USA TODAY International Edition

Researcher­s explain why encrypted emails may be at risk

- Brett Molina

If you use a tool to encrypt your email messages, it may be at risk from flaws uncovered by European researcher­s.

A paper posted by German and Belgian researcher­s to the website Efail details how tools used to secure sensitive email messages can be exposed in plain text.

“There are currently no reliable fixes for the vulnerabil­ity,” said Sebastian Schinzel, one of the researcher­s who helped write the Efail paper, in a post on Twitter.

Here’s what you should know about the vulnerabil­ity:

What is Efail?

It breaks down flaws found in two key tools for email encryption: PGP and S/ MIME.

PGP (Pretty Good Privacy) and S/ MIME (Secure/Multipurpo­se Internet Mail Extensions) are tools used to secure sensitive email messages. While most email clients offer baseline levels of security for email, users who want an extra layer of protection will add PGP extensions to encrypt messages. In the case of S/MIME, the standard is often used in corporate versions of email clients to secure messages.

The Efail flaws break encryption “by coercing clients into sending the full plaintext of the emails to the attacker,” says a post from researcher­s.

“PGP in its current form has served us well, but ‘pretty good privacy’ is no longer enough,” says a blog post from the Electronic Frontier Foundation. “We all need to work on really good privacy, right now.”

Why does it matter?

People like journalist­s or whistleblo­wers who rely on encrypted messaging to send and receive sensitive informatio­n find themselves at great risk of exposure.

“Powerful attackers such as nation state agencies are known to eavesdrop on email communicat­ions of a large number of people,” Efail researcher­s said.

How should I protect myself?

Researcher­s advise decrypting your messages outside of your email client using a third-party applicatio­n. The EFF said it would cut back on sending messages via PGP for both internal and external messages.

The group said dropping PGP entirely is too challengin­g.

“There is no other email encryption tool that has the adoption levels, multiple implementa­tions, and open standards support that would allow us to recommend it as a complete replacemen­t for PGP,” it wrote.

EFF also suggests considerin­g using encrypted messaging apps including Signal.

If you use PGP plug-ins for your email accounts, you should consider disabling them. EFF has posted tutorials on how to remove them from clients such as Mozilla’s Thunderbir­d and Apple’s Mail.

 ?? GETTY IMAGES ?? Researcher­s on the website Efail have uncovered flaws in a popular tool used to encrypt emails.
GETTY IMAGES Researcher­s on the website Efail have uncovered flaws in a popular tool used to encrypt emails.

Newspapers in English

Newspapers from United States