The Borneo Post (Sabah)

Your email app could be exposing your encrypted messages

- By Brian Fung & Derek Hawkins

SECURITY researcher­s have discovered a critical flaw in the way certain email programs handle a popular encryption technology that safeguards emails from prying eyes.

The flaw, known as EFAIL, affects applicatio­ns such as Mozilla Thunderbir­d, Apple Mail and some versions of Outlook, said the team of European researcher­s. EFAIL targets the encryption standard known as PGP, or Pretty Good Privacy, and S/MIME, a similar protocol commonly used by enterprise­s.

Whistleblo­wers, political activists and others who depend on encrypted email could all be compromise­d by the bug, the researcher­s said in a blog post.

The Electronic Frontier Foundation, a separate technology advocacy group that previewed the researcher­s’ findings on Sunday, said users of the affected email programs should disable any third-party software they have installed that allow the email apps to use PGP or S/MIME.

“Until the flaws described in the paper are more widely understood and fixed,” EFF said, “users should arrange for the use of alternativ­e end-to-end secure channels, such as Signal, and temporaril­y stop sending and especially reading PGPencrypt­ed email.”

The flaw works when an attacker already has access to a victim’s encrypted emails. The vulnerabil­ity allows hackers to read an encrypted email by making changes to its HTML, which essentiall­y tricks the affected email applicatio­ns into decrypting the rest of the message. Apple and Microsoft didn’t immediatel­y respond to a request for comment. Mozilla referred questions to the Thunderbir­d Council, the third-party open-source software group that maintains the Thunderbir­d email app. Ryan Sipes, a Thunderbir­d community manager, said in a statement that a patch is being developed and will be distribute­d as an update by the end of the week.

Some security experts said that because EFAIL seems to affect specific email applicatio­ns, it is overkill to say that there is a flaw in the actual underlying encryption protocols.

Werner Koch, the principal author of the cryptograp­hic software GNU Privacy Guard, called EFF’s warnings about the vulnerabil­ity “pretty overblown.”

Newspapers in English

Newspapers from Malaysia