Hacker Newsnew | past | comments | ask | show | jobs | submit | fensipens's commentslogin

GOWK is the right answer


Response by Werner Koch (GPG), contains some details:

https://lists.gnupg.org/pipermail/gnupg-users/2018-May/06031...


>Due to broken MIME parsers a bunch of MUAs seem to concatenate decrypted HTML mime parts which makes it easy to plant such HTML snippets.

To me this sounds strictly like a MUA issue, not a PGP/SMIME one. If that's really all it is it does seem massively overblown to me. Why not single out the broken MUA implementations instead of saying "don't decrypt emails OR YOU'LL DIE"? I mean just look at the wild speculation in this thread, nobody understood what was going on or even what was really vulnerable and what wasn't. Given the alarmist tone and the claims of "no workaround available" I was personally expecting a deep conceptual flaw in PGP/SMIME themselves. Terrible communication IMO. The parent email in the GnuPG thread seems to agree: https://lists.gnupg.org/pipermail/gnupg-users/2018-May/06031...

We'll know for sure tomorrow I suppose.


Sounds like this has been handled absolutely terrible both by the original researchers and EFF. The researcher then trying to shush the directly affected GPG developers on Twitter, evidently just for the sake of a stupid no-prior publication bullshit for their paper just adds to it.


I dunno, a client issue like this seems pretty terrible to me since there is no obvious (to me) way to fix it. If I am encrypting a message, I have no control over what client decrypts it (and whether that client unwittingly passes the information along) without maybe changing the standard completely.

The thing is, If I am reading correctly, it seems like this kind of vulnerability seems totally predictable.


I agree, after getting the details it's fair to say that while some MUAs should fix their handling of encrypted emails PGP implementations and the S/MIME standard shares a part of the blame by not detecting and preventing the decoding of tampered documents. Still, the way the problem was disclosed is rather misleading and confusing.


So in short, if you have all mails set to display as plain text rather than HTML, there's no problem?


to quote the letter:

There are two ways to mitigate this attack

- Don't use HTML mails. Or if you really need to read them use a proper MIME parser and disallow any access to external links.

- Use authenticated encryption.


Like every sane person should do.


That ship sailed when email got named email instead of etelegram.


Why do you think so? People are not forced to use HTML mails. I don't.


Oh, I thought you were making the "email should only be text" argument, not the "you should avoid looking at the non-text part of multipart email" argument. I was addressing the former.


I'm stealing etelegram for a new startup I'm going to make


Aren't telegrams already "e"?


Time to start testing your email clients with https://www.emailprivacytester.com


You are not alone, see the following exchange on LKML, where Donenfeld immediately "disciplines" another subscriber for asking some minor question that was not 100% on topic:

https://lkml.org/lkml/2017/12/7/1745

Follow-up by David Miller:

https://lkml.org/lkml/2017/12/8/533

That said, I like the idea of WG like I liked the idea of systemd.. but Donenfeld just seems to be another Poettering in the making.


To be fair, his own reply to that was reasonable: https://lkml.org/lkml/2017/12/8/714


> Big data helped New York's cops bust Bobby Shmurda

So glad Palantir helped getting Bobby Shmurda (best known for Shmoney Dance) off the streets.


The new ones are always "completely different" from the old ones.. until someone digs up old articles that say the same thing about the old ones.


better than Virtualbox

Just take a look at VBoxManage --help for a crazy list of settings and features that VBox has accumulated during the past ~10 years.

It even supports ATA TRIM so your fs-driver can discard blocks and keep the VDI-file deflated at all times.

Performance-wise: Compiling stuff within VBox on an i7 quad-core (-j5) is almost as fast as native. X on Linux-VMs feels native too, especially when running in fullscreen.


Out of curiosity, have you tried anything other than VirtualBox (e.g. VMware Fusion)?

I was happy with VirtualBox's (on OS X) performance until I bought VMware Fusion. I didn't do any benchmarks so I don't have numbers to back up my claim but it definitely "felt" much faster than VirtualBox.


I never tried VMF so it may be faster, sure. The thing about VBox is, like I wrote, features. VBox is basically a full-featured Virtualization-Suite, has multiple UIs and an API. It is also available on Win7,8,10/macOS/Linux and Solaris.

You may add: excellent documentation and friendly support (board, irc, list).

If I'll ever have to switch, I'd first need feature-parity.


Bridging to a wireless interface is done differently from bridging to a wired interface, because most wireless adapters do not support promiscuous mode. All traffic has to use the MAC address of the host's wireless adapter, and therefore VirtualBox needs to replace the source MAC address in the Ethernet header of an outgoing packet to make sure the reply will be sent to the host interface. When VirtualBox sees an incoming packet with a destination IP address that belongs to one of the virtual machine adapters it replaces the destination MAC address in the Ethernet header with the VM adapter's MAC address and passes it on. VirtualBox examines ARP and DHCP packets in order to learn the IP addresses of virtual machines.

https://www.virtualbox.org/manual/ch06.html#network_bridged


> Ex Google Zürich

Badge of Honor



So what? Many standards originated from some particular need of one or two companies popular at that time. Look at the current IETF WGs and the authors of the drafts they produce.


what Facebook did with email

What did Facebook do with email?


Bloody murder, basically.

Whenever I try to communicate with someone under 30, e-mail is simply not an option. A Facebook message is often the only way (or worse).


Made it obsolete, didn't you hear?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: