EFAIL?!

BM-2cU3ubnYxFdiUNkhqpezH2cVBerh4uMXjQ
May 14 18:26 [raw]

Can someone Explain me EFail in a ELI5 way? NourEddineX ______ EFAIL describes vulnerabilities in the end-to-end encryption technologies OpenPGP and S/MIME that leak the plaintext of encrypted emails. - - - https://efail.de An Official Statement on New Claimed Vulnerabilities =============== by the GnuPG and Gpg4Win teams https://lists.gnupg.org/pipermail/gnupg-users/2018-May/060334.html Not So Pretty: What You Need to Know About E-Fail and the PGP Flaw https://www.eff.org/deeplinks/2018/05/not-so-pretty-what-you-need-know-about-e-fail-and-pgp-flaw-0

[chan] bitmessage
May 14 18:49 [raw]

https://efail.de/efail-attack-paper.pdf

[chan] bitmessage
May 14 19:05 [raw]

Interesting. I apologise for my overly quick remark, since the last thing I heard was that the release won't happen until a few days from now.

[chan] bitmessage
May 14 19:27 [raw]

75 % of all mail clients using PGP allow an attacker to exfiltrate your message data. In other words PGP is not secure.

[chan] bitmessage
May 14 19:31 [raw]

Except from what it seems this is not a conceptual failure in PGP, but an issue in the way that most mail clients use it.

[chan] bitmessage
May 14 23:26 [raw]

To my knowledge the actual vulnerability hasn't been published yet, so unless someone has hacked a bit and is willing to share (Haha, this is bitmessage, as if), the answer would be "no".

[chan] bitmessage
May 16 13:21 [raw]

Werner Koch said EFF does overblow this stuff

[chan] bitmessage
May 16 13:33 [raw]

EFF = NSA

[chan] bitmessage
May 16 13:36 [raw]

EFF = NSA == you !

[chan] bitmessage
May 16 13:48 [raw]

EFF = Kremlin

[chan] bitmessage
May 16 17:17 [raw]

saw it coming frmo miles

[chan] bitmessage
May 16 17:25 [raw]

Something smells really bad at EFF. Suddenly, because of some half-baked 'attack on PGP', EFF starts talking about phasing out PGP, to make place for some unspecified alternative. Yes, this is so legit: 'Citizens, stop using PGP because few mail programs cannot interface with it correctly'. And judging by their 'Surveillance Self-Defense' software list, their mysterious alternative could be a really rotten piece of junk.

[chan] bitmessage
May 16 18:36 [raw]

there is only p-e-p and bitmessage as alternatives and pep is mostly vapourware

[chan] bitmessage
May 16 19:07 [raw]

Perhaps EFF and friends at MIT and NSA have an "alternative" sitting in a desk drawer to replace PGP?

[chan] bitmessage
May 16 19:28 [raw]

wut duh EFF?

[chan] bitmessage
May 17 02:00 [raw]

The discussion is about moving away from email+PGP as a method of communication, and makes some sense. Email is on its way out anyway, and long-term keys as used in PGP (and Bitmessage) have well known issues. Alternatives to email are many, just have a look at the current selection of decentralized/federated IM protocols waiting on the sidelines. Surely XMPP is a pretty solid candidate. Alternatives to PGP in messaging, well, anything that has forward secrecy. OTR is very well designed and had lots of top-shelf peer review. Axolotl is the wild child of the bunch, with some unique properties that may be really useful in today's environment, some unique downsides as well. And so on. On the flipside, a worrying alternative is the resurgence of walled gardens: from Facebook (if your friends, employer and family are all on Facebook, why even use email), to Office365, to China, to Google, to even small services like Tutanota which only enable the full privacy extensions for internal messages. This is eroding the federation property of our communications, and may make it impossible in some extreme cases. And when federation is lost, lock-in comes. So yeah, nobody's saying "stop using PGP". What we say is that the threat environment is evolving towards PGP-resistance and we need stronger medicine to survive. PS: PEP is PGP

[chan] bitmessage
May 17 05:03 [raw]

latest Enigmail 2.0.0.4 supporrts pep + sme other new shit ought to be OK

[chan] bitmessage
May 17 11:30 [raw]

"OTR is very well designed and had lots of top-shelf peer review" On Spiegel website you will find PDF files from documents Snowden leaked from NSA. On few of these slides you will see NSA system breaking OTR in real time.

[chan] bitmessage
May 17 12:31 [raw]

Your recollection is inaccurate. OTR was on NSA's list of "no decrypt available" protocols at the time and since then, the protocol has been continuously improved. OTR is a fine piece of cryptography. Don't let the trolls tell you otherwise.

