachstellen sind jedoch nicht vollständig behoben. www.heise.de/newsticker/meldun… #Sicherheitslücken #Thunderbird #Thunderbird52 #efail