Technology

Your encrypted email messages might not be that secure after all

Your encrypted email messages might not be that secure after all

Security researchers have found vulnerabilities in some of the email encryption software.

"There are now no reliable fixes for the vulnerability", lead researcher Sebastian Schinzel, professor of applied cryptography at the Muenster University of Applied Sciences, said yesterday. Within hours, the researchers published the paper, which is titled Efail: Breaking S/MIME and OpenPGP Email Encryption using Exfiltration Channels.

Prior to the leak, Schnizel stated that there were "no reliable fixes", and recommended that affected users disable breached encryption software.

The researchers meant to hold off on full publication until Tuesday, May 15, though the white paper was published earlier due to the embargo being broken.

After breaking the news on Twitter on Sunday night he added: "There are now no reliable fixes for the vulnerability". This new vulnerability allows hackers and attackers the ability to read encrypted HTML emails in plaintext files.

A set of vulnerabilities in the encryption technologies used to secure sensitive emails threaten to expose corporate communications as well as the messages of at-risk users such as journalists, political dissidents and whistleblowers operating in hostile environments. It will be safer for the users to switch to services like Signal, the massaging app backed by WhatsApp co-founder Brian Acton.

More news: Moktada al-Sadr Leads In Iraqi Election Count
More news: Walmart may come up with IPO for Flipkart in 4 years
More news: Neymar named France's player of the year

More details to come.

The Electronic Frontier Foundation -which researchers contacted to help them broadcast their message to a broader audience- has published tutorials on how to disable email encryption plugins. It works in clients such as Mozilla Thunderbird, Postbox, MailMate, iOS Mail or Apple Mail and enables the attacker to exfiltrate the plaintext message of the encrypted email directly.

In the future, patches should prevent this PGP flaw from being exploited.

The researchers have informed e-mail providers of their findings, under so-called responsible disclosure, and it now falls to others to establish whether the exploits can be replicated. (Both protocols are used to secure end-to-end encrypted emails.) They dubbed the vulnerability "EFAIL" because it effectively breaks these emails' protections. On the other hand, S/MIME is used mainly in enterprise infrastructure.

For the time being, there's no fix so your best bet would be to remove these encryption standards from their email communications. Although it was first developed in 1991 by a software engineer named Phil Zimmermann, it became mainstream after whistleblower Edward Snowden revealed the scope of the USA government's surveillance programme. Unfortunately, the newly discovered "Efail" vulnerability could make that a possibility.


  • Palace finish with a bang

    Palace finish with a bang

    The home team went close after the break when Zaha broke free on the left wing before cutting it back for Ruben Loftus-Cheek, but his attempt was smothered by Foster.
    Everton interested in Newcastle boss Rafael Benitez

    Everton interested in Newcastle boss Rafael Benitez

    Ashley said: "I would like to thank Rafa Benitez for his magnificent achievement this season". That condemns them to a place in the less prestigious Europa League next season.
    Thiem shocks Nadal in Madrid to qualify for semifinals

    Thiem shocks Nadal in Madrid to qualify for semifinals

    It was very important I went in with a positive attitude, with an attitude to win. "Also in maybe the next upcoming tournaments". The loss also will knock Nadal out of the top spot in the world rankings, although perhaps not for long.
  • 4 prison guards' names added to memorial

    4 prison guards' names added to memorial

    Among those names, fallen Douglas County Deputy Zackari Parrish, who was killed in the line of duty on December 31, 2017. The evening's program also featured moving musical tributes and a special recognition of survivors of fallen officers.
    Two critically injured in light aircraft crash

    Two critically injured in light aircraft crash

    The crashed aircraft was found approximately 2 kilometres from the Clonbullogue Airfield they had departed from earlier. The aircraft initlaly took off with 16 parachutists on board at around 2.30pm, from Clonbullogue Airfield, Gardai said.
    Centurions! All of Manchester City's remarkable Premier League records

    Centurions! All of Manchester City's remarkable Premier League records

    They needed only a point to head off Chelsea and seal the fourth remaining spot in Europe's premier club competition next season. Four Italians, two Scots, a Frenchman, a Portuguese and a Chilean have also won the Premier League.
  • US Secretary of State Mike Pompeo promises North Korea 'prosperous' future

    US Secretary of State Mike Pompeo promises North Korea 'prosperous' future

    Singapore is an ideal site for the summit because Singapore historically has been an honest broker between East and West. And there are a number of things - provocative actions, for example, from North Korea would not be received well.
    MP Board Result 2018: Class 12th Result Announced Today

    MP Board Result 2018: Class 12th Result Announced Today

    The pass percentage of girls for MP Board 10th Result was 51.02 per cent, whereas for boys it was 50.71 per cent. The Madhya Pradesh Board (MP Board) Class 10 & Class 12 Board 2018 shall be officially declared on May 14, 2018.
    Sean William Scott To Replace Clayne Crawford After 'Lethal Weapon' Firing

    Sean William Scott To Replace Clayne Crawford After 'Lethal Weapon' Firing

    Lethal Weapon is packed with action, drama and pure fun and we can't wait to see Damon and Seann together on screen. Fan reaction was varied with one saying they would stop watching if Clayne Crawford was sacked .
  • Cannes film fest chiefs sign gender equality charter

    Cannes film fest chiefs sign gender equality charter

    What's important is that the 82 of us who stood there stood in solidarity with women from all professions, all countries. Kristen Stewart , Marion Cotillard , Ava DuVernay , Léa Seydoux and Salma Hayek were among those who joined.
    How the SCOTUS sports betting ruling could impact Alabama

    How the SCOTUS sports betting ruling could impact Alabama

    A long-time observer of match-fixing and sports gambling had strong words of caution over what's to come. Legalized sports betting is coming to New Jersey very soon and more than likely DE very quickly.
    Ramirez homers, Price snaps slide as Red Sox beat Blue Jays

    Ramirez homers, Price snaps slide as Red Sox beat Blue Jays

    The under is 6-1 in the last seven meetings between these two teams in Toronto and is 4-1 in the last five meetings overall. The Red Sox pushed the lead to 5-3 in the top of the eighth, when Benintendi scored on a ground out by Xander Bogaerts.