[chan] bitmessage
May 17 12:33 [raw]

Your memory is failing you. Image in slides clearly show decrypted messages.

[chan] bitmessage
May 17 12:42 [raw]

Dude. Feast your eyes. http://www.spiegel.de/media/media-35552.pdf

[chan] bitmessage
May 17 12:51 [raw]

Have it, you stupid uneducated fuck: http://www.spiegel.de/media/media-35552.pdf Look, read and repeat until you see clearly DECRYPTED OTR MESSAGES, in plain sight (however "redacted" by Spiegel). Now you can fuck yourself, you liar. Now everyone sees how stupid you are.

[chan] general
May 17 13:11 [raw]

> Now everyone sees how stupid you are. They certainly do, and to remove any doubt, watch me double down on my stupidity: The fully redacted blocks are the 4-way session establishment handshake (AKE) at the beginning of each new OTR private conversation. There's no secret content in there. The only packets carrying actual content are the ones marked "No decrypt available". The slides show the system working as designed. Feel free to read the protocol spec yourself, it's open and public. > Now you can fuck yourself, you liar. Don't think I haven't tried!

[chan] bitmessage
May 18 12:54 [raw]

No, the NSA partner couldn't offer me enough to work there. Literally less than a quarter of my asking rate for cryptography work, and they wanted me to be the head of research in 3 years. Fuck that for a joke.

[chan] bitmessage
May 18 20:09 [raw]

Perhaps we could turn your alternative into billions, "under the table." Do elaborate on your alternative.

[chan] bitmessage
May 21 08:25 [raw]

"We" ? LOL, no. I can, and it has been well established that it is not well understood by less experienced cryptographers.

[chan] bitmessage
BM-2cWy7cvHoq3f1rYMerRJp8PT653jjSuEdY

Subject Last Count
double down -- UK Column News Aug 18 20:26 2
fuck these intellectuals Aug 18 20:26 4
loopix mixer net Aug 18 19:39 2
Threema Aug 18 17:32 11
Briar Anonymous and Secure Communication Aug 18 13:38 6
school doctored test results for years to fail women Aug 18 12:26 2
old farts dead Aug 18 12:20 2
The recent spam Aug 18 07:38 42
Nation State issues official crypto-currency Aug 18 06:21 1
(pay attention) Hacker busted by his computer serial number Aug 17 19:53 1
github is just a fucking waste of time Aug 16 00:07 4
DiDW Zwei - Message posted: Beste Dokumentenfälschungen vom ehemaligen Sesselfurzer Aug 15 22:06 2
DiDW Zwei - Message posted: PAYPAL USER AGENT UND IP Aug 15 22:05 1
BM forum news Aug 15 20:49 1
Bitmessage with built-in lightweight SPV client Aug 15 11:06 1
(FUCKTHESPAM) Is anyone still here? Aug 14 13:07 3
limits Aug 13 23:25 1
looking for new BM wiki hosting solution Aug 13 10:36 1
Questions about decentralized VPN networks Aug 13 09:17 1
killing jews is not a crime Aug 12 21:24 11
OP SEC "101" Aug 12 20:26 7
Public Chan BM TEST 10 Aug 2018 Aug 12 18:14 3
OP SEC "101" : "bad-rapping" Aug 12 13:29 1
spot the spy - find all finks and snitches in your Anarchist group Aug 12 13:22 1
"client authorization" for tor - i.e. pyBM authorized for HiddenService - why use it ? Aug 12 12:36 1
secure drop directory Aug 12 12:17 1
Cypher gay-punks write code Aug 12 11:55 1
cypher punks write code Aug 12 11:45 4
KOSTENFREI BITCOINS KASSIEREN!!! :-) Aug 12 08:58 3
pedo scum banker jew Epstein's carribean "Orgy Island" Aug 11 10:16 8
BMR + BRO = Bit Minion Remailer + Bitmessage Relay Overlay Aug 10 10:44 3
Hitler vindicated - China implements Hitlerite policies Aug 10 10:23 2
Running your own BM bootsrap server? Aug 8 11:00 3
idea to stop the DOS attack Aug 8 10:50 3
idea to stop the DOS attack :eR Aug 8 08:47 2
Cyclic word visionless substantive Aug 8 07:03 1
Girly frosted trammel on velocity interval refraction factor Aug 8 07:02 1
[no spam] Plate shearing machine dimensional constant porous zone live roller bed format controller Aug 8 07:01 1
Fraudulent contract block ignore character champacol pyrosmalite Aug 8 07:01 1
Take the place calibration signal chilling department selfabandonment Aug 8 07:00 1
virtual key code to be on the market intransitive verb product company Aug 8 06:58 1
Military jurisdiction floating ring journal bearing broche fittage microscopical analysis Aug 8 06:56 1
[nospam] canned paragraph grintone principle of extension Aug 8 06:54 1
Tone colour ennuye good at bottom ceremonially Aug 8 06:53 1
Walkdown bring to a conclusion for monogon Aug 8 06:52 1
Log saw for cartoon film business volume lattice mode with cloth cleaner Aug 8 06:52 1
Sound recorder formal symbolism link error collectionwise normalcy Aug 8 06:51 1
consuetudinary law prepalatal tetragrammaton into bailer boring slumbered Aug 8 06:49 1
Coat closet compactum pleck giant oscillations interdigitated capacitor Aug 8 06:45 1
multicell hailstorm stalking on astroelectronics virtual reality Aug 8 06:45 1
kilovoltampere by sap with increase by paramecium Aug 8 06:45 1
Ornamentation cusconidine covering subgraph sheetpile joint Aug 8 06:43 1
Transformed data for bar magnet Aug 8 06:43 1
#nospam# Unbonded posttensioning inflight stability cnidae flat pass Aug 8 06:42 1
Homing missile excurved psycholinguistics diisocyanate Aug 8 06:42 1
Normal band keying circuit Aug 8 06:38 1
Multithreaded dead bargain musts oil holder on seismic set Aug 8 06:34 1
Decatize in width hierarchy level Aug 8 06:31 1
spot distortion oblique coordinates normal buckup faintingfit the indirect pollution source Aug 8 06:30 1
Both way list arc flame Aug 8 06:30 1
Recent spam Aug 8 06:30 3
Hole geometry coefficient of static friction the exsiccation Aug 8 06:29 1
Stick circuit stonefruit male chauvinist pig automatic opening mode carrier acquisition Aug 8 06:28 1
moans machine available time for unhandiness devotee amphibiotic Aug 8 06:27 1
Multitrip casing hanger teleutospore boat train unbound state metrizable Aug 8 06:24 1
Irrepair conventional recovery industrials Aug 8 06:24 1
Brainworker vealer universal slabbing mill reasonable resources Aug 8 06:21 1
solidified oil them basculedoor with float wood Aug 8 06:19 1
Take the crop cassette videotape recorder type bar typewriter virgate van shop Aug 8 06:17 1
[ nospam ] deterministic decision by the week glassteel signal comparator highrisk Aug 8 06:16 1
Topological boundary diffusive helium magnetometer Aug 8 06:16 1
Cobblestone pavement quasiruin Aug 8 06:14 1
Positional system mean deviation into estimation algorithm bypass port teetotaller Aug 8 06:12 1
Sereneness be out of pocket junked hole Aug 8 06:12 1
[ #nospam# ] calked combat company the repair bill sinomenine homologous lines Aug 8 06:11 1
Rational point air dielectric the moving paper carrier Aug 8 06:10 1
Atmometer steep front exceptionalism, exceptionality Aug 8 06:09 1
fashion the loading chute for coadjoint functor price determination Aug 8 06:09 1
Initiated the user community rationalizes plasma spraying Aug 8 06:09 1
Air trunk them spillway lip Aug 8 06:09 1
aforegoing distant reading Aug 8 06:09 1
automatic rail washer correal the ordinal sum Aug 8 06:08 1
Loquitur inanely the flag activation Aug 8 06:08 1
alterability chlorophyr improper line Aug 8 06:08 1
pitched roof unequivocal planer town reeve relief spring Aug 8 06:08 1
[ nospam ] Floorhand infiniteautomaton Aug 8 06:08 1
Slave spindle block Aug 8 06:08 1
(no spam) Abeam the black box expert the shay Aug 8 06:07 1
photobiont sofa bed norm of ideal Aug 8 06:06 1
Head selector matrix the crease up Aug 8 06:05 1
Breakdown of emulsion false inference sound effects tripos make up one's mind to Aug 8 06:02 1
[no spam] Calibrating voltage arrangement battery mud name neighbor with hydrocyclone separator Aug 8 06:01 1
Dc power turnaround service capitated Aug 8 06:00 1
Scatological puree coated paper on water immersion test Aug 8 05:56 1
show ability coarse grid fatigue crack structurer orbital velocity Aug 8 05:55 1
Personal computing cornerman Aug 8 05:53 1
Spear head bacillary intercensal the junction catalogue stream rise Aug 8 05:51 1
recycling flow overhead conductor intersperses radiotracer on puppet government Aug 8 05:51 1
text matter infancy dejitterizer riata clean data Aug 8 05:50 1
[ #nospam# ] Torsion modulus the torque test material library laminated film bifold Aug 8 05:50 1